Suppr超能文献

利用公共区块链增强边界网关协议安全性。

Enhancing Border Gateway Protocol Security Using Public Blockchain.

机构信息

Faculty of Informatics and Information Technologies, Slovak University of Technology in Bratislava, Ilkovicova 2, 842 16 Bratislava, Slovakia.

出版信息

Sensors (Basel). 2020 Aug 11;20(16):4482. doi: 10.3390/s20164482.

Abstract

Communication on the Internet consisting of a massive number of Autonomous Systems (AS) depends on routing based on Border Gateway Protocol (BGP). Routers generally trust the veracity of information in BGP updates from their neighbors, as with many other routing protocols. However, this trust leaves the whole system vulnerable to multiple attacks, such as BGP hijacking. Several solutions have been proposed to increase the security of BGP routing protocol, most based on centralized Public Key Infrastructure, but their adoption has been relatively slow. Additionally, these solutions are open to attack on this centralized system. Decentralized alternatives utilizing blockchain to validate BGP updates have recently been proposed. The distributed nature of blockchain and its trustless environment increase the overall system security and conform to the distributed character of the BGP. All of the techniques based on blockchain concentrate on inspecting incoming BGP updates only. In this paper, we improve on these by modifying an existing architecture for the management of network devices. The original architecture adopted a private blockchain implementation of HyperLedger. On the other hand, we use the public blockchain Ethereum, more specifically the Ropsten testing environment. Our solution provides a module design for the management of AS border routers. It enables verification of the prefixes even before any router sends BGP updates announcing them. Thus, we eliminate fraudulent BGP origin announcements from the AS deploying our solution. Furthermore, blockchain provides storage options for configurations of edge routers and keeps the irrefutable history of all changes. We can analyze router settings history to detect whether the router advertised incorrect information, when and for how long.

摘要

互联网上的通信由大量自治系统(AS)组成,依赖于基于边界网关协议(BGP)的路由。路由器通常信任来自其邻居的 BGP 更新中的信息的真实性,就像许多其他路由协议一样。然而,这种信任使得整个系统容易受到多种攻击,例如 BGP 劫持。已经提出了许多增加 BGP 路由协议安全性的解决方案,大多数基于集中式公钥基础设施,但它们的采用相对较慢。此外,这些解决方案容易受到这个集中式系统的攻击。最近提出了利用区块链来验证 BGP 更新的去中心化替代方案。区块链的分布式性质和无需信任的环境提高了整体系统安全性,并符合 BGP 的分布式特点。所有基于区块链的技术都集中在检查传入的 BGP 更新上。在本文中,我们通过修改网络设备管理的现有架构来改进这些技术。原始架构采用了 Hyperledger 的私有区块链实现。另一方面,我们使用公共区块链以太坊,更具体地说是 Ropsten 测试环境。我们的解决方案为 AS 边界路由器的管理提供了模块设计。它能够在任何路由器发送通告前缀的 BGP 更新之前验证前缀。因此,我们消除了部署我们解决方案的 AS 中欺诈性的 BGP 起源通告。此外,区块链为边缘路由器的配置提供了存储选项,并保留了所有更改的不可辩驳的历史记录。我们可以分析路由器设置历史记录,以检测路由器何时何地错误地宣传了信息,以及持续了多长时间。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/5104/7472367/92da653bc3dd/sensors-20-04482-g001.jpg

相似文献

1
Enhancing Border Gateway Protocol Security Using Public Blockchain.
Sensors (Basel). 2020 Aug 11;20(16):4482. doi: 10.3390/s20164482.
2
Secure Inter-Domain Routing Based on Blockchain: A Comprehensive Survey.
Sensors (Basel). 2022 Feb 13;22(4):1437. doi: 10.3390/s22041437.
3
Design and Analysis of Optimization Algorithms to Minimize Cryptographic Processing in BGP Security Protocols.
Comput Commun. 2017 Jul;106:75-85. doi: 10.1016/j.comcom.2017.03.007. Epub 2017 Mar 24.
5
Blockchain-Based Authentication and Trust Management Mechanism for Smart Cities.
Sensors (Basel). 2022 Mar 29;22(7):2604. doi: 10.3390/s22072604.
6
A Blockchain-Based Trusted Edge Platform in Edge Computing Environment.
Sensors (Basel). 2021 Mar 18;21(6):2126. doi: 10.3390/s21062126.
7
Blockchain-Based Lightweight Trust Management in Mobile Ad-Hoc Networks.
Sensors (Basel). 2020 Jan 27;20(3):698. doi: 10.3390/s20030698.
8
A Survey of Advanced Border Gateway Protocol Attack Detection Techniques.
Sensors (Basel). 2024 Oct 3;24(19):6414. doi: 10.3390/s24196414.
9
Management and Monitoring of IoT Devices Using Blockchain .
Sensors (Basel). 2019 Feb 19;19(4):856. doi: 10.3390/s19040856.
10
Towards developing a secure medical image sharing system based on zero trust principles and blockchain technology.
BMC Med Inform Decis Mak. 2020 Oct 7;20(1):256. doi: 10.1186/s12911-020-01275-y.

引用本文的文献

1
Secure Inter-Domain Routing Based on Blockchain: A Comprehensive Survey.
Sensors (Basel). 2022 Feb 13;22(4):1437. doi: 10.3390/s22041437.
2
SAT and SMT-Based Verification of Security Protocols Including Time Aspects.
Sensors (Basel). 2021 Apr 27;21(9):3055. doi: 10.3390/s21093055.

本文引用的文献

1
Management and Monitoring of IoT Devices Using Blockchain .
Sensors (Basel). 2019 Feb 19;19(4):856. doi: 10.3390/s19040856.

文献AI研究员

20分钟写一篇综述,助力文献阅读效率提升50倍。

立即体验

用中文搜PubMed

大模型驱动的PubMed中文搜索引擎

马上搜索

文档翻译

学术文献翻译模型,支持多种主流文档格式。

立即体验