首页> 外文期刊>IEEE systems journal >Secure Route Optimization for MIPv6 Using Enhanced CGA and DNSSEC
【24h】

Secure Route Optimization for MIPv6 Using Enhanced CGA and DNSSEC

机译:使用增强型CGA和DNSSEC的MIPv6安全路由优化

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

With mobile phones evolving every year, it is no surprise that recent surveys have shown that the worldwide number of mobile phone subscriptions reached 5.6 billion in 2011, becoming the largest pool of interconnected devices. Since mobile IP is the most-used protocol by mobile operators, the obvious solution to support more users in their network would be to replace it with MIPv6. In addition to integrating the newest IP stack, MIPv6 adds an important feature meant to replace the inefficient triangle routing by allowing an MN to communicate bidirectionally with the CN without passing through its home agent. However, the lack of preshared information between the MN and CN makes security for this RO mechanism a difficult challenge. MIPv6 adopts the RR mechanism that is only to verify the MN reachability in both its home address and care-of address without being a security feature. Other works have attempted to solve the multiple security issues in RR, but either their design was flawed or their assumptions were unrealistic. This paper presents a secure MIPv6 with a secure and efficient RO that uses DNSSEC to validate CGAs from trusted domains and provides strong authentication rather than the weak sender invariance security property. It integrates an enhanced cryptographically generated address (ECGA) based on a backward key chain that offers support to bind multiple logically linked CGAs together. ECGA tackles the time-memory tradeoff attacks with high efficiency. The validation through both AVANTSSAR and AVISPA platforms show that the proposed solution has no security flaw while still being lightweight in signaling messages on the radio network.
机译:随着移动电话的每年发展,最近的调查显示,2011年全球移动电话订购量达到56亿,成为互连设备的最大池,这一点不足为奇。由于移动IP是移动运营商最常用的协议,因此在其网络中支持更多用户的明显解决方案是将其替换为MIPv6。除了集成最新的IP堆栈外,MIPv6还添加了一项重要功能,即通过允许MN与CN进行双向通信而无需经过其原籍代理,来替换低效的三角路由。但是,由于MN和CN之间缺乏预共享信息,因此该RO机制的安全性成为难题。 MIPv6采用RR机制,该机制仅用于验证MN在其本地地址和转交地址中的可达性,而不是一种安全功能。其他工作试图解决RR中的多个安全问题,但是它们的设计存在缺陷或假设不切实际。本文提出了一种具有安全高效RO的安全MIPv6,它使用DNSSEC来验证来自受信任域的CGA,并提供强身份验证,而不是弱发送者不变性安全属性。它基于后向密钥链集成了增强的加密生成地址(ECGA),该密钥链提供了将多个逻辑链接的CGA绑定在一起的支持。 ECGA可以高效地解决时间记忆权衡攻击。通过AVANTSSAR和AVISPA平台进行的验证表明,所提出的解决方案没有安全漏洞,同时在无线电网络上的信令消息方面仍然轻巧。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号