首页 | 本学科首页   官方微博 | 高级检索  
     

基于事实所有权的RPKI缓存更新冲突检测机制
引用本文:肖文龙,马迪,毛伟,邵晴.基于事实所有权的RPKI缓存更新冲突检测机制[J].计算机系统应用,2022,31(2):366-375.
作者姓名:肖文龙  马迪  毛伟  邵晴
作者单位:中国科学院 计算机网络信息中心, 北京 100190;中国科学院大学, 北京 100049;中国科学院 计算机网络信息中心, 北京 100190;中国科学院大学, 北京 100049;互联网域名系统国家地方联合工程研究中心, 北京, 100190
摘    要:随着RPKI覆盖的域间网络的范围不断扩大,RPKI在实际部署中的数据同步一致性的问题,运维失误和权威机构权力滥用的风险已成为影响RPKI全面部署的主要障碍.本文提出了一种基于事实所有权的RPKI缓存更新冲突检测机制.该机制利用反向RTR协议与RPKI数据层级分发架构进行事实路由起源信息的采集与同步,并通过比较事实路由起...

关 键 词:资源公钥基础设施  事实所有权  路由起源信息  冲突检测  缓存更新
收稿时间:2021/4/19 0:00:00
修稿时间:2021/5/19 0:00:00

Fact Ownership-based Conflict Detection Scheme for RPKI Cache Update
XIAO Wen-Long,MA Di,MAO Wei,SHAO Qing.Fact Ownership-based Conflict Detection Scheme for RPKI Cache Update[J].Computer Systems& Applications,2022,31(2):366-375.
Authors:XIAO Wen-Long  MA Di  MAO Wei  SHAO Qing
Affiliation:Computer Network Information Center, Chinese Academy of Sciences, Beijing 100190, China;University of Chinese Academy of Sciences, Beijing 100049, China;Computer Network Information Center, Chinese Academy of Sciences, Beijing 100190, China;University of Chinese Academy of Sciences, Beijing 100049, China;Internet Domain Name System Beijing Engineering Research Center, Beijing 100190, China
Abstract:As the resource public key infrastructure (RPKI) coverage of the inter-domain network expands, the consistency of RPKI data synchronization in the actual deployment, the risk of operational errors and abuse of authority power have become major obstacles to the full deployment of RPKI. This study presents a scheme for detecting conflicts of updating RPKI cache based on fact ownership of route origin. This scheme uses reverse RTR protocol and multi-layer transmission architecture of RPKI data to collect and synchronize fact route origin information. Then, it compares fact route origin information and RPKI cache update data to detect conflicting data of RPKI cache update, which ensures authenticity and effectiveness of RPKI cache. Finally, the data synchronization efficiency and detection performance of this scheme are compared with those of other schemes. The experimental results show that this scheme has some detection advantages.
Keywords:RPKI  fact ownership  route origin information  conflict detection  cache update
本文献已被 维普 等数据库收录!
点击此处可从《计算机系统应用》浏览原始摘要信息
点击此处可从《计算机系统应用》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号