首页 | 本学科首页   官方微博 | 高级检索  
     检索      

穿越自治系统联盟的域间路由安全机制
引用本文:孔令晶,曾华燊,窦军,李耀.穿越自治系统联盟的域间路由安全机制[J].通信学报,2014,35(10):18-164.
作者姓名:孔令晶  曾华燊  窦军  李耀
作者单位:西南交通大学 信息科学与技术学院,四川 成都 610031
基金项目:国家自然科学基金资助项目(60773102);国家自然科学基金与中国工程院联合基金资助项目(U0970122)
摘    要:通过对SE-BGP (security enhanced BGP)的研究与分析,发现此方案不仅无法认证动态变化的跨联盟AS (autonomous system),也无法抵御其自身所发起的主动攻击。为了解决SE-BGP存在的安全问题,设计了二层跨联盟等级结构CAHS (cross-alliance hierarchical structure),基于CAHS结构,借鉴护照签证思想,利用递增散列——AdHASH (additive hash)的特性提出了一种跨联盟安全机制SCA-BGP(secure crossing alliance for BGP)。该机制具有更高的安全性,可以有效地认证跨联盟AS的身份及行为授权,还可对其所携带的信息进行安全验证。实验分析表明,SCA-BGP可以有效地减少所需证书的规模和额外的时间开销,具有更好的可扩展性和网络收敛性能。

关 键 词:SE-BGP  SCA-BGP  跨联盟AS  递增散列

Inter-domain routing security mechanism for crossing autonomous system alliance
Ling-jing KONG,Hua-xin ZENG,Jun DOU,Yao LI.Inter-domain routing security mechanism for crossing autonomous system alliance[J].Journal on Communications,2014,35(10):18-164.
Authors:Ling-jing KONG  Hua-xin ZENG  Jun DOU  Yao LI
Institution:School of Information Science and Technology,Southwest Jiaotong University,Chengdu 610031,China
Abstract:Through studying and analyzing SE-BGP (security enhanced BGP),it was found that it couldn’t validate the cross-alliance AS (autonomous system) and defense the self-launched active attack.To solve the security problems,two-layer cross-alliance hierarchical structure CAHS (cross-alliance hierarchical structure) was designed.Based on CAHS,using the idea of passport visa and the features of AdHASH (additive hash),a cross-alliance BGP security mechanism SCA-BGP (secure crossing alliance for BGP) was proposed.The mechanism has higher security,which is able to effectively validate the identities and behavior authorization of the cross-alliance AS as well as the message carried by them.The experiment results show that SCA-BGP can effectively reduce the certificate scale and extra time overhead to get better scalability and convergence performance.
Keywords:SE-BGP  SCA-BGP  cross-alliance AS  AdHASH
点击此处可从《通信学报》浏览原始摘要信息
点击此处可从《通信学报》下载免费的PDF全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号