APVAS+: A Practical Extension of BGPsec with Low Memory Requirement
Tatsuya Takemura, Naoto Yanai, Naoki Umeda, Masayuki Okada, Shingo Okamura, Jason Paul Cruz · 2021
BGPsec is a protocol that utilizes digital signatures to guarantee the validity of routing information on the Internet. However, it is impractical because its use of digital signatures requires significant memory that is beyond the memory capacity of current routers. The latest extension of BGPsec based on an aggregate signature scheme, which aggregates individual signatures into a single short signature, has been proposed in the recent years, but its memory requirement is still impractical. In this paper, we present APVAS+, a protocol that reduces the memory consumption of routers compared to state-of-the-art protocols. The memory requirement of APVAS+ is almost within the memory capacity of real-world routers. While the latest BGPsec protocol can only aggregate signatures generated on a single linear network topology, APVAS+ can aggregate signatures generated on any network topology by using a novel aggregate signature scheme. We also show a prototype implementation of APVAS+ by extending a router software called BIRD. Using this prototype, we conducted experiments on a full route information, i.e., about 800,000 routes. We consider that APVAS+ can be optimized to further reduce its memory requirement, and our promising results show that the memory consumption of routers running APVAS+ is lower than that of routers running other protocols by more than half when guaranteeing the validity of routing information.