Securing Route Origin Authorization with Blockchain for Inter-Domain Routing

被引:0
|
作者
He, Guobiao [1 ]
Su, Wei [1 ]
Gao, Shuai [1 ]
Yue, Jiarui [1 ]
机构
[1] Beijing Jiaotong Univ, Sch Elect & Informat Engn, Beijing, Peoples R China
来源
2020 IFIP NETWORKING CONFERENCE AND WORKSHOPS (NETWORKING) | 2020年
关键词
BGP security; ROA; decentralized; tamper-proof; blockchain;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The inter-domain routing with BGP is highly vulnerable to malicious attacks, due to the lack of a secure means of verifying authenticity and legitimacy of inter-domain routes. Resource Public Key Infrastructure (RPKI) is a new security infrastructure to verify that an IP address block holder has authorized an Autonomous System (AS) to originate routes by maintaining a Route Origin Authorization (ROA) repository, preventing the most devastating prefix hijacks in BGP. However, RPKI is a centralized hierarchical architecture that may empower the centralized authorities to unilaterally revoke or compromise any IP prefixes under their control. To eliminate the risks of RPKI, we present ROAchain, a novel BGP security infrastructure based on blockchain. Different from RPKI, ROAchain is a decentralized architecture, in which each AS maintains a globally consistent and tamper-proof ROA repository, authenticating the legitimacy of route origin and preventing BGP prefix hijacks. In ROAchain, a novel consensus algorithm is proposed to guarantee the strong consistency, scalability, and security of the system. Moreover, an incremental deployment scheme is designed without changing the current BGP protocol. Finally, ROAchain is implemented in Golang and validated on the Google Cloud.
引用
收藏
页码:504 / 508
页数:5
相关论文
共 50 条
  • [21] Stabilizing inter-domain routing in the Internet
    Chen, Y
    Datta, AK
    Tixeuil, S
    EURO-PAR 2002 PARALLEL PROCESSING, PROCEEDINGS, 2002, 2400 : 749 - 752
  • [22] Enforcing convergence in inter-domain routing
    Cobb, JA
    Musunuri, R
    GLOBECOM '04: IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, VOLS 1-6, 2004, : 1353 - 1358
  • [24] A Secure Inter-domain Routing Protocol
    Wang, Na
    Wang, Binqiang
    2008 INTERNATIONAL SYMPOSIUM ON INTELLIGENT INFORMATION TECHNOLOGY APPLICATION, VOL II, PROCEEDINGS, 2008, : 780 - 785
  • [25] Stabilizing inter-domain routing in the Internet
    Chen, Y
    Datta, AK
    Tixeuil, S
    JOURNAL OF HIGH SPEED NETWORKS, 2005, 14 (01) : 21 - 37
  • [26] Inter-domain routing in optical networks
    Muchanga, A
    Wosinska, L
    Orava, F
    Haralson, J
    OPTICAL NETWORKS AND TECHNOLOGIES, 2005, 164 : 263 - 270
  • [27] DTIA: An Architecture for Inter-domain Routing
    Amaral, Pedro
    Bernardo, Luis
    Pinto, Paulo
    2009 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, VOLS 1-8, 2009, : 2102 - 2107
  • [28] Fault management of inter-domain routing
    Zhao, Yinxin
    Yin, Xia
    Wu, Jianping
    Yu, Bin
    2002, Press of Tsinghua University (42): : 60 - 63
  • [29] Inter-domain routing bottlenecks and their aggravation
    Yang, Yan
    Yin, Xia
    Shi, Xingang
    Wang, Zhiliang
    He, Jiong
    Fu, Tom Z. J.
    Winslett, Marianne
    COMPUTER NETWORKS, 2019, 162
  • [30] Inter-domain multipath routing protocols
    Su, Jin-Shu
    Dai, Bin
    Liu, Yu-Jing
    Peng, Wei
    Ruan Jian Xue Bao/Journal of Software, 2012, 23 (01): : 65 - 81