xBGPsec: Enhancing BGP Security with Transitive Signatures and External Validation
Nils Höger, Cristian Hesselman, Moritz Müller, Savvas Kastanakis · 2025
The Border Gateway Protocol (BGP), a cornerstone of global Internet routing, remains vulnerable to various attacks due to its lack of integrated security features and mechanisms to verify the authenticity and integrity of routing information. Although BGPsec was introduced as a standardized solution to address these concerns, it has not seen real-world deployment even after eight years, primarily due to operational complexity and deployment challenges. We present the design and implementation of xBGPsec, a protocol that improves BGP security by attaching digital signatures to BGP updates using optional transitive attributes. These signatures cover both the AS path and dedicated BGP attributes, and are generated and verified by a dedicated external validator, allowing enhanced security without disrupting existing routing operations. To demonstrate the feasibility of this approach, we built a dedicated testbed integrating xBGPsec-enabled routers and a supporting cryptographic infrastructure. This proof-of-concept provides the foundation for future empirical evaluation and offers initial insights for network operators and researchers exploring scalable, interoperable BGP security solutions.