Study of BGP Secure Scheme Based on Divide and Conquer Strategy

WANG Bin,AN Jin-liang,WU Chun-ming,LAN Ju-long
DOI: https://doi.org/10.3969/j.issn.1000-436x.2012.05.012
2012-01-01
Journal of Communications
Abstract:A new approach was studied for BGP security:SE-BGP.By analyzing the security of SE-BGP,was found it had some secure leaks which couldnt resist active attack.To solve these secure problems of SE-BGP,an AS-alliance-based secure BGP scheme :SA-BGP was proposed,which used the aggregate signatures algorithm based on RSA.The SA-BGP has strong ability of security that can effectively verify the propriety of IP prefix origination and verifies the validity of an AS to announce network layer reachability information (NLRI).SA-BGP can large-scale reduced the number of the used certificates.Performance evaluation results that SA-BGP can be implemented efficiently and the incurred overhead,in terms of time and space,ptable in practice.
What problem does this paper attempt to address?