Securing Route Origin Authorization with Blockchain for Inter-Domain Routing

被引:0
|
作者
He, Guobiao [1 ]
Su, Wei [1 ]
Gao, Shuai [1 ]
Yue, Jiarui [1 ]
机构
[1] Beijing Jiaotong Univ, Sch Elect & Informat Engn, Beijing, Peoples R China
来源
2020 IFIP NETWORKING CONFERENCE AND WORKSHOPS (NETWORKING) | 2020年
关键词
BGP security; ROA; decentralized; tamper-proof; blockchain;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The inter-domain routing with BGP is highly vulnerable to malicious attacks, due to the lack of a secure means of verifying authenticity and legitimacy of inter-domain routes. Resource Public Key Infrastructure (RPKI) is a new security infrastructure to verify that an IP address block holder has authorized an Autonomous System (AS) to originate routes by maintaining a Route Origin Authorization (ROA) repository, preventing the most devastating prefix hijacks in BGP. However, RPKI is a centralized hierarchical architecture that may empower the centralized authorities to unilaterally revoke or compromise any IP prefixes under their control. To eliminate the risks of RPKI, we present ROAchain, a novel BGP security infrastructure based on blockchain. Different from RPKI, ROAchain is a decentralized architecture, in which each AS maintains a globally consistent and tamper-proof ROA repository, authenticating the legitimacy of route origin and preventing BGP prefix hijacks. In ROAchain, a novel consensus algorithm is proposed to guarantee the strong consistency, scalability, and security of the system. Moreover, an incremental deployment scheme is designed without changing the current BGP protocol. Finally, ROAchain is implemented in Golang and validated on the Google Cloud.
引用
收藏
页码:504 / 508
页数:5
相关论文
共 50 条
  • [31] Reputation for Inter-Domain QoS Routing
    Anceaume, Emmanuelle
    Busnel, Yann
    Lajoie-Mazenc, Paul
    Texier, Geraldine
    2015 IEEE 14TH INTERNATIONAL SYMPOSIUM ON NETWORK COMPUTING AND APPLICATIONS (NCA), 2015, : 142 - 146
  • [32] Inter-domain routing stability measurement
    Jiang, Y
    Doria, A
    Olsson, D
    HPSR 2002: WORKSHOP ON HIGH PERFORMANCE SWITCHING AND ROUTING, PROCEEDINGS: MERGING OPTICAL AND IP TECHNOLOGIES, 2002, : 42 - 46
  • [33] Inter-Domain Route Diversity for the Internet
    Misseri, Xavier
    Gojmerac, Ivan
    Rougier, Jean-Louis
    NETWORKING 2012 WORKSHOPS, 2012, 7291 : 63 - 71
  • [34] Distributed inter-domain link capacity optimization for inter-domain IP/MPLS routing
    Tomaszewski, Artur
    Pioro, Michat
    Mycek, Mariusz
    GLOBECOM 2007: 2007 IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, VOLS 1-11, 2007, : 1872 - +
  • [35] A Lightweight Decentralized Authorization Model for Inter-domain Collaborations
    Lee, Hannah K.
    Luedemann, Heiko
    SWS'07: PROCEEDINGS OF THE 2007 ACM WORKSHOP ON SECURE WEB SERVICES, 2007, : 83 - 89
  • [36] A novel routing verification approach based on blockchain for inter-domain routing in smart metropolitan area networks
    Liu, Yaping
    Zhang, Shuo
    Zhu, Haojin
    Wan, Peng-Jun
    Gao, Lixin
    Zhang, Yaoxue
    Tian, Zhihong
    JOURNAL OF PARALLEL AND DISTRIBUTED COMPUTING, 2020, 142 : 77 - 89
  • [37] Blockchain based Inter-domain Latency Aware Routing Proposal in Software Defined Network
    Arins, Andis
    2018 IEEE 6TH WORKSHOP ON ADVANCES IN INFORMATION, ELECTRONIC AND ELECTRICAL ENGINEERING (AIEEE), 2018,
  • [38] Blockchain-Based Self-Sovereign Identity for Routing in Inter-Domain Networks
    Zeydan, Engin
    Mangues, Josep
    Arslan, Suayb S.
    Turk, Yekta
    IEEE COMMUNICATIONS MAGAZINE, 2024, 62 (01) : 96 - 102
  • [39] Route Leak Identification: A Step Toward Making Inter-Domain Routing More Reliable
    Siddiqui, M. S.
    Montero, D.
    Yannuzzi, M.
    Serral-Gracia, R.
    Masip-Bruin, X.
    2014 10TH INTERNATIONAL CONFERENCE ON THE DESIGN OF RELIABLE COMMUNICATION NETWORKS (DRCN), 2014,
  • [40] A Distributed Scheme for Inter-Domain Routing Optimization
    Tomaszewski, Artur
    Pioro, Michal
    Mycek, Mariusz
    DRCN: 2007 6TH INTERNATIONAL WORKSHOP ON THE DESIGN OF RELIABLE COMMUNICATION NETWORKS, 2007, : 70 - 77