DocumentCode :
3644300
Title :
Deploying new hash algorithms in Secure Neighbor Discovery
Author :
Valter Vasić;Ana Kukec;Miljenko Mikuc
Author_Institution :
University of Zagreb
fYear :
2011
Firstpage :
1
Lastpage :
5
Abstract :
IP protocol version 6 (IPv6), a successor of IP protocol version 4 (IPv4), puts a significant effort in enhancing security facilities. Secure Neighbor Discovery (SEND) is an optional IPv6 protocol that counters threats in link-local communication allowed by Neighbor Discovery protocol (NDP). It protects from attacks against the integrity and authentication capabilities, relying on trustworthiness of cryptographic hash functions. After a recent discovery of reduced hash function resistance, their efficiency has been called into question. Attacks against the collision-free property of hash functions lead to the reexamination of how Internet protocols use hashes. In the paper we contribute with analyzes of attacks on hash functions, use of hashes in SEND, impact of hash attacks on each use of hash functions in SEND, propose and evaluate possible approaches to allowing hash agility, and finally propose the most efficient solution - a solution for SEND hash agility based on a negotiation approach.
Keywords :
"Protocols","Digital signatures","Public key","Internet","Authorization"
Publisher :
ieee
Conference_Titel :
Software, Telecommunications and Computer Networks (SoftCOM), 2011 19th International Conference on
Print_ISBN :
978-1-4577-1439-9
Type :
conf
Filename :
6064420
Link To Document :
بازگشت