Message safety protection method based on boundary gateway protocol message
A border gateway protocol and security protection technology, applied in data exchange details, user identity/authority verification, data collection prevention, etc., can solve problems such as routing black holes, damage, and hidden dangers of data bureau message transmission mechanism, and achieve The effect of protecting safety
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Publication Date
- 2005-10-12
- Estimated Expiration
- Not applicable · inactive patent
Smart Images
Figure 1 Figure 2 Figure 3
Abstract
Description
technical field
[0001] The invention relates to a security protection method for messages in a network system. Background technique
[0002] Data security in the Internet (Internet) is an important research topic. For the core protocol of the Internet - Border Gateway Protocol (BGP, Border Gateway Protocol), since a large number of routes are transmitted between domains, the security of routes is guaranteed. Security and security of the BGP connection becomes an important issue. Specifically, it is to prevent tampering after the BGP message is intercepted, so as to realize the protection of the BGP connection. According to the BGP protocol, the existing BGP message is composed of 16-byte all-ones plus BGP specific message content, so if the transmission control protocol (TCP protocol) connection is intercepted, according to the 16-byte all-1 message header , as long as the field of all 1s is analyzed, the content of the BGP message can be easily obtained. In this way, not ...
Examples
Embodiment Construction
[0018] The realization of the present invention is that when establishing a BGP connection, both sides of the sending end and the receiving end of the BGP message exchange verification words through the OPEN message, so that after the ability negotiation to the message verification, the first 16 bits of the message header based on the BGP protocol are changed. Byte mark field, that is, use the BGP message header mark field to dynamically verify the message, so as to realize the protection of the entire BGP message, and thus protect the BGP connection. Although the illegal person can intercept the BGP message from the TCP message flow, but because the header of the BGP is not known, the message has no way to synchronize, so the specific content of the BGP message cannot be obtained.
[0019] The present invention will be described in further detail below in conjunction with the accompanying drawings.
[0020] figure 1 It is an embodiment flowchart of the method of the present ...