Mitigating Route Hijacking via Cryptographically Certified ROA Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current telecommunications networks are vulnerable to route hijacking due to the lack of effective verification of routing information, allowing fraudulent actors to intercept communications by manipulating AS_PATH fields in BGP announcements, which existing security measures fail to adequately address.
Innovation Solution
Implementing a method that utilizes cryptographically certified Recognized Operating Agency (ROA) objects to generate an interconnect network model, verifying announced routing information against this model to ensure authenticity and prevent hijacking, by generating an AS interconnect table and comparing AS path information to mitigate fraudulent route announcements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If routing information is shared based on trust among networks, then network operation simplicity is improved, but network security deteriorates due to route hijacking vulnerabilities
Solution Approach 1:
The system performs preliminary verification of routing information by checking AS_PATH fields against a database of legitimate IP address assignments before accepting route announcements. This preventive measure is implemented in advance of potential hijacking attempts, validating the authenticity of routing information proactively rather than reactively.
Solution Approach 2:
A verification system acts as an intermediary between route announcement and routing table installation. The system introduces an additional validation layer that checks whether announced IP addresses match legitimate assignments, mediating between the simplicity of trust-based routing and the security requirements of hijacking prevention.
2Productivity
If route announcements are accepted without verification, then routing information processing speed is improved, but accuracy of routing information deteriorates due to fraudulent announcements
Solution Approach 1:
The verification check is performed preliminarily during route announcement processing by comparing AS_PATH fields against pre-populated databases of legitimate IP assignments. This ensures accurate routing information is established before being added to routing tables, preventing fraudulent routes from propagating through the network.
3Reliability
If additional verification mechanisms are implemented, then network security is improved, but device complexity increases due to verification system requirements
Solution Approach 1:
Databases of legitimate IP address assignments and autonomous system relationships are pre-populated and stored in advance. During route verification, the system simply queries these pre-existing databases rather than performing complex real-time analysis, reducing the computational burden and device complexity while maintaining security.
Solution Approach 2:
The system uses copies of authoritative routing information stored in databases as reference data for verification. By comparing announced routes against these pre-stored copies of legitimate routing information, the system achieves security verification without requiring complex real-time computation or direct access to remote authorities.
Data Source
AI summary
Aspects of the present disclosure involve systems and methods for utilizing verified autonomous system (AS) network interconnections received via a cryptographically certified Recognized Operating Agency (ROA) object to generate an interconnect network model which may be used as a reference model to mitigate hijacking of network communications in downstream route announcements. In particular, AS networks may announce or share a cryptographically certified ROA object that includes a list of other AS networks to which the announcing network is connected. A router, server, or other networking device may receive ROA objects from multiple AS networks and generate a model or graph of the interconnectedness of the AS networks. Further, because each ROA object may be cryptographically certified or signed, the networking device may trust the information provided in the received ROA objects. The networking device may further verify announced routing information against the generated network model.


