In an interdomain network, autonomous systems (ASes) often establish peering agreements, so that one AS (agreement consumer) can influence the routing policies of the other AS (agreement provider). Peering agreements are implemented in the BGP configuration of the agreement provider. It is crucial to verify their implementation because one error can lead to disastrous consequences. However, the fundamental challenge for peering agreement verification is how to preserve the privacy of both ASes involved in the agreement. To this end, this paper presents IVeri, the first privacy-preserving interdomain agreement verification system. IVeri models the interdomain agreement verification problem as a SAT formula, and develops a novel, efficient, privacy-serving SAT solver, which uses oblivious shuffling and garbled circuits as the key building blocks to let the agreement consumer and provider collaboratively verify the implementation of interdomain peering agreements without exposing their private information. A prototype of IVeri is implemented and evaluated extensively. Results show that IVeri achieves accurate, privacy-preserving interdomain agreement verification with reasonable overhead.
翻译:在一个内部网络中,自主系统(ASes)往往会建立同侪协议,以便一个AS(协议消费者)能够影响另一个AS(协议提供方)的路线政策;在协议提供方的BGP配置中执行同侪协议;由于一个错误可能导致灾难性后果,因此必须核查其执行情况;然而,同侪协议核查的根本挑战是如何保护协议所涉及的两个ASe的隐私;为此,本文件介绍了第一个隐私保护协议之间的核查系统Vieri。IVeri将内部协议的核查问题作为SAT公式来模型,并开发一个新的、高效的、为隐私服务的SAT解答器,该解答器使用模糊的打拼和缠绕的电路作为关键构件,使协议的消费者和供应商在不泄露其私人信息的情况下合作核查内部同侪协议的执行情况。一个IVeri的原型得到了广泛实施和评价。结果显示,Vieri实现了准确的、隐私维护协议与合理间接费用的核查。