APVAS: Reducing Memory Size of AS_PATH Validation by Using Aggregate Signatures

08/31/2020
by   Ouyang Junjie, et al.
0

The BGPsec protocol, which is an extension of the border gateway protocol (BGP), uses digital signatures to guarantee the validity of routing information. However, BGPsec's use of digital signatures in routing information causes a lack of memory in BGP routers and therefore creates a gaping security hole in today's Internet. This problem hinders the practical realization and implementation of BGPsec. In this paper, we present APVAS (AS path validation based on aggregate signatures), a new validation method that reduces memory consumption of BGPsec when validating paths in routing information. To do this, APVAS relies on a novel aggregate signature scheme that compresses individually generated signatures into a single signature in two ways, i.e., in sequential and interactive fashions. Furthermore, we implement a prototype of APVAS on BIRD Internet Routing Daemon and demonstrate its efficiency on actual BGP connections. Our results show that APVAS can reduce memory consumption by 80% in comparison with the conventional BGPsec.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
04/01/2023

Pointcheval-Sanders Signature-Based Synchronized Aggregate Signature

Synchronized aggregate signature is a special type of signature that all...
research
11/06/2018

Digital Signature Security in Data Communication

Authenticity of access in very information are very important in the cur...
research
09/20/2023

Tropical cryptography III: digital signatures

We use tropical algebras as platforms for a very efficient digital signa...
research
07/31/2022

Nested Cover-Free Families for Unbounded Fault-Tolerant Aggregate Signatures

Aggregate signatures are used to create one short proof of authenticity ...
research
12/21/2022

Quotable Signatures for Authenticating Shared Quotes

Quotable signatures are digital signatures that allow a user to quote pa...
research
03/16/2019

On the classification and false alarm of invalid prefixes in RPKI based BGP route origin validation

BGP is the default inter-domain routing protocol in today's Internet, bu...
research
05/17/2023

Nowcasting with signature methods

Key economic variables are often published with a significant delay of o...

Please sign up or login with your details

Forgot password? Click here to reset