- 1、本文档共43页,可阅读全部内容。
- 2、有哪些信誉好的足球投注网站(book118)网站文档一经付费(服务费),不意味着购买了该文档的版权,仅供个人/单位学习、研究之用,不得用于商业用途,未经授权,严禁复制、发行、汇编、翻译或者网络传播等,侵权必究。
- 3、本站所有内容均由合作方或网友上传,本站不对文档的完整性、权威性及其观点立场正确性做任何保证或承诺!文档内容仅供研究参考,付费前请自行鉴别。如您付费,意味着您自己接受本站规则且自行承担风险,本站不退款、不进行额外附加服务;查看《如何避免下载的几个坑》。如果您已付费下载过本站文档,您可以点击 这里二次下载。
- 4、如文档侵犯商业秘密、侵犯著作权、侵犯人身权等,请点击“版权申诉”(推荐),也可以打举报电话:400-050-0827(电话支持时间:9:00-18:30)。
查看更多
EfficientBGPSecurity详解
08/01/2005 63rd IETF - Paris, FRANCE Efficient BGP Security Meiyuan Zhao, Sean Smith Dartmouth College David Nicol University of Illinois, Urbana-Champaign Motivation BGP—central routing for the Internet BGP lacks security Black holes Disconnected networks Suboptimal routes … Secure BGP Deployment difficulties Processing overheads Storage demands PKIs Goal Efficient AND practical security Outline Overview BGP S-BGP Path authentication PKI and origin authentication Discussion Conclusions Border Gateway Protocol (BGP) Inter-domain routing protocol Mainly between autonomous systems (ASes) Updates are in form of route announcements Secure BGP (S-BGP) Attestations Route Attestations—authenticate AS path Address Attestations—authorization of IP address ownerships Public key infrastructures Certificates for routers Certificates for address ownership Outline Overview Path authentication S-BGP RAs Aggregated Path Authentication Performance evaluation PKI and origin authentication Discussion Conclusions S-BGP Route Attestations (RAs) Router signs (AS path, prefix, next_hop) Sends all previous signatures Verify AS path {1, 2, 3} Needs 3 signatures Sign AS path {1, 2, 3} Creates n signatures Signature Algorithm—DSA Caching optimization Performance Problems Time Processing latency 230% longer Space Message size: 800% longer Memory cost: 10 times more For Attestations Certificate database Current routers: 128MB or 256MB RAM Signature Amortization (S-A) Fast signature verification—RSA Fewer signature signings—amortized cost Bit vectors (indicating recipients) Merkle hash trees Auxiliary values for each signature Aggregate Signatures k signers {s1, s2, …, sk} k messages {m1, m2, …, mk} one aggregate signature s One aggregate signature for entire AS path Aggregate Signature Variants General aggregate signature (GAS) Based on BLS short signature on Anyone can aggregate in any ordering Takes k+1 pairing calculation for verifying Sequential aggregate signa
您可能关注的文档
- DSA800系列详解.PDF
- DSA_Flyer_v4.indd-IVSS-Symposium详解.PDF
- DSAE-SeriesiSCSI磁盘阵列详解.PDF
- DSAOutputAnalysis详解.PDF
- DSA详解.PDF
- ebusinessondemandforRetailTheIBMPointofView详解.ppt
- EffectofNaCldopedintoBphen详解.PDF
- Dysmenorrhoea&详解.PDF
- ElectrochemicalTechnologiesin详解.PDF
- EBV相关恶性肿瘤的新病毒靶向性治疗研究进展详解.PDF
- 主题四 微专题1 中国优秀传统文化的内涵、价值与演变.docx
- 主题四 微专题1 中国优秀传统文化的内涵、价值与演变.pptx
- Unit 5 Music 单元词汇默写与运用(含答案)-2024-2025学年高中英语人教版(2019)必修第二册.docx
- 安徽省天长市2024-2025学年高三上学期第四次学情调研考试历史试题(含解析).docx
- Unit 3 The Internet 单元词汇默写与运用(含答案)--2024-2025学年高中英语人教版(2019)必修第二册.docx
- 部编人教版二年级下册道德与法治《我的环保小搭档》课件.pptx
- 山东省中企质信检测技术有限公司实验室建设项且建设项目环境影响报告表(污染影响类).pdf
- 北师大版(2019)必修第三册Unit 7 Art Lesson 3 A Musical Genius 课文变形语法填空(含答案).docx
- 福建省龙岩市2024-2025学年高一上学期1月期末英语试题(无答案).docx
- 广东省广州市2024-2025学年高三2月月考英语试题(无答案).docx
文档评论(0)