Method for Securing the Announcements and Withdrawals of Inter-domain Routes

Yang Bo · Journal of Chinese Computer Systems · 2012

Most of current existing schemes for securing inter-domain routing whose security is popularly accepted,eg.S-BGP,can not distinguish whether an update message is a regular update message for announcing route(s) or malicious replay for route(s) which have been withdrawn before.This security hole can pose serious threat to the Internet security about the inter-domain routing.In this paper,we analyse this hole in detail,and present a method for remedying it.In this presented method,we introduce a sequence number for every update message,and fuse a digital self-certified signature scheme with message recovery.This presented method can prevent the sequence number from being tampered without introducing extra burden of computation.When the speaker router of an autonomous system receives an update message for announcing or withdrawing route(s),it can prevent this kind of replay attack by its mechanisms about caching,comparing and judging these sequence numbers,so as to achieve a scheme for securing the announcements and withdrawals of inter-domain routes at the same time the heavy tasks of certificate storage and management are eliminated without introducing key escrow.

Read the paper · More papers on PaperTik