• DocumentCode
    3391950
  • Title

    Resolution of ISAKMP/Oakley key-agreement protocol resistant against denial-of-service attack

  • Author

    Matsuura, Kanta ; Imai, Hideki

  • Author_Institution
    Inst. of Ind. Sci., Tokyo Univ., Japan
  • fYear
    1999
  • fDate
    1999
  • Firstpage
    17
  • Lastpage
    24
  • Abstract
    Key-agreement protocols will play an important role as an entrance to secure communication over the Internet. Specifically, ISAKMP (Internet Security Association and Key Management Protocol)/Oakley key-agreement is currently a leading approach for communication between two parties. The basic idea of ISAKMP/Oakley is an authenticated Diffie-Hellman (DH) key-agreement protocol. This authentication owes a lot to public key primitives whose implementation includes modular exponentiation. Since modular exponentiation is computationally expensive, attackers are motivated to abuse it for Denial-of-Service (DoS) attacks. In search of resistance against DoS attacks, the paper first describes a basic idea on the protection mechanism for authenticated DH key-agreement protocols against DoS attacks. The paper then proposes a DoS-resistant version of three-pass ISAKMP/Oakley´s Phase 1 where DoS attacks impose expensive computation on the attackers themselves. The DoS resistance is evaluated in terms of: (1) the computational cost caused by bogus requests and (2) a server-blocking probability
  • Keywords
    Internet; computational complexity; message authentication; protocols; public key cryptography; telecommunication security; DoS attacks; DoS-resistant version; ISAKMP/Oakley key-agreement protocol resolution; Internet Security Association and Key Management Protocol; authenticated DH key-agreement protocols; authenticated Diffie-Hellman key-agreement protocol; authentication; bogus requests; computational cost; denial-of-service attack; modular exponentiation; protection mechanism; public key primitives; secure communication; server-blocking probability; Authentication; Computer crime; DH-HEMTs; Internet; Protection; Protocols; Public key; Radio frequency; Resists; Security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Internet Workshop, 1999. IWS 99
  • Conference_Location
    Osaka
  • Print_ISBN
    0-7803-5925-9
  • Type

    conf

  • DOI
    10.1109/IWS.1999.810911
  • Filename
    810911