首页> 外文OA文献 >Cryptographically generated addresses (CGAs): possible attacks and proposed mitigation approaches
【2h】

Cryptographically generated addresses (CGAs): possible attacks and proposed mitigation approaches

机译:密码生成的地址(CGa):可能的攻击和建议的缓解方法

摘要

Cryptographically Generated Addresses (CGAs) were mainly designed to prove address ownership and to prevent the theft of existing IPv6 addresses by binding the owner’s public key to the generated address. The address owner uses a corresponding private key to prove its ownership by using signedmessages that are originated from that address. Though the CGA approach is quite useful in providing a means of proving address ownership in IPv6 networks, it does have some limitations andsome vulnerabilities. In this paper we will provide a security analysis and descriptions of possible ways of attacking CGA. We found that the CGA verification process is prone mainly to Denial-of-Service (DoS) attacks. We also found that CGAs are still susceptible to privacy related attacks. We will therefore propose some extensions to the CGA standard verification algorithm to mitigate DoS attacks and to make CGA more privacy-conscious
机译:密码生成的地址(CGA)的主要目的是证明地址所有权,并通过将所有者的公钥绑定到生成的地址来防止现有的IPv6地址被盗。地址所有者使用对应的私钥通过使用源自该地址的签名消息来证明其所有权。尽管CGA方法在提供一种证明IPv6网络中的地址所有权的方法中非常有用,但它确实存在一些局限性和一些漏洞。在本文中,我们将提供安全性分析以及对攻击CGA的可能方法的描述。我们发现CGA验证过程主要倾向于拒绝服务(DoS)攻击。我们还发现,CGA仍然容易受到与隐私相关的攻击的影响。因此,我们将对CGA标准验证算法提出一些扩展,以减轻DoS攻击并提高CGA的隐私意识

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号