nanog mailing list archives
Re: BGP Security and PKI Hierarchies (was: Re: Wifi Security)
From: Sandy Murphy <sandy () tislabs com>
Date: Thu, 24 Nov 2005 06:53:20 -0500 (EST)
the rir attests to the delegation of the prefix and an asn to the identified isp. the isp signs, using their isp identity to o originating from the asn o originating that prefix (in sbgp, toward another isp)
Looks to me like: proof of allocation: S(withRIRkey, Prefix_p_key, prefix_p) as Steve pointed out, there could be two of these, one with CA bit set for use in suballocation and one without the CA bit set for use in routing proof of identity S(withRIRkey, AS_A_key, AS_A) or S(withwebofttrustkeys, AS_A_key, AS_A) maybe Randy is saying this is two steps, not an "OR" proof of origination authorization: S(withPrefix_p_key, authr_origin_AS_#, prefix_p) proof of origination authentication: S(withAS_A_key, (AS_A,prefix_p)update) could be S(withAS_A_key, (AS_A,prefix_p)||proofoforiginationauthr) The binding between the proof of origination authorization and the proof of origination authentication is that the AS_A in the proof of identity mapping AS_A to the AS_A_key must be the same as the authr_origin_AS_# in the proof of origination authorization. [Future complication of this would have to decide what to do with ISPs that own more than one AS #. (make "authr_origin_AS_#" a list?)] --Sandy who really should be baking
Current thread:
- Re: BGP Security and PKI Hierarchies (was: Re: Wifi Security), (continued)
- Re: BGP Security and PKI Hierarchies (was: Re: Wifi Security) Randy Bush (Nov 23)
- Re: BGP Security and PKI Hierarchies (was: Re: Wifi Security) George Michaelson (Nov 23)
- Re: BGP Security and PKI Hierarchies (was: Re: Wifi Security) Randy Bush (Nov 23)
- Re: BGP Security and PKI Hierarchies (was: Re: Wifi Security) George Michaelson (Nov 23)
- Re: BGP Security and PKI Hierarchies (was: Re: Wifi Security) Randy Bush (Nov 23)
- Re: BGP Security and PKI Hierarchies (was: Re: Wifi Security) Steven M. Bellovin (Nov 23)
- Re: BGP Security and PKI Hierarchies (was: Re: Wifi Security) Sean Donelan (Nov 24)
- Re: BGP Security and PKI Hierarchies (was: Re: Wifi Security) Kurt Erik Lindqvist (Nov 25)
- Re: BGP Security and PKI Hierarchies (was: Re: Wifi Security) Kurt Erik Lindqvist (Nov 25)
- Re: BGP Security and PKI Hierarchies (was: Re: Wifi Security) Randy Bush (Nov 28)
- Re: BGP Security and PKI Hierarchies (was: Re: Wifi Security) william(at)elan.net (Nov 28)