节点文献

基于分治策略的BGP安全机制

Study of BGP secure scheme based on divide and conquer strategy

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 王滨安金梁吴春明兰巨龙

【Author】 WANG Bin1,2,3,AN Jin-liang4,WU Chun-ming1,LAN Ju-long3 (1.Computer Science College,Zhejiang University,Hangzhou 310027,China; 2.College of Information and Electronic Engineering,Zhejiang Gongshang University,Hangzhou 310018,China; 3.National Digital Switching System Engineering&Technological R&D Center,Zhengzhou 450002,China; 4.College of Information Technology,Henan Institute of Science and Technology,Xinxiang 453003,China)

【机构】 浙江大学计算机科学与技术学院浙江工商大学信息与电子工程学院国家数字交换系统工程技术研究中心河南科技学院信息工程学院

【摘要】 研究了SE-BGP的安全性,通过分析发现该机制存在安全漏洞,无法抵御合法用户发起的主动攻击。为了克服SE-BGP存在的安全漏洞,基于AS联盟的思想,使用基于RSA的聚合签名算法设计了一种新的BGP安全机制:SA-BGP,该机制具有更高的安全性,可以有效地验证AS宣告的网络层可达信息(NLRI)的正确性和AS宣告的路径属性的真实性,还可以大规模地减少网络证书规模和单个节点存储的证书数量,通过仿真实验得到SA-BGP和同级别的安全机制相比对网络的影响较小,收敛速度更快。

【Abstract】 A new approach was studied for BGP security: SE-BGP.By analyzing the security of SE-BGP,was found it had some secure leaks which couldnt resist active attack.To solve these secure problems of SE-BGP,an AS-alliance-based secure BGP scheme : SA-BGP was proposed,which used the aggregate signatures algorithm based on RSA.The SA-BGP has strong ability of security that can effectively verify the propriety of IP prefix origination and verifies the validity of an AS to announce network layer reachability information(NLRI).SA-BGP can large-scale reduced the number of the used certificates.Performance evaluation results show that SA-BGP can be implemented efficiently and the incurred overhead,in terms of time and space,is acceptable in practice.

【基金】 国家高技术研究发展计划(“863”计划)基金资助项目(2008AA01A323,2009AA01A334,2008AA01A325);国家重点基础研究发展计划(“973”计划)基金资助项目(2007CB307102);国家科技支撑计划基金资助项目(2008BAH37B02);国家自然科学基金资助项目(60773182,61070157)~~
  • 【文献出处】 通信学报 ,Journal on Communications , 编辑部邮箱 ,2012年05期
  • 【分类号】TP393.08
  • 【被引频次】6
  • 【下载频次】163
节点文献中: 

本文链接的文献网络图示:

本文的引文网络