IPv6地址空间巨大,IPv6单播地址可分为网络前缀和接口标识两部分,网络前缀由运营商(ISP,Internet service provider)分配,接口标识可以手工配置、随机生成或者通过EUI-64格式生成。手工配置或通过EUI-64格式生成的静态IPv6地址存在个人...IPv6地址空间巨大,IPv6单播地址可分为网络前缀和接口标识两部分,网络前缀由运营商(ISP,Internet service provider)分配,接口标识可以手工配置、随机生成或者通过EUI-64格式生成。手工配置或通过EUI-64格式生成的静态IPv6地址存在个人隐私泄露的网络安全风险;随机生成的IPv6地址不满足基于IP地址的网络访问控制需求。因此,提出了一种基于祖冲之(ZUC,ZU Chongzhi)加密的IPv6地址动态编码(ZBDA,ZUC-based dynamic addressing)算法,将网络终端的MAC地址通过ZUC算法加密生成动态的IPv6地址,在接收端解密即可获得终端的MAC地址,以此验证终端的访问权限。ZBDA算法既解决了不当的IPv6地址编址带来的个人隐私泄露问题,又满足了基于IP地址的网络访问控制需求,且该算法的IPv6地址编码和地址验证速度快,具有实际应用价值。展开更多
In IPv6 based MANETs, the neighbor discovery enables nodes to self-configure and communicate with neighbor nodes through autoconfiguration. The Stateless address autoconfiguration(SLAAC) has proven to face several sec...In IPv6 based MANETs, the neighbor discovery enables nodes to self-configure and communicate with neighbor nodes through autoconfiguration. The Stateless address autoconfiguration(SLAAC) has proven to face several security issues. Even though the Secure Neighbor Discovery(SeND) uses Cryptographically Generated Addresses(CGA) to address these issues, it creates other concerns such as need for CA to authenticate hosts, exposure to CPU exhaustion attacks and high computational intensity. These issues are major concern for MANETs as it possesses limited bandwidth and processing power. The paper proposes empirically strong Light Weight Cryptographic Address Generation(LW-CGA) using entropy gathered from system states. Even the system users cannot monitor these system states; hence LW-CGA provides high security with minimal computational complexity and proves to be more suitable for MANETs. The LW-CGA and SeND are implemented and tested to study the performances. The evaluation shows that LW-CGA with good runtime throughput takes minimal address generation latency.展开更多
文摘In IPv6 based MANETs, the neighbor discovery enables nodes to self-configure and communicate with neighbor nodes through autoconfiguration. The Stateless address autoconfiguration(SLAAC) has proven to face several security issues. Even though the Secure Neighbor Discovery(SeND) uses Cryptographically Generated Addresses(CGA) to address these issues, it creates other concerns such as need for CA to authenticate hosts, exposure to CPU exhaustion attacks and high computational intensity. These issues are major concern for MANETs as it possesses limited bandwidth and processing power. The paper proposes empirically strong Light Weight Cryptographic Address Generation(LW-CGA) using entropy gathered from system states. Even the system users cannot monitor these system states; hence LW-CGA provides high security with minimal computational complexity and proves to be more suitable for MANETs. The LW-CGA and SeND are implemented and tested to study the performances. The evaluation shows that LW-CGA with good runtime throughput takes minimal address generation latency.