作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2007, Vol. 33 ›› Issue (17): 34-36. doi: 10.3969/j.issn.1000-3428.2007.17.012

• 博士论文 • 上一篇    下一篇

基于身份的BGP路径验证机制

王 娜1,2,顾纯祥3,汪斌强1,3   

  1. (1. 国家数字交换系统工程技术研究中心,郑州450002;2. 解放军信息工程大学电子技术学院,郑州450004;3. 解放军信息工程大学信息工程学院,郑州450002)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2007-09-05 发布日期:2007-09-05

BGP Path Verification Mechanism Based on ID

WANG Na1,2, GU Chun-xiang3, WANG Bin-qing1,3   

  1. (1. National Digital Switching System Engineering & Technological R & D Center, Zhengzhou 450002; 2. College of Electronic Technology, PLA Information Engineering Univ., Zhengzhou 450004; 3. College of Information Engineering, PLA Information Engineering Univ., Zhengzhou 450002)
  • Received:1900-01-01 Revised:1900-01-01 Online:2007-09-05 Published:2007-09-05

摘要: 边界网关协议(BGP)因设计缺陷易受到各种类型的攻击。然而,当前BGP路径验证机制中繁重复杂的公钥基础设施(PKI)密钥管理和过量的存储空间开销严重阻碍了BGP安全方案在实际中部署实现。基于此,该文将基于身份的签名算法引入路径验证,提出了一个基于身份的路径验证机制(IDPV)。与当前基于证书的路径验证机制相比,IDPV有效地简化了PKI密钥管理,减少了路由器存储开销,提高了路径验证的性能,促进了BGP安全方案在实际中的应用。

关键词: 路由, 安全, BGP, 路径验证, 基于身份的密码学

Abstract: The border gateway protocol(BGP) is vulnerable to various attacks for previous design limitations. However, the heavy and complicated public key infrastructure (PKI) key management and too much storage space cost in current BGP path verification mechanisms severely block BGP security solutions from being implemented and deployed in real world. For the first time the ID-based signature scheme is introduced into BGP path verification, and so the ID-based path verification mechanism(IDPV) is proposed. Compared with current certificate-based path verification mechanisms, IDPV effectively simplifies PKI key management and reduces router’s storage space cost, improves path verification performance. The BGP secure solution with IDPV will be more easily realized and deployed in Internet.

Key words: route, security, BGP, path verification, identity-based cryptography

中图分类号: