首页> 外文会议>IEEE International Conference on Communications >End-host Authentication and Authorization for Middleboxes based on a Cryptographic Namespace
【24h】

End-host Authentication and Authorization for Middleboxes based on a Cryptographic Namespace

机译:基于加密命名空间的终端主机身份验证和授权

获取原文

摘要

Today, middleboxes such as firewalls and network address translators have advanced beyond simple packet forwarding and address mapping. They also inspect and filter traffic, detect network intrusion, control access to network resources, and enforce different levels of quality of service. The cornerstones for these security-related network services are end-host authentication and authorization. Using a cryptographic namespace for end-hosts simplifies these tasks since it gives them an explicit and verifiable identity. The Host Identity Protocol (HIP) is a key-exchange protocol that introduces such a cryptographic namespace for secure end-to-end communication. Although HIP was designed with middleboxes in mind, these cannot securely use its namespace because the on-path identity verification is susceptible to replay attacks. Moreover, the binding between HIP as an authentication protocol and IPsec as payload transport is insufficient because on-path middleboxes cannot securely map payload packets to a HIP association. In this paper, we propose to prevent replay attacks by allowing packet-forwarding middleboxes to directly interact with end-hosts. Also we propose a method for strengthening the binding between the HIP authentication process and its payload channel with hash-chain-based authorization tokens for IPsec. Our solution allows on-path middleboxes to efficiently leverage cryptographic end-host identities and integrates cleanly into existing standards.
机译:今天,诸如防火墙和网络地址转换器等中间盒超出了简单的数据包转发和地址映射。它们还检查和过滤流量,检测网络入侵,控制对网络资源的访问,并强制执行不同的服务级别。这些与安全相关的网络服务的基石是最终主机认证和授权。使用加密命名空间以用于最终主机简化了这些任务,因为它为他们提供了显式和可验证的身份。主机标识协议(HIP)是一个密钥交换协议,它介绍了这样的加密命名空间,以确保最终到最终通信。虽然臀部设计了用中间盒设计,但这些不能安全地使用其命名空间,因为路径上的身份验证易于重播攻击。此外,由于路径的中间箱不能将有效载荷分组牢固地将有效载荷分组牢固地将有效载荷分组牢固地将有效载荷分组牢固地将有效载荷分组牢固地将有效载荷传输映射到HIP关联。在本文中,我们建议通过允许分组转发的中间盒直接与最终主机进行交互来防止重放攻击。此外,我们提出了一种用于加强髋关节认证过程与其有效载荷信道之间的绑定的方法,其中具有基于哈希链的授权令牌,用于IPsec。我们的解决方案允许路径的中间盒有效利用加密端主机标识,并将干净整合到现有标准中。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号