作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2025, Vol. 51 ›› Issue (8): 39-52. doi: 10.19678/j.issn.1000-3428.0070248

• 热点与综述 • 上一篇    下一篇

区块链在BGP路由泄露防护中的应用研究

王群1,2,*(), 李馥娟1,2, 马卓1,2   

  1. 1. 江苏省电子数据取证分析工程研究中心,江苏 南京 210031
    2. 江苏警官学院计算机信息与网络安全系,江苏 南京 210031
  • 收稿日期:2024-08-13 修回日期:2024-11-20 出版日期:2025-08-15 发布日期:2025-01-07
  • 通讯作者: 王群
  • 基金资助:
    国家自然科学基金(62202209); 公安部科技计划项目(2023JSZ09); 教育部人文社会研究规划基金(24YJAZH158)

Research on Application of Blockchain in BGP Route Leakage Prevention

WANG Qun1,2,*(), LI Fujuan1,2, MA Zhuo1,2   

  1. 1. Jiangsu Electronic Data Forensics and Analysis Engineering Research Center, Nanjing 210031, Jiangsu, China
    2. Department of Computer Information and Cybersecurity, Jiangsu Police Institute, Nanjing 210031, Jiangsu, China
  • Received:2024-08-13 Revised:2024-11-20 Online:2025-08-15 Published:2025-01-07
  • Contact: WANG Qun

摘要:

组成边界网关协议(BGP)的自治系统(AS)之间存在不同的利益关系和路由策略,当实际的路由宣告超出预期范围时,可能产生路由泄露,从而导致因路由重定向引起的网络安全事件。然而,在BGP路由信息传播过程中,AS会无条件信任和接受邻居AS对外宣告的路由,而每个AS自主配置本地策略且信息保密,增加了路由策略验证的难度,成为BGP安全领域一直备受关注且尚未有效解决的难题。区块链以其独有的去中心化、可溯源、防篡改、开放透明等特征,可为AS间的数字资源认证与信任建立提供基础设施保障,有望成为应对路由泄露威胁的关键技术。首先,界定了邻居AS之间以及GR(Gao-Rexford)模型与BGP路由策略之间的关系,明确了导致路由泄露的根源和防御挑战;然后,梳理了针对路由泄露的传统解决方案的研究脉络,重点分析了其优缺点以及尚未解决的问题;接着,提出了区块链技术在BGP路由泄露防护中的优势及技术思路,探讨了典型解决方案的实现原理和应用特点;最后,在阐述存在问题和挑战的基础上,对下一步研究进行了展望。

关键词: 区块链, 域间路由安全, 路由源认证, 路由泄露, IP地址前缀

Abstract:

Autonomous Systems (ASes) that constitute the Border Gateway Protocol (BGP) have different interests and route policies. When actual route announcements exceed expected boundaries, route leakages can occur, leading to network security incidents caused by route redirection. In the propagation of BGP route information, ASes unconditionally trust and accept the routes declared by neighboring ASes. Additionally, each AS independently configures its own local policies and keeps this information secret, which complicates the verification of this route policy. This has been a persistent and unresolved challenge in the field of BGP security. Blockchain technology, with its inherent characteristics of decentralization, traceability, immutability, and transparency, offers a promising infrastructure for digital resource authentication and trust among ASes, potentially serving as a key technology for addressing the threat of route leakages. This study first clearly defines the relationships between neighboring ASes, as well as between the GR (Gao-Rexford) model and BGP route policies, elucidating the root causes of route leakages and the challenges in their prevention. Additionally, it reviews the research on traditional solutions to route leakages, focusing on their strengths, weaknesses, and unresolved issues. Subsequently, it proposes the advantages and technical approaches of using blockchain technology to defend against BGP route leakages and explores the principles and application characteristics of typical solutions. Finally, it discusses the existing challenges and outlines future research directions.

Key words: blockchain, interdomain route security, Route Origin Attestation (ROA), route leakage, IP address prefix