Inter-domain routing security audit protection method and device based on RPKI encryption object

By introducing ForwardingCommitment (FC) encryption objects into RPKI, the routing table entries of inter-domain routers are security audited, which solves the problems of routing leakage and route hijacking in the BGP protocol, and realizes security audit and protection of BGP routing.

CN120017313AActive Publication Date: 2025-05-16TSINGHUA UNIVERSITY +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411992179.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-31
Publication Date
2025-05-16
Estimated Expiration
2044-12-31

Smart Images

  • Figure CN120017313A_ABST
    Figure CN120017313A_ABST
Patent Text Reader

Abstract

The invention discloses an inter-domain routing security auditing protection method and device based on an RPKI encryption object, and the method comprises the steps: adding a new encryption object Forwarding Committee (FC) in an RPKI, carrying out the security auditing of a routing table item of an inter-domain router through the synchronization of the encryption object with an RPKI storage library, removing a problematic routing table item, and carrying out the security auditing of the routing table item of the inter-domain router. According to the method, prefix hijacking protection of routing between autonomous domains and protection of ASPATH path attributes in a BGP-UPDATE message are realized, and routing leakage attacks are partially solved. According to the method and the device, security auditing can be performed on the routing table items of the inter-domain router, and prefix hijacking, path tampering and routing leakage attacks in the BGP routing are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer network information security technology, and in particular to an inter-domain routing security audit protection method, device, electronic device and storage medium based on RPKI encryption objects. Background Art

[0002] BGP, the full name of which is Border Gateway Protocol, is a dynamic routing protocol between autonomous systems (AS) currently used in the Internet. It is used to automatically exchange IP routing information and reachability information between different ASs. Its main function is to control inter-domain routing propagation and select the optimal route.

[0003] Although the BGP protocol plays a vital role in the Internet, its own security is difficult to guarantee. General BGP-related problems can be divided into two categories: route leakage and route hijacking. Route leakage is the propagation of one or more route announcements beyond their intended scope. This is when the BGP route learned from an AS to another AS violates the predetermined policy of the receiver, sender and / or an AS along the previous AS path. Route hijacking is usually an unauthorized route source that announces routes. Route hijacking can be divided into route prefix hijacking and route path tampering. The cause of route leakage or route hijacking may be unintentional administrator misconfiguration or malicious attackers launching network attacks. The results of these two routing problems may be path loops, route redirection or denial of service attacks.

[0004] BGPSec is used to solve the security problem of BGP. However, BGPSec requires all routers of routing entities on the path to sign and verify the prefix to ensure the correctness and integrity of the path. Therefore, its incremental deployment is difficult and the computational burden on routers is too heavy. Summary of the invention

[0005] The present application aims to solve one of the technical problems in the related art at least to some extent.

[0006] To this end, the first purpose of this application is to propose an inter-domain routing security audit protection method based on RPKI encryption objects, aiming to perform security audits on routing table entries of inter-domain routers and solve prefix hijacking, path tampering and routing leakage attacks in BGP routing.

[0007] The second objective of this application is to propose an inter-domain routing security audit protection device based on RPKI encryption objects.

[0008] The third objective of the present application is to provide an electronic device.

[0009] A fourth objective of the present application is to provide a computer-readable storage medium.

[0010] To achieve the above-mentioned purpose, the first embodiment of the present application proposes an inter-domain routing security audit protection method based on RPKI encryption objects, including:

[0011] When the first routing entity makes a routing announcement, a first encrypted object is generated through a router request of the first routing entity and stored in the RPKI repository;

[0012] After the router of the first routing entity sends the routing announcement, the routing entities on the routing path receive the routing announcement in order according to the receiving sequence;

[0013] After receiving the route announcement, the router of the current priority routing entity obtains the encrypted objects generated by all routing entities before the current priority for verification to verify whether the message information of the received route announcement is authorized;

[0014] After verification, the router of the current routing entity generates an encrypted object corresponding to the current routing entity and stores it in the RPKI repository to authorize the subsequent routing entities on the routing path to forward the routing announcement;

[0015] The routing announcement is transmitted in sequence according to the order of reception of the routing entities on the routing path, until the last routing entity receives the encrypted objects generated by all the previous routing entities and verifies the passing of the routing announcement.

[0016] Among them, the first encrypted object indicates that the first routing entity authorizes the routing entities on the preset routing path to announce the routing declaration information; the encrypted object corresponding to the current-order routing entity indicates that the current-order routing entity authorizes the routing entities on the preset routing path to announce the routing declaration information; the message type contained in the routing declaration message corresponds to the certificate of the encrypted object, and the number of encrypted objects generated by the routing entity is equal to the number of message types contained in the routing declaration message.

[0017] After receiving the route announcement, the router of the current priority routing entity obtains the encrypted object generated by the previous priority routing entity to verify whether the message information of the route announcement is authorized. If the authorization is not passed, the route announcement message is discarded.

[0018] Among them, the router of each hop routing entity on the path will verify the existing encryption object and generate a new encryption object according to the direction of the routing announcement to avoid routing path tampering hijacking attacks.

[0019] The routing announcement message is a BGP-UPDATE message, and the BGP-UPDATE message includes a routing address prefix of each routing entity on a preset routing path.

[0020] The routing entity at the previous order on the preset routing path announces its own routing entity routing address prefix to the routing entity at the next order through routing announcement.

[0021] Among them, the router of the routing entity in the latter order obtains the encrypted objects stored by all the routing entities in the previous order from the RPKI repository, verifies the certificate signature information of each encrypted object, and if the verification is passed, it means that the routing announcement has not been hijacked and can continue to be received and announced; otherwise, it means that there is a problem with the routing announcement and the message needs to be discarded.

[0022] To achieve the above-mentioned purpose, the second embodiment of the present application proposes an inter-domain routing security audit protection device based on RPKI encryption objects, including:

[0023] A first encryption object signing module, configured to generate a first encryption object through a router request of the first routing entity when the first routing entity makes a routing announcement, and store the first encryption object in the RPKI repository;

[0024] A receiving module, configured to receive the routing announcements in order according to a receiving sequence by the routing entities on the routing path after the router of the first routing entity sends the routing announcements;

[0025] The verification module is used for the router of the current priority routing entity to obtain the encrypted objects generated by all routing entities before the current priority for verification after receiving the routing announcement, so as to verify whether the message information of the received routing announcement is authorized;

[0026] The authorization module is used for, after the verification is passed, the router of the current priority routing entity generates an encrypted object corresponding to the current priority routing entity and stores it in the RPKI repository, so as to authorize the subsequent priority routing entity on the routing path to forward the routing announcement;

[0027] The loop module is used to transmit the routing announcement in sequence according to the receiving order of the routing entities on the routing path, until the last routing entity receives the encrypted objects generated by all the routing entities in the previous order and verifies the passing of the routing announcement.

[0028] To achieve the above-mentioned purpose, the third aspect of the present application provides an electronic device, including: a processor, and a memory communicatively connected to the processor;

[0029] Memory stores computer-executable instructions;

[0030] The processor executes the computer-executable instructions stored in the memory to implement the method of the aforementioned technical solution.

[0031] To achieve the above-mentioned purpose, the fourth aspect embodiment of the present application proposes a computer-readable storage medium, in which computer execution instructions are stored. When the computer execution instructions are executed by a processor, they are used to implement the method as the aforementioned technical solution.

[0032] Different from the prior art, the present invention provides a method, device, electronic device and storage medium for inter-domain routing security audit protection based on RPKI encrypted objects. The method adds a new encrypted object ForwardingCommitment (FC) to RPKI, uses the encrypted object to synchronize with the RPKI repository, performs security audits on the routing table items of the inter-domain routers, removes problematic routing table items, implements prefix hijacking protection for autonomous inter-domain routing and protection of the AS_PATH path attribute in the BGP-UPDATE message, and partially solves routing leakage attacks. Through the present invention, it is possible to perform security audits on the routing table items of the inter-domain routers, and solve prefix hijacking, path tampering and routing leakage attacks in BGP routing.

[0033] Additional aspects and advantages of the present application will be given in part in the description below, and in part will become apparent from the description below, or will be learned through the practice of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] Figure 1 It is a flow chart of an inter-domain routing security audit protection method based on RPKI encryption objects provided by the present invention.

[0035] Figure 2 It is a schematic diagram of the architecture of RPKI in an inter-domain routing security audit protection method based on RPKI encryption objects provided by the present invention.

[0036] Figure 3 It is a schematic diagram of BGP routing prefix hijacking in an inter-domain routing security audit protection method based on RPKI encryption objects provided by the present invention.

[0037] Figure 4 It is a schematic diagram of BGP routing path tampering in an inter-domain routing security audit protection method based on RPKI encryption objects provided by the present invention.

[0038] Figure 5 It is a schematic diagram of a BGP route leakage attack in an inter-domain route security audit protection method based on RPKI encryption objects provided by the present invention.

[0039] Figure 6 It is a schematic diagram of the eContent content of the BM encryption object in the inter-domain routing security audit protection method based on the RPKI encryption object provided by the present invention.

[0040] Figure 7 The present invention provides a schematic diagram of a route UPDATE announcement processing flow of a single BGP router in an inter-domain route security audit protection method based on an RPKI encryption object.

[0041] Figure 8 It is a schematic diagram of an actual case of an inter-domain routing security audit protection method based on RPKI encryption objects provided by the present invention.

[0042] Fig. 9 It is a structural schematic diagram of an inter-domain routing security audit protection device based on RPKI encryption objects provided by the present invention. DETAILED DESCRIPTION

[0043] The embodiments of the present application are described in detail below, and examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to be used to explain the present application, and should not be construed as limiting the present application.

[0044] The following describes an inter-domain routing security audit protection method and device based on RPKI encryption objects in an embodiment of the present application with reference to the accompanying drawings.

[0045] Figure 1 A flowchart of an inter-domain routing security audit protection method based on RPKI encryption objects provided in an embodiment of the present application. The method comprises the following steps:

[0046] S101: When a first routing entity makes a routing announcement, a first encryption object certificate is signed through a router request of the first routing entity, and a first encryption object is generated and stored in an RPKI repository.

[0047] The first encryption object certificate indicates that the first routing entity authorizes the routing entity on the preset routing path to notify the routing announcement information.

[0048] In the embodiment of the present invention, AS represents the routing entity, RP represents the relying party, and FC represents that ForwardingCommitment is an encryption object to be newly added to RPKI.

[0049] When the router R1 of the first routing entity AS1 announces the route to its neighbors and broadcasts the BGP-UPDATE message, R1 generates a corresponding first encrypted object. The first encrypted object involved in the present invention, and the encrypted objects generated by subsequent routing entities, are all FC encrypted objects and are placed in the RPKI repository. The certificate of the first encrypted object is self-signed by R1 and uploaded to the RPKI repository for synchronization and download by other RPs. The first encrypted object is verified by the RP to prove its correctness. Specifically, the certificate of the first encrypted object indicates that AS1 authorizes its neighbors to announce a certain IP address prefix, how many IP address prefixes are in the BGP-UPDATE message, and the routing entity corresponding to each IP address prefix generates an encrypted object and signs the certificate accordingly. The architecture of RPKI is as follows: Figure 2 shown.

[0050] In practical applications, routing prefix hijacking attacks such as Figure 3 As shown, AS3's router R3 received two announcements for the same routing prefix. Since the routing prefix announced by AS4 is longer, according to the BGP routing rules, AS4 is selected as the best route, and the hijacking is successful.

[0051] Routing path tampering attack Figure 4 As shown, AS3's router R3 received two announcements for the same routing prefix. Since the AS_PATH path announced by AS4 is shorter, according to the BGP routing rules, AS4 is selected as the best route, and the hijacking is successful.

[0052] Route leakage attacks such as Figure 5 As shown in the figure, this is an example of route leakage. The relationships between ASs are Provider-Customer (P2C), Peer-Peer (P2P), and Sibling-Sibling (S2S). The principles to be followed when configuring route announcement rules are:

[0053] Announce to a Provider: When a Customer announces routing information to its Provider, the AS serving as the Customer can output its own routes and the routes of its Customers, but cannot output routes obtained from other Providers or Peers.

[0054] Announce to a Customer: When a Provider announces routing information to its Customer, the AS acting as a Provider can announce its own routes and its Customer's routes, or it can output routes obtained from other Providers or Peers.

[0055] Announce to a Peer: When exchanging routing information with a Peer, you can announce your own routes and Customer's routes, but you cannot output routes obtained from other Providers or Peers.

[0056] The routing strategy between ASs needs to be based on the No-Valley criterion, which estimates the direction of routing information exchange in Provider-Customer and Peer-Peer relationships:

[0057] Principle 1: There is at most one P2P connection in an AS path;

[0058] Rule 2: If there is a P2C connection in an AS path, it cannot be followed by a C2P connection, but only by a P2C or S2S connection.

[0059] Principle 3: A P2C connection cannot be a P2P connection;

[0060] Principle 4: A P2P connection cannot be a C2P connection, it can only be a P2C or S2S connection.

[0061] According to the No-Valley standard, RFC7908 classifies BGP route leaks as follows:

[0062] The AS announces the routes received from the provider to other providers (P2C followed by C2P);

[0063] The AS announces the routes received from the peer to other peers; (P2P followed by P2P);

[0064] The AS advertises the routes received from the provider to its peers; (P2C followed by P2P);

[0065] The AS advertises the routes received from its peers to its providers (P2P followed by C2P).

[0066] RPKI is short for Resource Public Key Infrastructure. RPKI is a resource public key infrastructure built around the right to use Internet digital resources, including IP and ASN. The purpose of RPKI is to make Internet routing more secure. RPKI mainly consists of three parts: public key infrastructure, cryptographic signature objects, and distributed repositories. RPKI allows holders of Internet digital resources to make verifiable statements about how their resources are used. To achieve this, it uses a public key infrastructure that creates a resource certificate chain with the same structure as the way IP addresses and numbers are passed. Currently, RPKI is used by the legitimate owner of an IP address block to make a certification statement, which is used to indicate which AS the IP prefix in BGP belongs to. This certification statement is called Route Origin Authorization (ROA), which contains a prefix, a maximum prefix length, and the source AS number, which is used to authorize the source AS to announce the IP address prefix. Afterwards, other network operators can download and verify these statements from the distributed repository of RPKI and make routing decisions based on them. This process is called Route Origin Validation (ROV).

[0067] BGPSec is used to solve the security problem of BGP. However, BGPSec requires all AS routers on the path to sign and verify the prefix to ensure the correctness and integrity of the path. Therefore, its incremental deployment is difficult and the computational burden on routers is too heavy.

[0068] The content of the eContent of the FC encryption object designed by the method of the present invention is as follows Figure 6 In step S101, when the BGP router R1 of the first routing entity AS1 performs BGP-UPDATE route announcement, it first generates an FC encryption object for the BGP-UPDATE message, which includes a signed certificate to authorize the next routing entity AS to continue to announce the IP address prefix, and at the same time prove the origin of the IP address prefix, and put the FC encryption object into the RPKI repository.

[0069] S102: After the router of the first routing entity sends the routing announcement, the routing entities on the routing path receive the routing announcement in sequence according to a receiving order.

[0070] In the embodiment of the present invention, the encrypted object corresponding to the current-order routing entity indicates that the current-order routing entity authorizes the routing entity on the preset routing path to notify the routing announcement information.

[0071] The message type included in the routing announcement message corresponds to the certificate of the encryption object, and the number of encryption objects generated by the routing entity is equal to the number of message types included in the routing announcement message.

[0072] The router of each hop routing entity on the path will verify the certificate of the existing encryption object and generate a new encryption object according to the direction of the routing announcement to avoid routing path tampering hijacking attacks.

[0073] After AS1's router R1 generates an encryption object with a self-signed certificate and places it in the RPKI repository, R1 will send a BGP-UPDATE message to AS2's router R2, which is the first routing entity on its routing path. This FC encryption object is recorded as FC{1,2}. R1 announces it to AS2's router R2 through a BGP-UPDATE message based on its own routing policy.

[0074] S103: After receiving the routing announcement, the router of the routing entity in the current order obtains the encrypted objects generated by all routing entities before the current order for verification, so as to verify whether the received message information of the routing announcement is authorized.

[0075] Continuing from the previous step, after receiving the BGP-UPDATE message, AS2's router R2 first obtains the FC encryption object FC{1,2} from the RPKI repository based on the BGP-UPDATE path information, and uses the public key therein to verify the signature information in the certificate of FC{1,2} to verify whether the current BGP-UPDATE message information is authorized; if the verification is successful, it means that the route announcement has not been hijacked and can continue to be received and announced; otherwise, it means that there is a problem with the route announcement and the message needs to be discarded.

[0076] S104: After the verification is passed, the router of the current priority routing entity generates an encrypted object corresponding to the current priority routing entity and stores it in the RPKI repository to authorize the subsequent priority routing entity on the routing path to forward the routing announcement.

[0077] If the verification passes, R2 uses its own private key to sign the new FC encryption object FC{2,3} according to its own routing policy, authorizes the next-order routing entity AS3 to continue to announce the IP routing prefix, and continues to announce BGP-UPDATE to the router R3 of its next-order routing entity AS3 according to step S102; otherwise, the message is discarded.

[0078] S105: The routing announcement is transmitted in sequence according to the receiving order of the routing entities on the routing path, until the last routing entity receives the encrypted objects generated by all the previous routing entities and verifies that the routing announcement has been passed.

[0079] Specifically, after receiving the BGP-UPDATE message, router R3 of the second-ranked routing entity AS3 obtains the current path AS_PATH as 2,1 from the UPDATE message, obtains the FC encryption objects FC{2,3} and FC{1,2} from the RPKI repository, and uses the public key information therein to perform signature verification on the FC encryption objects; if the verification passes, continue to sign the FC encryption object FC{3,i} and put it into the RPKI repository, and send the BGP-UPDATE message; otherwise, the message is discarded.

[0080] It should be noted that the i in FC{3, i} does not refer to a specific AS. It refers to a next-hop route of 3. If the route is not announced from AS3, then there is no need to sign the certificate. If there are not only three AS hops, but as long as the route announcement can be transmitted to N+1 hops, then there should be corresponding N FC encryption objects generated.

[0081] The remaining ASs on the path continue BGP-UPDATE notification and FC verification according to step S103 and step S104. After the BGP route converges, BGP route hijacking protection and route leakage detection can be achieved.

[0082] In the embodiment of the present invention, the BGP router of each routing entity in the next order needs to make a routing announcement to the routing entity in the next order. Before that, the router of the routing entity in the next order needs to sign and authenticate the route in the BGP-UPDATE, generate a new FC encryption object and put it into the RPKI repository.

[0083] The processing flow of the present invention on a single BGP router is as follows: Figure 7 If the router is the router of the routing entity to which the source prefix belongs, that is, the starting routing entity of the routing prefix, then the router does not need to perform the operations of steps ①②③ in the figure, that is, it does not need to wait for receiving BGP-UPDATE message information, does not need to obtain the FC encryption object list from the RPKI repository, and does not need to verify the FC encryption object. It can directly perform the operations of steps ④⑤ in the figure.

[0084] The following is a specific embodiment of the present invention. The example topology of the BGP-UPDATE announcement used in the present invention is as follows: Figure 8 As shown, the subsequent implementation methods and their explanations are all referred to Figure 8 conduct.

[0085] The FC encryption object of the present invention complies with the encryption object template designed by RFC 6488, wherein the eContent content of the FC encryption object is as follows: Figure 5 The fields are explained as follows:

[0086] version: is the current FC version number, the default is 0;

[0087] ASID: is the number of the AS to which the prefix of the FC belongs;

[0088] prefix: is the prefix content corresponding to the FC, which needs to indicate the address family, that is, IPv4 or IPv6 address prefix. Therefore, it contains three parts: IP address family identifier (1 is IPv4 address, 2 is IPv6 address), IP address, and prefix length.

[0089] FCID: It is the unique identifier of FC and is used to uniquely locate an FC encryption object in RPKI. It is a HASH result, and the HASH content is the prefix field, the current AS_PATH path information, and the next hop AS number.

[0090] FCSIG: FC signature information. Contains SKI for identifying the public key, and SigValue is the specific signature information.

[0091] This example simplifies the operations within the routing entity AS. This is because although there may be multiple BGP routers within a routing entity AS, the functions they play are actually the same and no more operations are required, so it can be simplified. The BGP router R1 of the first routing entity AS1 is about to announce the route to the BGP router R2 of the first-priority routing entity AS2. It needs to generate FC{1,2} first and put it into the RPKI repository. Assume that the routing prefix announced by R1 is 192.0.2.0 / 24, ASID is 1, FCID is HASH(192.0.2.0 / 24,{1},2), and FCSIG is filled in as needed. The public and private keys of the BGPSec router can be used to generate the public and private keys of the FC encryption object of the present invention. For details, please refer to RFC 8209, which will not be repeated here.

[0092] This embodiment declares BGP-UPDATE message information and performs related processing according to the BGP UPDATE message update mode. The present invention does not modify the BGP-UPDATE message format and processing flow.

[0093] The present invention requires RP to obtain all FC encryption objects from the RPKI repository. This can be divided into online processing and offline processing. Online processing requires the BGP router to immediately obtain and verify the relevant FC encryption objects from the RPKI repository after receiving the BGP-UPDATE message. This processing method has high latency requirements and is difficult to implement in the current RPKI validator implementation; offline processing is that the BGP router first processes the BGP-UPDATE message and updates the routing table items. When the RP synchronizes to the relevant FC encryption objects from the repository of the Trust Anchor of the RPKI, it will audit and remove illegal routing table items. This method has relatively low latency requirements and basically does not affect the routing convergence speed of the BGP router. Regardless of the method, the BGP router is required to obtain the routing prefix (here is 192.0.2.0 / 24), the current AS_PATH information (here is {1}), and the next hop AS number (here is 2) from the BGP-UPDATE message or the routing table item to verify the FC encryption object FC{1,2} and verify it. If the verification is successful, proceed to the subsequent steps; otherwise, discard the BGP-UPDATE message or routing table entry.

[0094] The BGP router R2 of the first-rank routing entity AS2 has verified that FC{1,2} has been passed, and the routing prefix 192.0.2.0 / 24 needs to be announced to the BGP router R3 of the second-rank routing entity AS3 through the BGP-UPDATE message. Before this, the FC encryption object FC{2,3} needs to be generated and put into the RPKI repository. Then the routing prefix is ​​192.0.2.0 / 24, the ASID is the starting routing source 1 of the routing prefix, the FCID is HASH(192.0.2.0 / 24,{1,2},3), and the FCSIG is filled in as needed.

[0095] The BGP-UPDATE message information is announced and related processing is performed according to the UPDATE message update mode of BGPv4. The present invention does not modify the BGP-UPDATE message format and processing flow.

[0096] The BGP router R3 of the second-rank routing entity AS3 received the BGP-UPDATE message from R2, in which AS_PATH is {2, 1}. R3 needs to verify two FC encryption objects, namely FC{1,2} and FC{2,3}. It obtains the two FC encryption object lists through FCID. After successful acquisition, it verifies the SigValue value of FCSIG. After the verification is passed, the route in the BGP-UPDATE message is updated into the routing table of BGP router R3. There are two scenarios of online processing and offline processing here, which will not be repeated.

[0097] Fig. 9 A schematic diagram of the structure of an inter-domain routing security audit protection device based on RPKI encryption objects provided in an embodiment of the present application.

[0098] like Fig. 9 As shown, the device 300 includes:

[0099] A first encryption object signing module 310 is used to generate a first encryption object through a router request of the first routing entity when the first routing entity makes a routing announcement, and store it in the RPKI repository;

[0100] A receiving module 320, configured to, after the router of the first routing entity sends the routing announcement, the routing entities on the routing path receive the routing announcement in sequence according to a receiving order;

[0101] Verification module 330, for the router of the current priority routing entity to obtain the encrypted objects generated by all routing entities before the current priority for verification after receiving the routing announcement, so as to verify whether the received message information of the routing announcement is authorized;

[0102] The authorization module 340 is used for, after the verification is passed, the router of the current priority routing entity generates an encrypted object corresponding to the current priority routing entity and stores it in the RPKI repository, so as to authorize the subsequent priority routing entity on the routing path to forward the routing announcement;

[0103] The loop module 350 is used to transmit the routing announcement in sequence according to the receiving order of the routing entities on the routing path, until the last routing entity receives the encrypted objects generated by all the previous routing entities and verifies that the routing announcement has been passed.

[0104] In order to implement the above embodiments, the present application also proposes an electronic device, comprising: a processor, and a memory communicatively connected to the processor; the memory stores computer-executable instructions; the processor executes the computer-executable instructions stored in the memory to implement the method provided by the above embodiments.

[0105] In order to implement the above embodiments, the present application also proposes a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, they are used to implement the methods provided by the above embodiments.

[0106] In order to implement the above embodiments, the present application also proposes a computer program product, including a computer program, which implements the methods provided by the above embodiments when executed by a processor.

[0107] The collection, storage, use, processing, transmission, provision and disclosure of user personal information involved in this application are in compliance with relevant laws and regulations and do not violate public order and good morals.

[0108] It should be noted that personal information from users should be collected for legitimate and reasonable purposes and should not be shared or sold outside of these legitimate uses. In addition, such collection / sharing should be carried out after receiving the user's informed consent, including but not limited to notifying the user to read the user agreement / user notice and sign the agreement / authorization including authorization of relevant user information before the user uses the function. In addition, any necessary steps should be taken to protect and safeguard access to such personal information data and ensure that others who have access to personal information data comply with its privacy policy and procedures.

[0109] The present application is expected to provide an implementation scheme for users to selectively block the use or access of personal information data. That is, the present disclosure is expected to provide hardware and / or software to prevent or block access to such personal information data. Once the personal information data is no longer needed, the risk can be minimized by limiting data collection and deleting the data. In addition, when applicable, such personal information is de-identified to protect the privacy of the user.

[0110] In the description of the aforementioned embodiments, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art may combine and combine the different embodiments or examples described in this specification and the features of the different embodiments or examples, without contradiction.

[0111] In addition, the terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined as "first" and "second" may explicitly or implicitly include at least one of the features. In the description of this application, the meaning of "plurality" is at least two, such as two, three, etc., unless otherwise clearly and specifically defined.

[0112] Any process or method description in a flowchart or otherwise described herein may be understood to represent a module, fragment or portion of code comprising one or more executable instructions for implementing the steps of a custom logical function or process, and the scope of the preferred embodiments of the present application includes alternative implementations in which functions may not be performed in the order shown or discussed, including performing functions in a substantially simultaneous manner or in the reverse order depending on the functions involved, which should be understood by technicians in the technical field to which the embodiments of the present application belong.

[0113] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by an instruction execution system, device or apparatus (such as a computer-based system, a system including a processor, or other system that can fetch instructions from an instruction execution system, device or apparatus and execute the instructions), or in combination with these instruction execution systems, devices or apparatuses. For the purpose of this specification, "computer-readable medium" can be any device that can contain, store, communicate, propagate or transmit a program for use by an instruction execution system, device or apparatus, or in combination with these instruction execution systems, devices or apparatuses. More specific examples of computer-readable media (a non-exhaustive list) include the following: an electrical connection with one or more wires (electronic device), a portable computer disk box (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), a fiber optic device, and a portable compact disk read-only memory (CDROM). In addition, the computer-readable medium may even be paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium and then editing, interpreting or processing in other suitable ways if necessary, and then stored in a computer memory.

[0114] It should be understood that the various parts of the present application can be implemented by hardware, software, firmware or a combination thereof. In the above-mentioned embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, it can be implemented by any one of the following technologies known in the art or their combination: a discrete logic circuit having a logic gate circuit for implementing a logic function for a data signal, a dedicated integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.

[0115] A person skilled in the art may understand that all or part of the steps in the method for implementing the above-mentioned embodiment may be completed by instructing related hardware through a program, and the program may be stored in a computer-readable storage medium, which, when executed, includes one or a combination of the steps of the method embodiment.

[0116] In addition, each functional unit in each embodiment of the present application may be integrated into a processing module, or each unit may exist physically separately, or two or more units may be integrated into one module. The above-mentioned integrated module may be implemented in the form of hardware or in the form of a software functional module. If the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it may also be stored in a computer-readable storage medium.

[0117] The storage medium mentioned above may be a read-only memory, a magnetic disk or an optical disk, etc. Although the embodiments of the present application have been shown and described above, it can be understood that the above embodiments are exemplary and cannot be understood as limiting the present application. A person of ordinary skill in the art may change, modify, replace and modify the above embodiments within the scope of the present application.

Claims

1. A method for protecting inter-domain routing security audit based on RPKI encryption objects, characterized in that: include: When the first routing entity makes a routing announcement, a first encrypted object is generated through a router request of the first routing entity and stored in the RPKI repository; After the router of the first routing entity sends the routing announcement, the routing entities on the routing path receive the routing announcement in sequence according to the receiving order; After receiving the routing announcement, the router of the routing entity of the current priority obtains the encrypted objects generated by all routing entities before the current priority for verification, so as to verify whether the message information of the received routing announcement is authorized; After the verification is passed, the router of the current priority routing entity generates an encrypted object corresponding to the current priority routing entity and stores it in the RPKI repository to authorize the subsequent priority routing entity on the routing path to forward the routing announcement; The routing announcement is transmitted in sequence according to the receiving order of the routing entities on the routing path, until the last routing entity receives the encrypted objects generated by all the previous routing entities and verifies that the routing announcement has been passed.

2. The inter-domain routing security audit protection method based on RPKI encryption object according to claim 1 is characterized in that: The first encrypted object indicates that the first routing entity authorizes the routing entity on the preset routing path to notify the routing announcement information; the encrypted object corresponding to the current priority routing entity indicates that the current priority routing entity authorizes the routing entity on the preset routing path to notify the routing announcement information; The message type included in the routing announcement message corresponds to the certificate of the encrypted object, and the number of encrypted objects generated by the routing entity is equal to the number of message types included in the routing announcement message.

3. The inter-domain routing security audit protection method based on RPKI encryption object according to claim 1 is characterized in that: After receiving the routing announcement, the router of the routing entity of the current priority obtains the encrypted object generated by the routing entity of the previous priority to verify whether the message information of the routing announcement is authorized. If the authorization is not passed, the routing announcement message is discarded.

4. The inter-domain routing security audit protection method based on RPKI encryption object according to claim 1 is characterized in that: The router of each hop routing entity on the path will verify the existing encryption object and generate a new encryption object according to the direction of the routing announcement to avoid routing path tampering hijacking attacks.

5. The inter-domain routing security audit protection method based on RPKI encryption objects according to any one of claims 1 to 4, characterized in that: The routing announcement message is a BGP-UPDATE message, and the BGP-UPDATE message includes a routing address prefix of each routing entity on a preset routing path.

6. The inter-domain routing security audit protection method based on RPKI encryption object according to claim 5 is characterized in that: The routing entity at the previous order on the preset routing path announces the routing address prefix of its own routing entity to the routing entity at the next order through the routing announcement.

7. The inter-domain routing security audit protection method based on RPKI encryption object according to claim 5 is characterized in that: The router of the routing entity in the next order obtains the encrypted objects stored by all the routing entities in the previous order from the RPKI repository, verifies the certificate signature information of each of the encrypted objects, and if the verification is successful, it means that the routing announcement has not been hijacked and can continue to be received and announced; Otherwise, it means that there is a problem with the routing announcement and the message needs to be discarded.

8. An inter-domain routing security audit protection device based on RPKI encryption objects, characterized in that: include: A first encryption object signing module, configured to generate a first encryption object through a router request of the first routing entity when the first routing entity makes a routing announcement, and store the first encryption object in an RPKI repository; A receiving module, configured to cause the routing entities on the routing path to receive the routing announcement in sequence according to a receiving order after the router of the first routing entity sends the routing announcement; A verification module, which is used for the router of the current priority routing entity to obtain the encrypted objects generated by all routing entities before the current priority for verification after receiving the routing announcement, so as to verify whether the received message information of the routing announcement is authorized; An authorization module, configured to, after verification, enable the router of the current priority routing entity to generate an encrypted object corresponding to the current priority routing entity and store it in the RPKI repository, so as to authorize the subsequent priority routing entity on the routing path to forward the routing announcement; The loop module is used to transmit the routing announcement in sequence according to the receiving order of the routing entities on the routing path, until the last routing entity receives the encrypted objects generated by all the routing entities in the previous order and verifies that the routing announcement has been passed.

9. An electronic device, characterized in that: include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory to implement the method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to any one of claims 1 to 7 when executed by a processor.

Citation Information

Patent Citations

  • Bottleneck deterioration of inter-domain routing based on BGP announcement

    CN109039894A

  • Efficient and safe BGP protection method and system based on topological structure

    CN118611958A

  • Inter-domain routing flow propagation protection method and device based on RPKI encryption object

    CN120017312A