期刊文献+

基于实体认证的安全DHCPv6系统实现 被引量:1

Implementation of a secure DHCPv6 system with entity authentication
下载PDF
导出
摘要 随着IPv6的不断发展,DHCPv6协议为IPv6环境下地址分配提供了极大的便利,但由于DHCPv6协议是基于DHCP协议进行扩展设计与实现,依然面临着许多安全威胁。本文提出并实现了一个具有实体认证功能的安全DHCPv6系统,在不改变现有协议的情况下对DHCPv6消息进行认证,保证传输安全。同时,DH-CPv6服务器为每个合法客户端分配与其公钥绑定的地址,与DHCP Snooping结合保证源地址的真实性,有效防止了非法用户的网络接入。该系统在校园网环境内进行部署和实验,验证了其设计的安全性与可靠性,可抵御多种常见网络攻击。 As the development of IPv6, configuring and managing IP address become more and more convenient by DHCPv6. However, since DHCPv6 is based on DHCP,there are many security short- comings and it is vulnerable to many network attacks. This paper proposes a novel secure DHCPv6 system which integrates entity authentication. The system authenticates messages without changing the original protocol which protects the security of transmission. In addition, because DHCPv6 server allocates public key binded addresses to legal clients and combined with DHCP Snooping, Illegal clients cannot access the network and the authenticity of source address can be assured. On the campus network, the efficient and security of the DHCPv6 was verified as being capable of preventting many network attacks.
出处 《广西大学学报(自然科学版)》 CAS CSCD 北大核心 2011年第A01期201-205,217,共6页 Journal of Guangxi University(Natural Science Edition)
基金 国家科技支撑计划资助课题(2008BAH37B10 2008BAH37B05001)
关键词 DHCPV6 DHCP安全 实体认证 消息认证 公钥绑定地址 DHCPv6 DHCP security entity authentication message authentication public key binding address
  • 相关文献

参考文献13

  • 1Droms R. Dynamic Host Configuration Protocol [ EB/OL]. RFC 2131, http://www, ietf. org/rfc/rfc2131, txt, 1997.
  • 2Croft B, Gilmore J. BOOTSTRAP PROTOCOL [ EB/OL]. RFC 951, http ://tools. ieff. org/html/rfe951, 1985.
  • 3Smith L, Lipner I. Free Pool of IPv4 Address Space Depleted [ EB/OL]. Number Resource Organization. http:/! www. nro. net/news/ipv4-free-pool-depleted, 2011.
  • 4Two/8s allocated to APNIC from IANA, [ EB/OL]. http ://www. apnic, net/publications/news/2011/delegation, 2011.
  • 5Droms R, Bound J, Packard H. Dynamic Host Configuration Protocol for IPv6 [ EB/OL ] . RFC 3315, http:// www. ietf. org/rfc/rfc3315, txt, 2003.
  • 6Droms R. Stateless Dynamic Host Configuration Protocol (DHCP) Service for IPv6 [ EB/OL]. RFC3736, http:// tools, ietf. org/html/rfc3736, 2004.
  • 7Yun Y, Mi J. Design of DHCP Protocol based on Access Control and SAKA Encryption Algorithm [ J ]. Computer Engineering and Technology, 2009.
  • 8Aura T, Cryptographieally Generated Addresses (CGA) [ EB/OL ]. RFC 3972, http ://www. ieff. org/rfe/rfe3972, txt, 2005.
  • 9Demerjian J, Serhrouchni A. DHCP Authentication Using Certificates [ J ]. Security and Protection in Information Processing Systems, 2004.
  • 10Glazer G, Hussey C, Shea R. Certificate-Based Authentication for DHCP [ EB/OL ]. http ://www. thesnowpit, com/research/other/cbda, pdf, 2003.

同被引文献11

引证文献1

二级引证文献2

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部