DocumentCode :
2998264
Title :
SSAS: A simple secure addressing scheme for IPv6 autoconfiguration
Author :
Rafiee, H. ; Meinel, Christoph
Author_Institution :
Hasso-Plattner-Inst., Univ. of Potsdam, Potsdam, Germany
fYear :
2013
fDate :
10-12 July 2013
Firstpage :
275
Lastpage :
282
Abstract :
The default method for IPv6 address generation uses an Organizationally Unique Identifier (OUI) assigned by the IEEE Standards Association and an Extension Identifier assigned by the hardware manufacturer (RFC 4291). For this reason a node will always have the same Interface ID (IID) whenever it connects to a new network. Because the node´s IP address does not change, the node will be vulnerable to privacy related attacks. Currently this problem is addressed by the use of two mechanisms that do not use MAC addresses or other unique values for randomizing the IID during its generation: Cryptographically Generated Addresses (CGA) (RFC 3972) and Privacy Extension (RFC 4941). The problem with the former approach is the computational cost involved in the IID generation and, more importantly, the verification process. The problem with the latter approach is the lack of necessary security mechanisms and that it provides the node with only partial protection against privacy related attacks. This document proposes the use of a new algorithm in the generation of the IID to reduce computational cost while, at the same time, securing the node against some types of attack, like IP spoofing. These attacks are prevented by the addition of a signature to messages sent over the network and by direct use of a public key in the IP address.
Keywords :
IEEE standards; IP networks; access protocols; computer network security; cost reduction; cryptographic protocols; data privacy; telecommunication industry; telecommunication standards; CGA; IEEE Standards Association; IID generation; IP spoofing; IPv6 address generation; IPv6 autoconfiguration; MAC address; OUI; RFC 3972; RFC 4291; SSAS; computational cost reduction; cryptographically generated address; extension identifier assignment; hardware manufacturer; interface ID generation; organizationally unique identifier; privacy extension; simple secure addressing scheme; verification process; Databases; IP networks; Privacy; Public key; Routing protocols; IPv6; IPv6 addressing; NDP; Randomized Interface ID; Stateless Autoconfiguration; public/private key;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Privacy, Security and Trust (PST), 2013 Eleventh Annual International Conference on
Conference_Location :
Tarragona
Type :
conf
DOI :
10.1109/PST.2013.6596063
Filename :
6596063
Link To Document :
بازگشت