论文标题
APVA:通过使用聚合签名降低AS \ _ Path验证的内存大小
APVAS: Reducing Memory Size of AS\_PATH Validation by Using Aggregate Signatures
论文作者
论文摘要
是边界网关协议(BGP)的扩展程序的\ textIt {BGPSEC}协议,使用数字签名来保证路由信息的有效性。但是,BGPSEC在路由信息中使用数字签名会导致BGP路由器中缺乏内存,因此在当今的互联网中造成了巨大的安全漏洞。这个问题阻碍了BGPSEC的实际实现和实施。在本文中,我们介绍APVA(作为基于聚合签名的路径验证),这是一种新的验证方法,可在验证路由信息中验证路径时减少BGPSEC的内存消耗。为此,APVA依赖于一种新型的聚集签名方案,该方案将单独生成的签名压缩为单个签名,以两种方式,即以顺序和交互式时尚。此外,我们在\ textit {bird Internet路由守护程序}上实现了APVA的原型,并证明了其在实际BGP连接上的效率。我们的结果表明,与常规BGPSEC相比,APVA可以将记忆消耗降低80 \%。
The \textit{BGPsec} protocol, which is an extension of the border gateway protocol (BGP), uses digital signatures to guarantee the validity of routing information. However, BGPsec's use of digital signatures in routing information causes a lack of memory in BGP routers and therefore creates a gaping security hole in today's Internet. This problem hinders the practical realization and implementation of BGPsec. In this paper, we present APVAS (AS path validation based on aggregate signatures), a new validation method that reduces memory consumption of BGPsec when validating paths in routing information. To do this, APVAS relies on a novel aggregate signature scheme that compresses individually generated signatures into a single signature in two ways, i.e., in sequential and interactive fashions. Furthermore, we implement a prototype of APVAS on \textit{BIRD Internet Routing Daemon} and demonstrate its efficiency on actual BGP connections. Our results show that APVAS can reduce memory consumption by 80\% in comparison with the conventional BGPsec.