Security mechanism for IPv6 router discovery based on distributed trust management

Supriyanto, rajakumar. murugesan, A. Osman, S. Ramadass, rajakumar. murugesan
{"title":"Security mechanism for IPv6 router discovery based on distributed trust management","authors":"Supriyanto, rajakumar. murugesan, A. Osman, S. Ramadass, rajakumar. murugesan","doi":"10.1109/RFID-TA.2013.6694519","DOIUrl":null,"url":null,"abstract":"IPv6 requires the support of other protocols such as neighbor discovery and ICMPv6 for its functioning. Neighbor discovery includes router discovery, and redirect. Router discovery is used by an IPv6 host to discover the presence of routers and network parameters. It enables the host to configure list of default gateway, list of address prefixes, Maximum Transmission Unit (MTU) in the link and hop limit setting for sending IPv6 packets. Failure to complete the initialization process will cause the network to have no IPv6 addresses, disabling it from sending any IPv6 packets and communication with others. As the original router discovery standard does not specify a security mechanism for it, they are vulnerable for any exploitation. This paper investigates the current router discovery mitigation methods such as ADD, SAVI, TRDP and RA Guard. The investigation would further increase the understanding on their weakness so that it could be used to formalize a new security method for router discovery. We propose a new security mechanism based on distributed trust management. Theoretical analysis of this mechanism shows a decrease in bandwidth consumption compared to ADD on Secure Neighbor Discovery mechanism up to 3.15 times lesser.","PeriodicalId":253369,"journal":{"name":"2013 IEEE International Conference on RFID-Technologies and Applications (RFID-TA)","volume":"22 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2013-09-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"8","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2013 IEEE International Conference on RFID-Technologies and Applications (RFID-TA)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/RFID-TA.2013.6694519","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 8

Abstract

IPv6 requires the support of other protocols such as neighbor discovery and ICMPv6 for its functioning. Neighbor discovery includes router discovery, and redirect. Router discovery is used by an IPv6 host to discover the presence of routers and network parameters. It enables the host to configure list of default gateway, list of address prefixes, Maximum Transmission Unit (MTU) in the link and hop limit setting for sending IPv6 packets. Failure to complete the initialization process will cause the network to have no IPv6 addresses, disabling it from sending any IPv6 packets and communication with others. As the original router discovery standard does not specify a security mechanism for it, they are vulnerable for any exploitation. This paper investigates the current router discovery mitigation methods such as ADD, SAVI, TRDP and RA Guard. The investigation would further increase the understanding on their weakness so that it could be used to formalize a new security method for router discovery. We propose a new security mechanism based on distributed trust management. Theoretical analysis of this mechanism shows a decrease in bandwidth consumption compared to ADD on Secure Neighbor Discovery mechanism up to 3.15 times lesser.
基于分布式信任管理的IPv6路由器发现安全机制
IPv6需要其他协议的支持,如邻居发现和ICMPv6。邻居发现包括路由器发现和重定向。路由器发现是由IPv6主机用来发现路由器和网络参数的存在。允许主机配置发送IPv6报文的默认网关列表、地址前缀列表、链路最大传输单元MTU (Maximum Transmission Unit)和跳数限制设置。如果没有完成初始化过程,将导致网络没有IPv6地址,无法发送任何IPv6报文,也无法与其他网络通信。由于原有的路由器发现标准没有为其指定安全机制,因此很容易被利用。本文研究了现有的路由器发现缓解方法,如ADD、SAVI、TRDP和RA Guard。调查将进一步增加对其弱点的理解,以便可以用来形式化一种新的路由器发现安全方法。提出了一种基于分布式信任管理的安全机制。对该机制的理论分析表明,与基于安全邻居发现机制的ADD相比,该机制的带宽消耗减少了3.15倍。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信