The Border Gateway Protocol (BGP) which is used to distribute routing information between autonomous systems (ASes), is a critical component of the Internet's routing infrastructure. BGP is highly vulnerable to a variety of malicious attacks, due to its lack of secure means of verifying the authenticity and authority of BGP control traffic. Secure BGP (S-BGP) addresses most of these security vulnerabilities by using a combination of IPsec, a new BGP path attribute containing “attestations,” and a public key infrastructure (PKI). This paper describes in detail this PKI and how it is used to support S-BGP, e.g., for verifying ownership of AS numbers and portions of the IP address space. This PKI embodies a number of unique features designed to support S-BGP security requirements and to facilitate automated access control management for the certificate and CRL repository used with S-BGP
Published in:
DARPA Information Survivability Conference & Exposition II, 2001. DISCEX '01. Proceedings
(Volume:1
)
Date of Conference: 2001