GesBGP: A Good-Enough-Security BGP

李琦,吴建平,徐明伟,徐恪,张新文
DOI: https://doi.org/10.3724/sp.j.1016.2009.00506
2009-01-01
Chinese Journal of Computers
Abstract:Inter-domain routing(BGP) directly influences availability of Internet routing which may be disrupted by misconfigured or malicious BGP updates.Although several secure solutions have been proposed to resolve the BGP security problem,they have many design drawbacks(e.g.,large router resource consumption).Considered the design and performance of secure BGP,this paper proposes a Good-Enough-Security BGP(GesBGP).Identity-based signature(IBS) algorithm presented in GesBGP guarantees the authenticity of BGP routes in the help of Trusted Computing(TC) technology.The presented IBS can effectively eliminate the centralized public key infrastructure(PKI) and resolve the problem of public key certificate distribution and restoration.Furthermore,GesBGP does not only rely on cryptography functions provided by IBS.BGP attestation service integrated in GesBGP prevents router from malicious change radically and thus builds strong trust relationship between different routers.In the optimized GesBGP,BGP security rules are enforced and the cumulated signature in original GesBGP is eliminated.The security analysis and performance study show that the optimized GesBGP improves the performance of GesBGP while achieving the goal of BGP security at the same time.
What problem does this paper attempt to address?