Resource Certification What it means for LIRs Alain P. AINA Special Project Manager.

Slides:



Advertisements
Similar presentations
RPKI Standards Activity Geoff Huston APNIC February 2010.
Advertisements

1 APNIC Resource Certification Service Project Routing SIG 7 Sep 2005 APNIC20, Hanoi, Vietnam George Michaelson.
Local TA Management A TA is a public key and associated data used as the starting point for certificate path validation It need not be a self-signed certificate.
RPKI Certificate Policy Status Update Stephen Kent.
Nigel Titley. RIPE 54, 9 May 2007, Tallinn, Estonia. 1 RIPE NCC Certification Task Force Update Presented by Nigel Titley RIPE NCC.
APNIC Member Services George Kuo. MyAPNIC 2 What is MyAPNIC A secure Member services website Internet resources management, for example: –Whois updates.
Projects Awaiting Prioritization Nate Davis. Planned Functionality Projects underway or next in queue Hosted RPKI (Planned 2012 Q2 Deployment) - RPKI.
RPKI and Routing Security ICANN 44 June Today’s Routing Environment is Insecure Routing is built on mutual trust models Routing auditing requires.
Overview of draft-ietf-sidr-roa-format-01.txt Matt Lepinski BBN Technologies.
An Introduction to Routing Security (and RPKI Tools) Geoff Huston May 2013.
Certificates Last Updated: Aug 29, A certificate was originally created to bind a subject to the subject’s public key Intended to solve the key.
Validation Algorithms for a Secure Internet Routing PKI David Montana Mark Reynolds BBN Technologies.
RPKI Validation - Revisited draft-huston-rpki-validation-01.txt Geoff Huston George Michaelson APNIC Slide 1/19.
Certification Authority. Overview  Identifying CA Hierarchy Design Requirements  Common CA Hierarchy Designs  Documenting Legal Requirements  Analyzing.
Review of draft-ietf-sidr-arch-01.txt Steve Kent BBN Technologies.
What’s Next: DNSSEC & RPKI Mark Kosters. Why are DNSSEC and RPKI Important Two critical resources – DNS – Routing Hard to tell when it is compromised.
6/1/20151 Digital Signature and Public Key Infrastructure Course:COSC Instructor:Professor Anvari Student ID: Name:Xin Wen Date:11/25/00.
PKI in US Higher Education TAGPMA Meeting, March 2006 Rio De Janeiro, Brazil.
DESIGNING A PUBLIC KEY INFRASTRUCTURE
Resource PKI: Certificate Policy & Certification Practice Statement Dr. Stephen Kent Chief Scientist - Information Security.
Some Lessons Learned from Designing the Resource PKI Geoff Huston Chief Scientist, APNIC May 2007.
Summary Report on Resource Certification February 2007 Geoff Huston Chief Scientist APNIC.
APNIC Trial of Certification of IP Addresses and ASes RIPE 52 Plenary George Michaelson Geoff Huston.
Resource Certificate Profile SIDR WG Meeting IETF 66, July 2006 draft-ietf-sidr-res-certs-01 Geoff Huston Rob Loomans George Michaelson.
A PKI For IDR Public Key Infrastructure and Number Resource Certification AUSCERT 2006 Geoff Huston Research Scientist APNIC.
Progress Report on resource certification February 2007 Geoff Huston Chief Scientist APNIC.
PKI To The Masses IPCCC 2004 Dan Massey USC/ISI. 1 March PKI Is Necessary l My PKI related actions since arriving at IPCCC n Used an.
1 Securing BGP Large scale trust to build an Internet again Lutz Donnerhacke db089309: 1c1c 6311 ef09 d819 e029 65be bfb6 c9cb.
Progress Report on APNIC Trial of Certification of IP Addresses and ASes APNIC 22 September 2006 Geoff Huston.
The Resource Public Key Infrastructure Geoff Huston APNIC.
Controller of Certifying Authorities Public Key Infrastructure for Digital Signatures under the IT Act, 2000 : Framework & status Mrs Debjani Nag Deputy.
APNIC eLearning: Intro to RPKI 10 December :30 PM AEST Brisbane (UTC+10)
1 PKI Update September 2002 CSG Meeting Jim Jokl
Introduction to Secure Messaging The Open Group Messaging Forum April 30, 2003.
1 San Diego, California 25 February Securing Routing: RPKI Overview Mark Kosters Chief Technology Officer.
NENA Development Conference | October 2014 | Orlando, Florida Security Certificates Between i3 ESInet’s and FE’s Nate Wilcox Emergicom, LLC Brian Rosen.
RPKI Tutorial Andy Newton Chief Engineer, ARIN. Agenda Resource Public Key Infrastructure(RPKI) Route Origin Authorizations (ROAs) Certificate Authorities.
Public Key Infrastructure (X509 PKI) Presented by : Ali Fanian.
Digital Signatures A Brief Overview by Tim Sigmon April, 2001.
Using Resource Certificates Progress Report on the Trial of Resource Certification October 2006 Geoff Huston Chief Scientist APNIC.
Using Resource Certificates Progress Report on the Trial of Resource Certification October 2006 Geoff Huston APNIC.
Public Key Infrastructure (X509 PKI) Presented by : Ali Fanian
1. 2 Overview In Exchange security is managed by assigning permissions in Active Directory Exchange objects are secured with DACL and ACEs Permissions.
Security in ebXML Messaging CPP/CPA Elements. Elements of Security P rivacy –Protect against information being disclosed or revealed to any entity not.
Secure Origin BGP: What is (and isn't) in a name? Dan Wendlandt Princeton Routing Security Reading Group.
Using Resource Certificates Progress Report on the Trial of Resource Certification November 2006 Geoff Huston APNIC.
1 Madison, Wisconsin 9 September14. 2 Security Overlays on Core Internet Protocols – DNSSEC and RPKI Mark Kosters ARIN Engineering.
Updates to the RPKI Certificate Policy I-D Steve Kent BBN Technologies.
Draft-huston-sidr-rfc6490-bis Geoff Huston Slide 1/6.
AFRINIC Update Adiel A. Akplogan CEO, AFRINIC RIPE-68, Warsaw (Poland) May 2014.
1 APNIC Trial of Certification of IP Addresses and ASes RIPE October 2005 Geoff Huston.
Status Report SIDR and Origination Validation Geoff Huston SIDR WG, IETF 71 March 2008.
Overview of draft-ietf-sidr-roa-00.txt Steve Kent BBN Technologies.
Wed 24 Mar 2010SIDR IETF 77 Anaheim, CA1 SIDR Working Group IETF 77 Anaheim, CA Wednesday, Mar 24, 2010.
AFRINIC Update Madhvi Gokool Registration Service Manager RIPE66 meeting, Dublin May 2013.
RPKI implementation experiences in the LAC Region Carlos M. Martínez – Arturo Servín LACSEC 2012 – LACNIC XVIII.
Using Resource Certificates Progress Report on the Trial of Resource Certification October 2006 Geoff Huston APNIC.
BGP Validation Russ White Rule11.us.
Are We There Yet? On RPKI Deployment and Security
Securing BGP: The current state of RPKI
November 2006 Geoff Huston APNIC
RPKI Trust Anchor Geoff Huston APNIC.
APNIC Trial of Certification of IP Addresses and ASes
Some Thoughts on Integrity in Routing
APNIC Trial of Certification of IP Addresses and ASes
Progress Report on Resource Certification
October 2006 Geoff Huston APNIC
ROA Content Proposal November 2006 Geoff Huston.
September 2002 CSG Meeting Jim Jokl
Presentation transcript:

Resource Certification What it means for LIRs Alain P. AINA Special Project Manager

What is Resource Certification ?  Resource Certification is a security framework for verifying the association between resource holders and their Internet resources. Add a verifiable form of a holder's current “right-of-use” over Internet resources in the resources management system  Resource Public Key Infrastructure(RPKI) is a PKI based on the Internet resources management hierarchy and under which X509 certificates with RFC 3779 extensions and other signed objects are published and bound together in an verifiable way.

Motivations  Facilitate a better routes filtering  Prepare for a secure Routing  Solve the chicken-and-egg problem  Provide trusted data Better than the current Whois and IRR data  Post IPv4 exhaustion data accuracy Resource transfers

Overview

THIS IS NOT AN IDENTITY CERTIFICATE A RPKI Certificate

Use Cases  ROAs - against hijacks  Enabling S*BGP  Customer sign-up  Resources transfers  RPSLSIG  ROA2RPSL ?  Bogon filtering – BOAs? More to come :-)

Use Cases: ROA ROA – Route Origination Authorization Using my certificate covering a prefix, I can formally, verifiably authorize an AS to announce that prefix  Can be useful for constructing route filters  Could be used by S*BGPs

Use Cases: ROA ROA – Route Origination Authorization

Without RPKI How do you verify their claim over a resource? Use Cases: Customer Sign-up

With RPKI Use Cases: Customer sign-up

Use Cases: Customer sign-up (cont’d) With RPKI

Use Cases: RPSLSIG Combining RPKI and RPSL: RPSL Signatures  Use RPKI to sign RPSL objects by extending RPSL syntax  It could raise the trust level of RPSL data by providing “object security” as an addition For example: Prefix and AS holder both sign a route object, thereby expressing their agreement on it.

Use Cases: RPSLSIG Route: /24 descr: GroupNet and ISP1 origin: AS65536 mnt-by: GroupNet-MNT signature: v=1;c=rsync://.../....cer; m=sha1- rsa;t= T10:11:01T;a=route+descr+origin+mnt- by;b=324kjndfg9083GAD4sEW32. signature: v=1;c=rsync://.../....cer; m=sha1- rsa;t= T11:11:01T;a=route+descr+origin+mnt- by; b=9ds3D4sW3234tj11wdhuon... source: AFRINIC

I nternet Registries(RIR/LIR/ISP) can:  Receive their certificates from their “upstreams”  Issue certificates to their clients or themselves: End Entities Certificate  Sign data with operative content using their own Certificates Participating in the RPKI

Enter the RPKI Engine Participating in the RPKI

To participate, an IR needs:  RPKIE software and an infrastructure to run it  On the higher levels: Hardware Security Module(s)  Good back-end database of resource delegations  Some Mandatory documents for a PKI: - Certificate Policy(CP) - Certification Practice Statement (CPS)

Services for the RPKI Intended AfriNIC services for LIRs:  Certify LIR resources using the AfriNIC own RPKIE  Provide hosted RPKI services for LIRs: - A full managed RPKIE for LIR - Run the LIR’s RPKIE et give real control to LIRs  Deploy the UP-Down protocol to talk to LIRs willing to run their own RPKIE  Provide the necessary public repository  Access to these services: - Through the normal channels (MyAFRINIC) - With strong authentication X509 Auth with BPKI certs

Services for the RPKI Potential services:  Central cache for certificates (repository collection)  Certificate validation  Object validation  Repository service  Others?

Trust Anchors for RP:Which root CAs ?  TA choice is the Relying Party’s decision  For the RPKI, RIRs seems to be a natural choice But just as every IRs, they will only certify what they allocate/assign  Possible use of multiple TAs  IANA can also be a single (or an additional) TA  The NRO statement of the RPKI TA

Questions ??? A resource certification portal soon