论文标题
艾维利:保护隐私的域间验证
IVeri: Privacy-Preserving Interdomain Verification
论文作者
论文摘要
在一个间网络中,自治系统(ASE)经常建立对等协议,以便一个作为(协议消费者)可以影响另一个AS(协议提供商)的路由策略。在协议提供商的BGP配置中实施了对等协议。验证其实施至关重要,因为一个错误可能导致灾难性后果。但是,对认识协议验证的基本挑战是如何保护协议中涉及的两个ASE的隐私。为此,本文介绍了第一个保护隐私的域间协议验证系统Iveri。 Iveri将域间协议验证问题模拟为SAT公式,并开发出一种新颖,高效,私密的服务SAT求解器,该解决方案使用忽略的改组和乱码的电路作为关键构建块,以使消费者和提供者协作验证与私人信息无私人信息的实施。实施和评估了Iveri的原型。结果表明,Iveri可以通过合理的开销来实现准确,保存隐私的域间协议验证。
In an interdomain network, autonomous systems (ASes) often establish peering agreements, so that one AS (agreement consumer) can influence the routing policies of the other AS (agreement provider). Peering agreements are implemented in the BGP configuration of the agreement provider. It is crucial to verify their implementation because one error can lead to disastrous consequences. However, the fundamental challenge for peering agreement verification is how to preserve the privacy of both ASes involved in the agreement. To this end, this paper presents IVeri, the first privacy-preserving interdomain agreement verification system. IVeri models the interdomain agreement verification problem as a SAT formula, and develops a novel, efficient, privacy-serving SAT solver, which uses oblivious shuffling and garbled circuits as the key building blocks to let the agreement consumer and provider collaboratively verify the implementation of interdomain peering agreements without exposing their private information. A prototype of IVeri is implemented and evaluated extensively. Results show that IVeri achieves accurate, privacy-preserving interdomain agreement verification with reasonable overhead.