@techreport{donnerhacke-sidr-bgp-verification-dnssec-04, number = {draft-donnerhacke-sidr-bgp-verification-dnssec-04}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-donnerhacke-sidr-bgp-verification-dnssec/04/}, author = {Lutz Donnerhacke and Wouter Wijngaards}, title = {{DNSSEC protected routing announcements for BGP}}, pagetotal = 21, year = 2008, month = may, day = 5, abstract = {This document describes an infrastructure for real time verification of routes reveived via BGP4. Some DNS query types are introduced to check the origin of a prefix and validity of the AS path. The crypto part can be offloaded from the routing engine by sending a DNS query and checking the AD bit in the DNS response. The proposal depends on the DNS scalability and caching mechanisms as well as PKI introduced by DNSSEC.}, }