Journal on Communications ›› 2014, Vol. 35 ›› Issue (10): 155-164.doi: 10.3969/j.issn.1000-436x.2014.10.018

• Papers • Previous Articles     Next Articles

Inter-domain routing security mechanism for crossing autonomous system alliance

Ling-jing KONG,Hua-xin ZENG,Jun DOU,Yao LI   

  1. School of Information Science and Technology,Southwest Jiaotong University,Chengdu 610031,China
  • Online:2014-10-25 Published:2017-06-14
  • Supported by:
    The National Natural Science Foundation of China;Chinese Academy of Engineering and the National Natural Science Foundation of China

Abstract:

Through studying and analyzing SE-BGP (security enhanced BGP),it was found that it couldn’t validate the cross-alliance AS (autonomous system) and defense the self-launched active attack.To solve the security problems,two-layer cross-alliance hierarchical structure CAHS (cross-alliance hierarchical structure) was designed.Based on CAHS,using the idea of passport visa and the features of AdHASH (additive hash),a cross-alliance BGP security mechanism SCA-BGP (secure crossing alliance for BGP) was proposed.The mechanism has higher security,which is able to effectively validate the identities and behavior authorization of the cross-alliance AS as well as the message carried by them.The experiment results show that SCA-BGP can effectively reduce the certificate scale and extra time overhead to get better scalability and convergence performance.

Key words: SE-BGP, SCA-BGP, cross-alliance AS, AdHASH

No Suggested Reading articles found!