首页> 外文会议>North-East Asia Symposium on Nano, Information Technology and Reliability >Security and privacy produced by DHCP unique identifiers
【24h】

Security and privacy produced by DHCP unique identifiers

机译:DHCP唯一标识符产生的安全和隐私

获取原文

摘要

As protection against the current privacy weaknesses of StateLess Address AutoConfiguration (SLAAC) in the Internet Protocol version 6 (IPv6), network administrators may choose to deploy the new Dynamic Host Configuration Protocol for IPv6 (DHCPv6). Similar to the Dynamic Host Configuration Protocol (DHCP) for the Internet Protocol version 4 (IPv4), DHCPv6 uses a client-server model to manage addresses in networks, providing stateful address assignment. While DHCPv6 can be configured to assign randomly distributed addresses to clients, the DHCP Unique Identifier (DUID) was designed to identify uniquely identify clients to servers and remains static to clients as they move between different subnets and networks. Since the DUID is globally unique and exposed in the clear, attackers can geotemporally track clients by sniffing DHCPv6 messages on the local network or by using unauthenticated protocol-valid queries that request systems' DUIDs or leased addresses. DUIDs can also be formed with system-specific information, further compromising the privacy and security of the host. To combat the threat of the static DUID, a dynamic DUID was implemented and analyzed for its effect on privacy and security as well as its computational overhead. The privacy implications of DHCPv6 must be addressed before large-scale IPv6 deployment.
机译:作为对在Internet协议版本6(IPv6)的无状态地址自动配置(SLAAC)当前隐私保护的弱点,网络管理员可以选择部署IPv6的新的动态主机配置协议(DHCPv6报)。类似于动态主机配置协议(DHCP)Internet协议版本4(IPv4)后,DHCPv6使用客户端 - 服务器模型在网络管理地址,提供有状态地址分配。虽然的DHCPv6可以被配置为随机分布的地址分配给客户端时,DHCP唯一标识符(DUID)被设计来识别唯一识别客户端到服务器和保持静止的客户,因为它们不同子网和网络之间移动。由于DUID是全局唯一的,并在暴露清晰,攻击者可以geotemporally通过嗅探本地网络上的DHCPv6报文,或通过使用未认证的协议有效查询追踪客户端请求系统DUIDs或租用的地址。 DUIDs也可以用系统特定信息形成,进一步损害主机的隐私和安全。为了解决静态DUID的威胁,动态DUID年实施的,以及它的计算开销,其对隐私和安全的影响进行分析。 DHCPv6协议中的隐私问题必须在大规模部署IPv6来解决。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号