Intra-domain BGP (Border Gateway Protocol) routing source verification method

By setting up the ASN conversion module and routing source verification module in the in-domain BGP network, combined with the ROA cached by the RTR protocol module, the in-domain BGP routing source verification is realized, solving the problem that existing RPKI technology is difficult to implement routing source verification in a single AS domain, effectively preventing in-domain routing conflicts and prefix hijacking.

CN120128519AActive Publication Date: 2025-06-10CHINESE PEOPLES LIBERATION ARMY UNIT 61516
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510366794.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-26
Publication Date
2025-06-10
Estimated Expiration
2045-03-26

AI Technical Summary

Technical Problem

The existing RPKI technology is difficult to implement routing source verification in intra-domain BGP routing within a single AS domain, and cannot effectively prevent security risks such as prefix hijacking.

Method used

By setting up the ASN conversion module, BGP protocol module, RTR protocol module and routing source verification module, BGP routing source verification in the domain can be realized. The specific steps include: the BGP protocol module interacts with the PE router BGP routing information, the RTR protocol module interacts with the RP dependant and caches, the ASN conversion module converts the ASN and sends the converted BGP routing information to the routing source verification module, and combines the converted BGP routing information and the cached ROA to perform routing source verification.

Benefits of technology

It realizes source verification of BGP routes in the iBGP network environment within the domain, prevents routing conflicts and prefix hijacking, and expands the applicable scenarios and application scope of RPKI technology.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128519A_ABST
    Figure CN120128519A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network management and route security protection, and provides an intra-domain BGP (Border Gateway Protocol) route source verification method, which comprises the following steps of: setting an ASN conversion module, a BGP protocol module, an RTR protocol module and a route source verification module; the ASN conversion module receives intra-domain BGP routing information transmitted by the BGP protocol module, converts an ASN, and sends the BGP routing information subjected to ASN conversion to the routing source verification module; the route source verification module performs route source verification by combining the BGP route information after ASN conversion and the ROA cached by the RTR protocol module, and judges whether the route is valid or not; then, the route source verification module judges whether the BGP route is a roaming route or not and judges whether the roaming route is effective or not in combination with the BGP route information and the ROA information; according to the method, the intra-domain BGP routing and the PE node equipment can be bound, and security risks such as intra-domain routing conflicts and prefix hijacking can be prevented.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical fields of network management and routing security protection, and particularly relates to a method for verifying BGP route sources within a domain. Background Art

[0002] BGP (Border Gateway Protocol) is a dynamic routing protocol for transmitting and selecting loop-free optimal routes between autonomous systems (AS). It is widely used in carrier backbone networks, the Internet, and industry private networks. BGP can be divided into two types according to usage scenarios: intra-domain and inter-domain. In the inter-domain scenario, eBGP neighbor relationships are established between peers running in different ASs for publishing and transmitting inter-domain routing information between different carrier ASs; in the intra-domain scenario, iBGP neighbor relationships are established between peers within the same AS for transmitting intra-domain routing information within the same carrier AS.

[0003] RPKI (Resource Public Key Infrastructure) is an architecture for enhancing the security of BGP (Border Gateway Protocol) routes on the Internet. By defining legal holdings of IP prefixes and ASNs (Autonomous System Numbers) for entities and providing cryptographic guarantees for route origin verification, it can prevent malicious attackers from spreading false routing information and ensure the security of inter-domain routing and the correct transmission of data in autonomous systems (AS). Its working principle is as follows: resource holders create route origin authorization objects (ROAs, Route Origin Authorisations), which include elements such as the IP address prefixes owned by the holder, the maximum prefix length, and the ASN for which the prefix is announced for routing. ROAs are signed with digital certificates, and the relevant certificates and ROAs are stored in the RPKI repository; the network management departments of operators or other organizations deploy RPs (Relying Parties), periodically synchronize the certificates and ROAs from the RPKI repository, and transfer them to the BGP routers at the AS boundary; when a BGP router receives a route advertisement message, it performs route origin verification (ROV, Route Origin Validation), that is, checks whether the IP address prefix length and the originating ASN match the ROA information, and generates one of three verification results: Valid, Invalid, or Unknown, and then accepts or discards the route according to the set policy, thereby preventing incorrect route advertisements and enhancing network security.

[0004] At present, the RPKI technology system binds IP address prefixes to the originating ASN and performs route origin verification, which can effectively prevent security risks such as eBGP route conflicts or prefix hijacking between different AS domains on the Internet. However, for a single AS domain network with a large number of network node devices, such as a large military backbone network or a national industry private network, it is also desired to achieve the same routing security protection effect, that is, to bind the corresponding relationship between routes and network node devices and perform route origin verification to avoid security risks such as prefix hijacking between different internal node devices. However, because the BGP routes within the domain have the same ASN, the existing RPKI technology system cannot be directly applied within the domain by verifying the correspondence between IP prefixes and ASNs and needs to be improved. On the other hand, after implementing the security policy of binding IP prefixes to network node devices within the domain, it is also necessary to consider the requirements of a real business scenario, that is, a small number of mobile command vehicles keep their IP prefixes unchanged but may roam within the domain and access from different node devices. That is, the method and device for verifying the BGP route source within the domain should be able to support both special IP prefixes not bound to node devices and verification at the same time. Summary of the Invention

[0005] An object of the present invention is to solve at least one technical problem in the background art and provide a method for verifying the BGP route source within a domain.

[0006] To achieve the above object, the present invention provides a method for verifying the BGP route source within a domain, including:

[0007] Set up an ASN conversion module, a BGP protocol module, an RTR protocol module, and a route source verification module;

[0008] The BGP protocol module exchanges BGP route information with the PE router in the network system by running the iBGP protocol;

[0009] The RTR protocol module exchanges ROAs with the RP dependents in the network system through the RTR protocol and caches them;

[0010] The ASN conversion module is connected in series between the BGP protocol module and the route source verification module, receives the intra-domain BGP route information transmitted by the BGP protocol module, converts the ASN according to the attribute information attached to the BGP route information, and sends the BGP route information after converting the ASN to the route source verification module;

[0011] The route source verification module combines the BGP route information after converting the ASN and the ROA cached by the RTR protocol module, and performs route source verification according to the IP address prefix, the maximum prefix length, the ASN attribute value, and the roaming flag bit to determine whether the route is valid.

[0012] According to one aspect of the present invention, the RTR protocol module interacts with RP dependents in the network system through the RTR protocol and caches the ROA as follows:

[0013] The RTR protocol module extends the function of the 8-bit Flags field in the IPv4 prefix PDU and IPv6 prefix PDU of the RTR protocol, sets the second-lowest bit as the roaming flag bit. When this roaming flag bit is set to 1, it indicates that the BGP route is a roaming route. When the RTR module interacts with the RP dependent through the RTR protocol and receives an IPv4 prefix PDU or an IPv6 prefix PDU from the RP dependent, it generates and caches an extended ROA including the IP prefix, the maximum mask length, the ASN, and the roaming flag.

[0014] According to one aspect of the present invention, the ASN conversion module converts the ASN according to the attribute information attached in the BGP routing information, and sends the BGP routing information after converting the ASN to the routing source verification module. The routing source verification module combines the BGP routing information after converting the ASN and the ROA cached by the RTR protocol module, and performs routing source verification according to the IP address prefix, the maximum prefix length, the ASN attribute value, and the roaming flag bit to determine whether the route is valid, including:

[0015] S1. The ASN conversion module extracts the peer IP address and Router-ID value corresponding to the BGP route according to the BGP routing information transmitted by the BGP protocol module;

[0016] S2. The ASN conversion module determines whether the BGP route is an intra-domain route. If the ASN is a null value, it is an intra-domain route, and step S3 is executed. If the ASN is not a null value, it is an inter-domain route, and step S5 is executed;

[0017] S3. The ASN conversion module judges the peer IP address. If the peer IP address is an IPv4 address, the ASN conversion module directly converts the peer IP address into a 4-byte ASN in a bit-by-bit mapping manner; if the peer IP address is an IPv6 address, the ASN conversion module directly converts the Router-ID into a 4-byte ASN in a bit-by-bit mapping manner;

[0018] S4. The ASN conversion module replaces the ASN in the original BGP route with the converted ASN and sends it to the routing source verification module;

[0019] S5. The routing source verification module combines the BGP routing information and the extended ROAs cached in the RTR protocol module, and performs routing source verification based on the IP address prefix, the maximum prefix length, the ASN attribute value, and the roaming flag. If the IP prefix and mask length in the BGP routing information match the IP prefix and the maximum mask length in the extended ROA cache entry, and the roaming flag in this extended ROA cache entry is set to 1, then regardless of whether the ASN matches, this BGP route is verified as valid.

[0020] To achieve the above object, the present invention further provides an electronic device, including a processor, a memory, and a computer program stored on the memory and executable on the processor. When the computer program is executed by the processor, it implements the intra-domain BGP routing source verification method as described above.

[0021] To achieve the above object, the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the intra-domain BGP routing source verification method as described above.

[0022] According to the solution of the present invention, the BGP routing source verification device provided by the present invention can perform routing source verification in the intra-domain iBGP network environment, realize the binding of intra-domain ordinary BGP routes to the home PE node devices and the unbinding of special BGP routes from the PE node devices, prevent security risks such as intra-domain routing conflicts and prefix hijacking, and expand the applicable scenarios, application scope, and usage value of the RPKI technology. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] Figure 1 Schematically shows a flowchart block diagram of an intra-domain BGP routing source verification method according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0024] Now the content of the present invention will be described with reference to exemplary embodiments. It should be understood that the described embodiments are only for enabling those of ordinary skill in the art to better understand and thus implement the content of the present invention, rather than implying any limitation to the scope of the present invention.

[0025] As used herein, the term "comprising" and its variants are to be construed as open-ended terms meaning "including but not limited to". The term "based on" is to be construed as "at least partially based on". The terms "one embodiment" and "an embodiment" are to be construed as "at least one embodiment".

[0026] Figure 1 Schematically shows a flowchart block diagram of an intra-domain BGP routing source verification method according to an embodiment of the present invention. As Figure 1As shown, in this embodiment, the method for verifying the source of intra-domain BGP routes includes:

[0027] Set up an ASN conversion module, a BGP protocol module, an RTR protocol module, and a route source verification module;

[0028] The BGP protocol module interacts with the PE routers in the network system to exchange BGP route information by running the iBGP protocol;

[0029] The RTR protocol module interacts with the RP dependents in the network system through the RTR protocol to exchange ROAs and cache them;

[0030] The ASN conversion module is connected in series between the BGP protocol module and the route source verification module, receives the intra-domain BGP route information transmitted by the BGP protocol module, converts the ASN according to the attribute information attached to the BGP route information, and sends the BGP route information with the converted ASN to the route source verification module;

[0031] The route source verification module combines the BGP route information after converting the ASN and the ROAs cached by the RTR protocol module, and performs route source verification according to the IP address prefix, the maximum prefix length, the ASN attribute value, and the roaming flag bit to determine whether the route is valid.

[0032] According to the above solution of the present invention, the BGP route source verification device provided by the present invention can perform route source verification in the intra-domain iBGP network environment, realize the binding of intra-domain BGP routes and PE node devices, prevent security risks such as intra-domain route conflicts and prefix hijacking, and expand the applicable scenarios, application scope, and usage value of the RPKI technology.

[0033] Further, according to an embodiment of the present invention, for the scenario where a certain type of special mobile node route may be randomly published by any PE node device in the domain, that is, the non-binding mode with the PE device, an extended ROA encoding for supporting roaming routes is performed. In this embodiment, the RTR protocol module interacts with the RP dependents in the network system through the RTR protocol to exchange ROAs and cache them as:

[0034] The RTR protocol module extends the function of the 8-bit Flags field in the IPv4 prefix PDU and IPv6 prefix PDU of the RTR protocol, sets the second-lowest bit as the roaming flag bit, and when this roaming flag bit is set to 1, it indicates that the BGP route is a roaming route. When the RTR module interacts with the RP dependent through the RTR protocol and receives the IPv4 prefix PDU or IPv6 prefix PDU from the RP dependent, it generates and caches an extended ROA including the IP prefix, the maximum mask length, the ASN, and the roaming flag.

[0035] Furthermore, according to an embodiment of the present invention, the ASN conversion module converts the ASN based on the attribute information attached in the BGP routing information, and sends the BGP routing information after converting the ASN to the routing source verification module. The routing source verification module combines the BGP routing information after converting the ASN and the ROA cached by the RTR protocol module, and performs routing source verification according to the IP address prefix, the maximum prefix length, the ASN attribute value, and the roaming flag bit to determine whether the route is valid, including:

[0036] S1. The ASN conversion module extracts the peer IP address and Router-ID value corresponding to the BGP route according to the BGP routing information transmitted by the BGP protocol module;

[0037] S2. The ASN conversion module determines whether the BGP route is an intra-domain route. If the ASN is a null value, it is an intra-domain route, and step S3 is executed. If the ASN is not a null value, it is an inter-domain route, and step S5 is executed;

[0038] S3. The ASN conversion module judges the peer IP address. If the peer IP address is an IPv4 address, the ASN conversion module directly converts the peer IP address into a 4-byte ASN in a bit-by-bit mapping manner; if the peer IP address is an IPv6 address, the ASN conversion module directly converts the Router-ID into a 4-byte ASN in a bit-by-bit mapping manner;

[0039] S4. The ASN conversion module replaces the ASN in the original BGP route with the converted ASN and sends it to the routing source verification module;

[0040] S5. The routing source verification module combines the BGP routing information and the extended ROA cached by the RTR protocol module, and performs routing source verification according to the IP address prefix, the maximum prefix length, the ASN attribute value, and the roaming flag bit. If the IP prefix and mask length in the BGP routing information match the IP prefix and the maximum mask length in the extended ROA cache entry, and the roaming flag bit in the extended ROA cache entry is set to 1, then regardless of whether the ASN matches, the BGP route is verified as valid.

[0041] According to the above solution of the present invention, the BGP routing source verification device provided by the present invention can perform routing source verification in the intra-domain iBGP network environment, realize the binding of intra-domain ordinary BGP routes to the home PE node devices and the unbinding of special BGP routes from the PE node devices, prevent security risks such as intra-domain routing conflicts and prefix hijacking, and expand the applicable scenarios, application scope, and usage value of the RPKI technology.

[0042] Furthermore, to achieve the above object, the present invention also provides an electronic device, including a processor, a memory, and a computer program stored on the memory and executable on the processor. When the computer program is executed by the processor, the method for verifying the BGP routing source within the domain as described above is implemented.

[0043] Furthermore, to achieve the above object, the present invention also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by the processor, the method for verifying the BGP routing source within the domain as described above is implemented.

[0044] Those of ordinary skill in the art can realize that the modules and algorithm steps described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.

[0045] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working processes of the above-described devices and equipment can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0046] In the embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only illustrative. For example, the division of the modules is only a logical function division. In actual implementation, there can be other division methods. For example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the devices or modules can be in an electrical, mechanical, or other form.

[0047] The modules described as separate components may or may not be physically separated. The components displayed as modules may or may not be physical modules, that is, they can be located in one place, or can be distributed to multiple network modules. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of the embodiments of the present invention.

[0048] In addition, in the embodiments of the present invention, the various functional modules can be integrated in a processing module, or each module can exist physically alone, or two or more modules can be integrated in one module.

[0049] When the above functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method for sending / receiving energy-saving signals in various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, ROM, RAM, magnetic disks, or optical discs that can store program codes.

[0050] The above description is only for the preferred embodiments of this application and the explanation of the applied technical principles. Those skilled in the art should understand that the scope of the invention involved in this application is not limited to the technical solutions formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the inventive concept. For example, the technical solutions formed by mutually replacing the above features with the (but not limited to) technical features with similar functions disclosed in this application.

[0051] It should be understood that the magnitudes of the sequence numbers of the steps in the invention content and embodiments of the present invention do not absolutely mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.

Claims

1. A method for verifying the source of intra-domain BGP routing, characterized in that: include: Set up ASN conversion module, BGP protocol module, RTR protocol module and routing source verification module; The BGP protocol module exchanges BGP routing information with the PE router in the network system by running the iBGP protocol; The RTR protocol module exchanges ROA with the RP relying party in the network system through the RTR protocol and caches it; The ASN conversion module is serially connected between the BGP protocol module and the routing source verification module, receives the intra-domain BGP routing information transmitted by the BGP protocol module, converts the ASN according to the attribute information attached to the BGP routing information, and sends the BGP routing information after the ASN conversion to the routing source verification module; The routing source verification module combines the BGP routing information after the ASN conversion and the ROA cached by the RTR protocol module, performs routing source verification according to the IP address prefix, maximum prefix length, ASN attribute value and roaming flag bit, and determines whether the route is valid.

2. The method for verifying the source of intra-domain BGP routing according to claim 1, characterized in that: The RTR protocol module interacts with the RP relying party in the network system through the RTR protocol and caches the ROA as follows: The RTR protocol module extends the 8-bit Flags field function in the IPv4 prefix PDU and IPv6 prefix PDU of the RTR protocol, sets the second lowest bit to the roaming flag bit, and when the roaming flag bit is 1, it indicates that the BGP route is a roaming route. The RTR module interacts with the RP relying party through the RTR protocol, and when receiving the IPv4 prefix PDU or IPv6 prefix PDU from the RP relying party, generates and caches an extended ROA including the IP prefix, maximum mask length, ASN and roaming flag.

3. The method for verifying the source of intra-domain BGP routing according to claim 2, characterized in that: The ASN conversion module converts the ASN according to the attribute information attached to the BGP routing information, and sends the BGP routing information after the ASN conversion to the routing source verification module. The routing source verification module combines the BGP routing information after the ASN conversion and the ROA cached by the RTR protocol module, and performs routing source verification according to the IP address prefix, the maximum prefix length, the ASN attribute value and the roaming flag bit to determine whether the route is valid, including: S1. The ASN conversion module extracts the BGP routing peer IP address and Router-ID value corresponding to the BGP routing according to the BGP routing information transmitted by the BGP protocol module; S2. The ASN conversion module determines whether the BGP route is an intra-domain route. If the ASN is null, it is an intra-domain route, and step S3 is executed. If the ASN is not null, it is an inter-domain route, and step S5 is executed; S3. The ASN conversion module determines the peer IP address. If the peer IP address is an IPv4 address, the ASN conversion module directly converts the peer IP address into a 4-byte ASN by bit-by-bit mapping; if the peer IP address is an IPv6 address, the ASN conversion module directly converts the Router-ID into a 4-byte ASN by bit-by-bit mapping; S4. The ASN conversion module replaces the converted ASN in the original BGP route ASN and sends it to the route source verification module; S5. The routing source verification module combines the BGP routing information and the extended ROA cached by the RTR protocol module to perform routing source verification based on the IP address prefix, maximum prefix length, ASN attribute value and roaming flag. If the IP prefix and mask length in the BGP routing information match the IP prefix and maximum mask length in the extended ROA cache entry, and the roaming flag position in the extended ROA cache entry is 1, then regardless of whether the ASN matches, the BGP route is verified to be valid.

4. An electronic device, characterized in that The method comprises a processor, a memory and a computer program stored in the memory and executable on the processor. When the computer program is executed by the processor, the method for verifying the source of intra-domain BGP routing as described in claims 1 to 3 is implemented.

5. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by the processor, the method for verifying the source of intra-domain BGP routing as described in claims 1-3 is implemented.

Citation Information

Patent Citations

  • BGP routing information verification method and device

    CN111211976A

  • Routing learning method, message forwarding method, equipment and storage medium

    CN112398741A

  • Method and Apparatus for Route Verification and Data Sending, Device, and Storage Medium

    US20240022602A1

  • Source address validation table entry acquisition method and apparatus

    WO2024234907A1