Method for Preventing BGP Man-in-the-Middle Attack Based on Certificate-Free Ordered Aggregation Signature

Through the key generation center and orderly aggregation signature technology of the certificate-free public key cryptography system, S-BGP cannot prevent multiple middlemen from conspiring attacks, and more efficient routing path verification and communication are achieved, reducing the cost of certificate management.

CN116015670BActive Publication Date: 2025-06-17FUJIAN NORMAL UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202211584113.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-09
Publication Date
2025-06-17
Estimated Expiration
2042-12-09

AI Technical Summary

Technical Problem

S-BGP technology cannot effectively prevent conspiring attacks from joint fraud by 2 or more middlemen, and there are performance bottlenecks due to the high computational overhead and storage cost of certificate verification.

Method used

The key generation center adopts a certificate-free public key cryptography system to generate public keys and private keys, and generate authentication codes and signatures for the EBGP routing path through orderly aggregation of signatures to prevent conspiracy attacks.

Benefits of technology

Effectively prevent BGP man-in-the-middle attacks, reduce the chance of routing path fraud, reduce communication overhead, improve verification efficiency, and reduce the computing and storage costs of certificate management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116015670B_ABST
    Figure CN116015670B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for preventing BGP man-in-the-middle attacks based on certificateless orderly aggregation signatures. The key generation center of the certificateless public key cryptosystem generates and manages public and private keys, and generates a neighbor relationship authentication code and an aggregation signature for the entire EBGP routing path for the EBGP routing path. To prevent collusion attacks, neighbor relationship verification and EBGP routing path aggregation signature verification are adopted. Among them, neighbor relationship verification can effectively reduce the probability of routing path forgery. EBGP routing path verification can not only prevent malicious routing domains from lurking in the routing prefix and routing path, but also prevent any two or more routing domains from participating in a collusion attack, resulting in downstream routing domains receiving false BGP update messages with lurking malicious routing domains.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security, and particularly to a method for preventing BGP man-in-the-middle attacks based on certificateless orderly aggregation signature. Background Art

[0002] The Border Gateway Protocol (BGP) is a protocol designed to exchange routing information for different autonomous systems (AS). It uses rich routing attributes such as AS_PATH, route origin, and local preference to provide the optimal path for communication between autonomous systems. Since BGP is currently the only routing protocol used to handle communication between autonomous systems on the Internet, its security is of great importance. In 2000, to address the security of BGP, the S-BGP technical solution emerged, but S-BGP still cannot cope with the collusion attacks of two or more man-in-the-middle parties jointly deceiving. Starting from analyzing the update messages of S-BGP, the collusion attack means of malicious man-in-the-middle parties against S-BGP are grasped.

[0003] As Figure 1 shown, when there is no malicious man-in-the-middle attack, in the update message after running S-BGP, AS1 generates the source authentication AA for 10.0.0.1 / 24 P , and at the same time uses the signature algorithm to generate the routing authentication RA for AS2 1-2 . AS1 adds AA P and RA 1-2 to the S-BGP update message and sends it to AS2. After receiving the routing announcement, AS2 performs source authentication. It determines the legal relationship between 10.0.0.1 / 24 and the autonomous system through the certification authority CA, and then verifies RA 1-2 . After passing the verification, AS2 modifies its own routing table according to the content of the update message, and at the same time uses the signature algorithm to generate the routing authentication RA for AS3 2-3 . AS2 adds AA P and RA 2-3 to the S-BGP update message and sends it to AS3. After receiving the routing announcement, AS3 updates its routing table and generates RA 3-4 . After receiving the routing announcement from AS3, AS4 verifies AA P and RA 3-4 . If the verification passes, it updates its own routing table; if the verification fails, it discards the announcement.

[0004] When two man-in-the-middle parties conduct malicious collusion attacks, AS1 and AS3 are the attackers, and the update message after running S-BGP is as Figure 1As shown in the figure. R1 in AS1 and R3 in AS3 establish a virtual link R1-R3 using tunneling technology. R1 and R3 establish a "real" neighbor relationship through the link tunnel AS1-AS3 to exchange routing data and establish an External Border Gateway Protocol (EBGP) neighbor relationship. AS1 generates a routing authentication RA for AS3 1-3 AS3 verifies the RA of AS2 2-3 and the RA of AS1 1-3 After AS4 receives the routing announcement from AS3, it verifies AA P and RA 3-4 .

[0005] AS4 stores all routing paths in the routing forwarding table and selects the best route according to the routing policy to generate a routing table. According to the AS_PATH routing selection principle of the BGP protocol, the forged path {AS3, AS1} is shorter than the real path {AS3, AS2, AS1}, and thus has a higher priority. Therefore, AS4 selects {AS3, AS1} to reach the routing prefix 10.0.0.1 / 24. Obviously, the routing updates exchanged between AS1 and AS3 are invisible to other ASs, and it is also unknown whether the routing updates are transmitted through the tunnel link. In this case, downstream ASs are likely to be attacked by the collusion of AS1 and AS3

[0006] Therefore, S-BGP has some disadvantages. (1) The S-BGP solution verifies the origin of the route by issuing certificates to each autonomous system through the public key infrastructure and makes it impossible for attackers to forge routing announcements through signature. Due to the large number of autonomous systems in the Internet, as the number of certificates increases, the receiver will pay a large computational overhead and storage cost when verifying the route. (2) S-BGP cannot cope with the collusion attack of two or more middlemen jointly deceiving Summary of the Invention

[0007] The purpose of the present invention is to provide a method for preventing BGP man-in-the-middle attacks based on certificateless ordered aggregation signature

[0008] The technical solution adopted by the present invention is as follows

[0009] A method for preventing BGP man-in-the-middle attacks based on certificateless ordered aggregation signature. The system adopted includes a key generation center of a certificateless public key cryptosystem, an authentication code and an ordered aggregation signature generation module, and an attack prevention verification module. The method includes the following steps

[0010] Step 1, initialization link: The key generation center generates a public key and a private key pair for each inter-domain routing domain, and calculates a digital signature for the routing prefix, that is, the aggregation signature of the present invention. The specific steps of Step 1 are as follows

[0011] Step 1-1, the system randomly generates a security parameter λ. The key generation center selects a large prime number q, selects an additive cyclic group (G, +) of order q composed of points on the elliptic curve and a multiplicative cyclic group (G T , ×) of order q, and a bilinear mapping e: G×G→G T ; M is a generator in the additive cyclic group G of the elliptic curve. Select a collision-resistant hash function: H1: {0, 1} * ×{0, 1}→G, H2: {0, 1} * →G, H3: {0, 1} * →G, where

[0012] Step 1-2, select a random number as the master secret key msk = a, calculate the system public key mpk = M a , and publish the system parameters {q, G, G T , e, M, mpk, H1, H2, H3, H4};

[0013] Step 1-3, set the identity ID0 of a virtual routing domain N0 to represent the routing prefix and interact with the key generation center and digitally sign the routing prefix number; for each routing domain N i where i = 1, 2,..., n, n is the total number of routing domains, and N1 is the source routing domain; N i corresponds to the autonomous system number m i ;

[0014] Step 1-4, each routing domain N i selects a random number as the partial private key, and sends the corresponding identity ID i and t i to the key generation center. The key generation center calculates g i,0 = H1(ID i , 0), g i,1 = H1(ID i , 1), then is used as the private key of N i , while pk i =(ID i , T i ) is used as the public key of N i ;

[0015] Step 1-5, when digitally signing the routing prefix P, first select the status information or one-time information and the initial value σ0 of the digital signature = (σ a , σb , s) = (1 G , 1 G , s), where 1 G is the identity element of the multiplicative cyclic group G T ;

[0016] Step 1 - 6, generate a random number Calculate the aggregated signature starting from the routing prefix P: and where is the private key of N0, M is the generator; W0 = H3(s || L0), || represents data concatenation, L0 = P || ID0, V = H2(s); c0 = H4(s || L0).

[0017] Step 2, Authentication code and ordered aggregated signature generation phase: Generate an authentication code for the neighbor relationship of the routing domain and an ordered aggregated signature for the routing path; The specific steps of Step 2 are as follows:

[0018] Step 2 - 1, Neighbor relationship authentication code generation: Send any routing domain N i and its relationship information Relation(N i+1 , N i , N i+1 ) to the key generation center;

[0019] Step 2 - 2, The key generation center determines whether there is a real neighbor relationship between each pair of routing domains N i , N i+1 on the physical link; If so, use the LSig algorithm to generate an authentication code for the neighbor relationship Relation(N i , N i+1 ) Otherwise, reject the generation of the authentication code for the neighbor relationship of routing domain N i ;

[0020] Step 2 - 3, Generate a corresponding random number for each routing domain N i (i = 1, 2,..., n, n is the total number of routing domains) and calculate iteratively starting from the digital signature / aggregated signature σ0 of the routing prefix P. The specific iterative formula is as follows:

[0021] L i = L i-1 || m i || ID i , V = H2(s), W i = H3(s || L i ), c i = H4(s || L i );)

[0022]

[0023]

[0024] Among them, || represents data concatenation, is the private key of N i , and M is the generator;

[0025] Step 2-4, the number of iterations is the total number n of routing domains, and the final result σ n of the iterative calculation is used as the ordered aggregated signature of the EBGP routing path order.

[0026] Step 3, signature verification link: Verify the neighbor authentication code pair and the EBGP routing path, and confirm the BGP update message after passing the verification.

[0027] Furthermore, it is necessary to perform neighbor authentication code pair and EBGP routing path verification, and only those that pass the verification can confirm the BGP update message. The specific verification steps of step 3 are as follows:

[0028] Step 3-1, each identification number {ID i} i=0,1,...n participating in the verification of the aggregated signature is different from each other, and the public key of each identification number calculated by the key generation center is correct. According to the rules of the autonomous system number, the plaintext (autonomous system number) {m i} i=0,1,...n participating in the verification of the aggregated signature is different from each other, and n is the total number of routing domains. Moreover, if any public key in the public key set {pk i =(ID i ,T i )} i=0,1,...n does not participate in the verification, the routing domain verification is invalid.

[0029] Step 3-2, neighbor relationship verification. In the present invention, the verification of the ordered aggregated signature is strictly in accordance with the public key of the EBGP routing path order, that is, P||ID0||m1| / ID1||...||m n ||ID n , || represents data concatenation, and n is the total number of routing domains. Therefore, the neighbor relationship verification determines the correctness of the OPEN message. For any routing domain N i , the neighbor relationship only needs to use the public key pk0 to verify the neighbor relationship authentication code of its neighbor routing domain N i-1 , that is, execute the signature verification algorithm and If the decrypted digital signature and are valid, it means that the neighbor routing domain N i-1If the neighbor authentication code pair passes the verification, then further use P||ID0||m1| / ID1||...||m n ||ID n to perform routing path verification.

[0030] Step 3-3, EBGP routing path verification. For the first routing domain N1, both the legality of the routing prefix and the legality of N1 (belonging to routing path verification) need to be verified in order to update the routing table. For each subsequent routing domain N i , both the legality of N i and the ordered aggregate signature need to be verified by P||ID0||m1| / ID1||...||m n ||ID n (n is the total number of routing domains). From {ID0, P, pk0=(ID0, T0)} using the routing prefix to {ID i , m i , pk i =(ID i , T i )} of each routing domain, i = 1, 2,... n, calculate and to check if they are equal. Here, M is the generator, s is the status information, V = H2(s), g i,0 = H1(ID i , 0), g i,1 = H1(ID i , 1), mpk is the system public key, W i = H3(s||L i ), c i = H4(s||L i ), || represents data concatenation, and e is the bilinear pair mapping. If they are not equal, it means the verification fails, and the routing path is rejected; if they are equal, the verification passes, and a routing advertisement is sent to the next domain. For example, the routing advertisement sent by N i includes option information A i to facilitate the signature verification in order, without omission, and without duplication for each routing domain (A i is the additional information P||ID0||m1| / ID1||...||m i ||ID i , || represents data concatenation, and n is the total number of routing domains).

[0031] Furthermore, the ordered aggregate signature verification is strictly based on the public keys in the EBGP routing path order, that is, P||ID0||m1| / ID1||...||m n ||ID n .

[0032] Specifically, a collusive attack causes the bilinear mapping values and to be unable to verify equality, thus detecting the existence of the attack and taking preventive measures; M is a generator, s is the status information, V = H2(s), g i , 0 = H1(ID i ), g i,1 = H1(ID i ), 1), mpk is the system public key, W i = H3(s || L i ), c i = H4(s || L i ), || represents data concatenation, n is the total number of routing domains, {q, G, G T , e, M, mpk, H1, H2, H3, H4} are the system public parameters.

[0033] The present invention adopts the above technical solutions. The key generation center of the certificateless public key cryptosystem generates and manages public keys and private keys, and generates a neighbor relationship authentication code and an aggregated signature for the entire EBGP routing path for the EBGP routing path; to prevent collusive attacks, neighbor relationship verification and EBGP routing path aggregated signature verification are adopted. Among them, neighbor relationship verification can effectively reduce the probability of routing path forgery. EBGP routing path verification can not only prevent malicious routing domains from lurking in the routing prefix, but also prevent any two or more routing domains from participating in collusive attacks, resulting in downstream routing domains receiving false BGP update messages with lurking malicious routing domains.

[0034] The deployment of the key generation center of the certificateless public key cryptosystem of the present invention is more convenient than the deployment of the public key infrastructure. The length of the aggregated signature is shorter than that of the signature of S-BGP, and the signature length is independent of the length of the EBGP routing path, which is more suitable for the Internet environment and greatly reduces the communication overhead. The aggregated signature is calculated once, shared on each EBGP routing domain and used unlimited times, and the computational complexity of verification is low, while a group of signatures is required in S-BGP.

[0035] The present invention verifies the identity of the routing source based on certificateless signatures and provides routing prefix authentication for it. The received routing domain must verify the permission of the source autonomous system to publish the routing prefix in the verification message, and add a neighbor authentication chain to the intermediate routing domain to verify the true neighbor relationship to prevent collusive attacks. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] The following further describes the present invention in detail with reference to the drawings and specific embodiments;

[0037] Figure 1 It is a schematic diagram of the S-BGP principle under a malicious man-in-the-middle collusive attack;

[0038] Figure 2 This is a schematic flowchart of the method for preventing BGP man-in-the-middle attacks based on certificateless ordered aggregation signatures of the present invention. Specific implementation manners

[0039] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application.

[0040] Compared with the traditional public key cryptosystem based on the public key infrastructure, the certificateless public key cryptosystem does not require public key certificates and eliminates the private key escrow problem in the identity-based system. However, in the certificateless public key cryptosystem, a trusted third-party key generation center is still required, which has the master key of the system. The function of the key generation center is to calculate the partial private key of the user according to the user's identity and the system master key and securely transmit it to the user. After securely receiving its own partial private key, the user then uses its own partial private key and a secret value randomly selected by itself to generate its own complete private key. The public key is calculated from its own secret value, identity, and system parameters and is published in a reliable manner. After that, it can use its own private key for decryption and signature.

[0041] As Figure 2 shown, the method for preventing BGP man-in-the-middle collusion attacks based on certificateless ordered aggregation signatures adopts functional components including: the key generation center of the certificateless public key cryptosystem, the updated routing module, the authentication code generation module, the verification module, etc. These functional components mainly work in three links: the initialization link, the authentication code and aggregation signature generation link, and the attack prevention verification link.

[0042] Initialization:

[0043] (1) The system randomly generates a security parameter λ. The key generation center selects a large prime number q, selects an additive cyclic group (G, +) of order q composed of points on the elliptic curve and a multiplicative cyclic group (G T , ×) of order q, and a bilinear mapping e: G × G → G T ; M is a generator in the additive cyclic group G of the elliptic curve. Select a collision-resistant hash function: H1: {0,1} * × {0,1} → G, H2: {0,1} * → G, H3: {0,1} * → G, where select a random number as the master key msk = a, calculate the system public key mpk = M a , and publish the system parameters {q, G, G T, e, M, mpk, H1, H2, H3, H4}。

[0044] (2) Set the identity ID0 of a virtual routing domain N0 to interact with the key generation center on behalf of the routing prefix and digitally sign the routing prefix. Each routing domain is N i (i = 1, 2,..., n, where n is the total number of routing domains), where N1 is the source routing domain, N i The corresponding autonomous system number is m i (i = 1, 2,..., n, where n is the total number of routing domains).

[0045] Each routing domain N i Select a random number As part of the private key, then send its own identity ID i And t i (i = 0, 1,..., n, where n is the total number of routing domains) to the key generation center. The key generation center calculates g i,0 = H1(ID i , 0), g i , 1 = H1(ID i , 1), Then As the private key of N i , and pk i =(ID i , T i ) As the public key of N i (i = 0, 1,..., n, where n is the total number of routing domains).

[0046] Authentication code and aggregated signature generation:

[0047] This link includes generating an authentication code for the neighbor relationship of the routing domain and generating an authentication code for the routing path.

[0048] (1) Neighbor relationship authentication code: Send the relationship information Relation(N i And its neighbor N i+1 ) to the key generation center. After verification by the key generation center, if there is no real neighbor relationship between each pair of routing domains N i , N i+1 ) on the physical link, then reject the generation of the authentication code for the neighbor relationship of the routing domain N i , N i+1 . Otherwise, use the LSig algorithm to generate an authentication code for the neighbor relationship Relation(N i , N i , N i+1 )

[0049] (2) Ordered Aggregation Signature of EBGP Routing Path Order:

[0050] ① When the virtual routing domain corresponding to the routing prefix P is N0 and aggregating and signing P, select the one-time information (When re-aggregating the name, s can be changed, also known as status information) The initial value of the digital signature σ0 = (σ a , σ b , s) = (1 G , 1 G , s), where 1 G is the identity element of the multiplicative cyclic group G T . Generate a random number Start calculating the aggregation signature from the routing prefix P: The calculation formula for each component is: L0 = P||ID0, V = H2(s), W0 = H3(s||L0), c0 = H4(s||L0), Here, || represents data concatenation, is the private key of N0, and M is the generator.

[0051] ② For each routing domain N i (i = 1, 2,..., n, n is the total number of routing domains), generate a random number Start iterative calculation in sequence from the authentication code of the routing prefix P: L i = L i-1 ||m i ||ID i , V = H2(s), W i = H3(s||L i ), c i = H4(s||L i ), Here, || represents data concatenation, is the private key of N i , and M is the generator. i = 1, 2,..., n, n is the total number of routing domains. The final result σ n of the iterative calculation is the ordered aggregation signature.

[0052] Prevention of Attack Verification:

[0053] To prevent attacks, neighbor authentication codes and EBGP routing path verification need to be carried out, and only those that pass the verification can update their own routing table information.

[0054] (1) Each identification number {ID i} i=0,1,...n participating in the verification of the aggregation signature is different from each other, and the public key of each identification number calculated by the key generation center is correct. According to the rules of the autonomous system number, the plaintext (autonomous system number) {mi} i=0,1,...n are different from each other, and n is the total number of routing domains. Moreover, for the public key set {pk i =(ID i , T i )} i=0,1,...n if any public key does not participate in the verification, the routing domain verification is invalid.

[0055] (2) Neighbor relationship verification: In the present invention, the ordered aggregate signature verification is strictly in accordance with the public keys in the order of the EBGP routing path, that is, P||ID0||m1| / ID1||...||m n ||ID n , || represents data concatenation, and n is the total number of routing domains. Therefore, the neighbor relationship verification determines the correctness of the OPEN message. For any routing domain N i , the neighbor relationship only needs to use the public key pk0 to verify the neighbor authentication code of its neighbor routing domain N i-1 , that is, execute the signature verification algorithms and If the decrypted digital signature and are valid, it means that the neighbor authentication code pair of the neighbor routing domain N i-1 passes the verification, and then further use P||ID0||m1| / ID1||...||m n ||ID n to perform the routing path verification.

[0056] (3) EBGP routing path verification: For the first routing domain N1, it is necessary to verify both the legality of the routing prefix and the legality of N1 (belonging to the routing path verification) to allow the routing table to be updated. For each subsequent routing domain N i , it is necessary to verify the legality of N i , and also verify whether the ordered aggregate signature passes by P||ID0||m1| / ID1||...||m n ||ID n (n is the total number of routing domains). From {ID0, P, pk0=(ID0, T0)} using the routing prefix to {ID i , m i , pk i =(ID i , T i )} of each routing domain, i = 1, 2,... n, calculate and whether they are equal. Here, M is the generator, s is the status information, V = H2(s), g i,0 = H1(ID i , 0), g i,1 = H1(ID i,1), mpk is the system public key, W i = H3(s||L i ), c i = H4(s||L i ), || represents data concatenation, and e is a bilinear pair mapping. If they are not equal, it means the verification fails, and the routing path is rejected; if they are equal, the verification passes, and a routing announcement is sent to the next domain, such as N i The routing announcement sent includes option information A i for non-repetitive signature verification in each routing domain (A i is additional information P||ID0||m1||ID1||...||m i ||ID i , || represents data concatenation, and n is the total number of routing domains).

[0057] The present invention adopts the above technical solution. The key generation center of the certificateless public key cryptosystem generates and manages public and private keys, generates a neighbor relationship authentication code and an aggregated signature for the entire EBGP routing path; to prevent collusion attacks, neighbor relationship verification and EBGP routing path aggregated signature verification are adopted. Among them, neighbor relationship verification can effectively reduce the probability of routing path forgery, and EBGP routing path verification can not only prevent malicious routing domains lurking in the routing prefix, but also prevent any two or more routing domains from participating in a collusion attack, resulting in downstream routing domains receiving false BGP update messages with lurking malicious routing domains.

[0058] The deployment of the key generation center of the certificateless public key cryptosystem of the present invention is more convenient than the deployment of the public key infrastructure. The length of the aggregated signature is shorter than that of the signature of S-BGP, and the signature length is independent of the length of the EBGP routing path, which is more suitable for the Internet environment and greatly reduces the communication overhead. The aggregated signature is calculated once, shared on each EBGP routing domain and used unlimited times, and the verification has a low computational complexity, while a group of signatures are required in S-BGP.

[0059] The present invention verifies the identity of the routing source based on certificateless signatures and provides routing prefix authentication for it. The received routing domain must verify the permission of the source autonomous system to publish the routing prefix in the verification message, and add a neighbor authentication chain to the intermediate routing domain to verify the true neighbor relationship and prevent collusion attacks.

[0060] Obviously, the described embodiments are some but not all of the embodiments of the present application. Without conflict, the embodiments in the present application and the features in the embodiments can be combined with each other. Generally, the components of the embodiments of the present application described and illustrated in the accompanying drawings here can be arranged and designed in various different configurations. Therefore, the detailed description of the embodiments of the present application is not intended to limit the scope of the present application claimed, but merely represents selected embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts fall within the scope of protection of the present application.

Claims

1. A method for preventing BGP man-in-the-middle attacks based on certificateless ordered aggregation signatures. The system used includes a key generation center of the certificateless public key cryptosystem, an authentication code, an ordered aggregation signature generation module, and an attack prevention verification module. It is characterized in that: The method includes the following steps: Step 1, initialization phase: The key generation center generates a public-private key pair for each inter-domain routing domain, and first digitally signs the routing prefix; Step 2, authentication code and ordered aggregate signature generation phase: Generate an authentication code for the neighbor relationship of the routing domain and an ordered aggregate signature for the routing path; Step 3, signature verification phase: Verify the neighbor authentication code pair and the EBGP routing path, and confirm the BGP update message after passing the verification. The specific verification steps of Step 3 are as follows: Step 3-1, each identification number participating in the verification of the aggregated signature {ID i} i=0,1,...n is different from each other, and the public key of each identification number calculated by the key generation center is correct; according to the rules of the autonomous system numbering, the autonomous system numbers {m i} i=0,1,...n participating in the verification of the aggregated signature are different from each other, and n is the total number of routing domains; moreover, if any public key in the public key set {pk i =(ID i , T i )} i=0,1,...n does not participate in the verification, the routing domain verification is invalid; Step 3-2, neighbor relationship verification: For any routing domain N i Verify the neighbor relationship of the neighbor routing domain N i-1 using the public key pk0 for its neighbor relationship authentication code, that is, execute the signature verification algorithm and When decrypting the aggregated signature and are valid, indicating that the neighbor authentication code pair of the neighbor routing domain N i-1 passes the verification; Step 3-3, perform EBGP routing path verification after passing the neighbor authentication code verification. The specific steps are as follows: Step 3-3-1, determine whether it is the first routing domain N1. If so, execute Step 3-3-2; otherwise, execute Step 3-3-3; Step 3-3-2, for the first routing domain N1, verify both the legality of the routing prefix and the legality of N1. After passing both verifications, update the routing table; Step 3-3-3, for each subsequent routing domain N i , verify both the legitimacy of N i , and verify whether the ordered aggregate signature passes by P||ID0||m1||ID1||...||m n ||ID n , where P represents the routing prefix and || represents data concatenation.

2. The method for preventing BGP man-in-the-middle attacks based on certificateless ordered aggregation signatures according to claim 1, characterized in that: The specific steps of Step 1 are as follows: Step 1-1, the system randomly generates a security parameter λ. The key generation center selects a large prime number q, and selects an additive cyclic group (G, +) of order q composed of points on the elliptic curve and a multiplicative cyclic group (G T , ×) of order q. The bilinear mapping e: G×G→G T ; M is a generator in the additive cyclic group G of the elliptic curve. Select collision-resistant hash functions: H1: {0, 1} * ×{0, 1}→G, H2: {0, 1} * →G, H3: {0, 1} * →G, H4: where Step 1-2, select a random number as the master secret key msk = a, and calculate the system public key mpk = M a , and publish the system parameters {q, G, G T , e, M, mpk, H1, H2, H3, H4}; Step 1-3, set the identity ID0 of a virtual routing domain N0 to interact with the key generation center on behalf of the routing prefix P and digitally sign the routing prefix; each routing domain is set to N i , i = 1, 2,..., n, where n is the total number of routing domains; among them, N1 is the source routing domain, N i The corresponding autonomous system number is m i , i = 1, 2,..., n, where n is the total number of routing domains; Steps 1-4, each routing domain N including the routing prefix P i , where i = 0, 1,..., n, n being the total number of routing domains; select a random number t i ∈Z q * as part of the private key, and send the corresponding identity ID i and t i to the key generation center. The key generation center calculates g i,0 = H1(ID i , 0), g i,1 = H1(ID i , 1), then serves as the private key of N i , while pk i = (ID i , T i ) serves as the public key of N i ; Steps 1-5, when aggregating signatures for the routing prefix P, first select the status information and the initial value σ0 of the aggregate signature = (σ a , σ b , s) = (1 G , 1 G , s), where 1 G is the identity element of the multiplicative cyclic group G T . Step 1-6, generate a random number Calculate the aggregated signature starting from the routing prefix P: and where is the private key of N0, M is the generator; W0 = H3(s||L0), || represents data concatenation, L0 = P||ID0, V = H2(s); c0 = H4(s||L0).

3. The method for preventing BGP man-in-the-middle attacks based on certificateless ordered aggregation signatures according to claim 2, characterized in that: The specific steps of Step 2 are as follows: Step 2-1, generation of neighbor relationship authentication code: Send any routing domain N i and its relationship information Relation(N i+1 with the corresponding neighbor N i ,N i+1 ) to the key generation center; Step 2-2, the key generation center determines whether there is a real neighbor relationship between each pair of routing domains N i and N i+1 on the physical link; If so, use the LSig algorithm to generate an authentication code for the neighbor relationship Relation(N i ,N i+1 ); Otherwise, reject the neighbor relationship of routing domain N i from generating an authentication code; Step 2-3, for each routing domain N i Generate a corresponding random number n is the total number of routing domains; starting from the aggregated signature σ0 of the routing prefix P, iterative calculations are performed in sequence. The specific iterative formula is as follows: L i = L i-1 ||m i ||ID i , V = H2(s), W i = H3(s||L i ), c i = H4(s||L i ); Among them, || represents data concatenation, is the private key of N i and M is the generator; Step 2-4, the number of iterations is the total number n of routing domains, and the final result σ of the iterative calculation n is used as the ordered aggregation signature of the EBGP routing path order.

4. The method for preventing BGP man-in-the-middle attacks based on certificateless ordered aggregation signatures according to claim 3, characterized in that: In step 3-3-3, from {ID0, P, pk0 = (ID0, T0)} using the routing prefix to {ID i , m i , pk i = (ID i , T i )} for i = 1, 2,... n, calculate and respectively to check if they are equal, where e is a bilinear pairing mapping; if they are not equal, it means the verification fails and the routing path is rejected; if they are equal, it means the verification passes and a routing advertisement is sent to the next domain.

5. The method for preventing BGP man-in-the-middle attacks based on certificateless ordered aggregation signatures according to claim 4, characterized in that: N i The sent routing advertisement includes option information A i , A i is additional information P||ID0||m1||ID1||...||m i ||ID i , || indicates data concatenation, and n is the total number of routing domains.