Secure Inter-domain Routing and Forwarding via Verifiable Forwarding Commitments
Xiaoliang Wang, Zhuotao Liu, Qi Li, Yangfei Guo, Sitong Ling, Jiangou, Zhan, Yi Xu, Ke Xu, Jianping Wu

TL;DR
This paper introduces FC-BGP, a secure, incrementally deployable inter-domain routing protocol that authenticates BGP announcements and validates forwarding paths efficiently, enhancing Internet routing security.
Contribution
It proposes FC-BGP, a novel primitive and protocol that secures BGP and forwarding validation in a deployable manner, addressing limitations of existing solutions.
Findings
FC-BGP reduces validation overhead by 55% compared to BGPsec.
FC-BGP enables incremental deployment without disrupting existing infrastructure.
Prototype evaluation shows effective security and efficiency improvements.
Abstract
The Internet inter-domain routing system is vulnerable. On the control plane, the de facto Border Gateway Protocol (BGP) does not have built-in mechanisms to authenticate routing announcements, so an adversary can announce virtually arbitrary paths to hijack network traffic; on the data plane, it is difficult to ensure that actual forwarding path complies with the control plane decisions. The community has proposed significant research to secure the routing system. Yet, existing secure BGP protocols (e.g., BGPsec) are not incrementally deployable, and existing path authorization protocols are not compatible with the current Internet routing infrastructure. In this paper, we propose FC-BGP, the first secure Internet inter-domain routing system that can simultaneously authenticate BGP announcements and validate data plane forwarding in an efficient and incrementally-deployable manner.…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInternet Traffic Analysis and Secure E-voting · Network Security and Intrusion Detection · Network Packet Processing and Optimization
