DHCPv6Auth: a mechanism to improve DHCPv6 authentication and privacy

被引:9
作者
Al-Ani, Ayman [1 ]
Anbar, Mohammed [1 ]
Al-Ani, Ahmed K. [1 ]
Hasbullah, Iznan Husainy [1 ]
机构
[1] Univ Sains Malaysia, Natl Adv IPv6 Ctr NAv6, Gelugor, Penang, Malaysia
来源
SADHANA-ACADEMY PROCEEDINGS IN ENGINEERING SCIENCES | 2020年 / 45卷 / 01期
关键词
Rogue DHCPv6 server; privacy; DHCPv6; IPv6; digital signature; DoS;
D O I
10.1007/s12046-019-1244-4
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Internet Protocol version 6 (IPv6) deployment continues to gain ground due to the increasing demand for IP addresses generated by the number of Internet facing devices, and it is compounded by the exhaustion of allocatable IPv4 addresses. Dynamic Host Configuration Protocol version 6 (DHCPv6) is used to allocate IPv6 addresses and distribute network configuration information to IPv6 hosts in a link-local network. However, DHCPv6 messages in transit expose identifiable information of the DHCPv6 client that could be used by malicious users to track their victims. Additionally, the lack of an authentication mechanism leaves IPv6 hosts vulnerable to rogue DHCPv6 server attacks. This paper introduces DHCPv6 Authentication (DHCPv6Auth) mechanism to prevent rogue DHCPv6 server attacks and protect the privacy of IPv6 hosts. DHCPv6Auth uses the Ed25519 digital signature algorithm for authentication and could be used in conjunction with Anonymity Profile mechanisms for privacy protection. The DHCPv6Auth mechanism was compared with other mechanisms in terms of processing time, prevention of rogue DHCPv6 server attack, and protection of users' privacy. The results show that it requires less processing time and traffic overhead than other authentication mechanisms; is able to prevent rogue DHCPv6 server attacks; and provides better privacy protection for the IPv6 host than other authentication mechanisms to which it was compared.
引用
收藏
页数:11
相关论文
共 44 条
  • [1] Discrete Event System Framework for Fault Diagnosis with Measurement Inconsistency: Case Study of Rogue DHCP Attack
    Agarwal, Mayank
    Biswas, Santosh
    Nandi, Sukumar
    [J]. IEEE-CAA JOURNAL OF AUTOMATICA SINICA, 2019, 6 (03) : 789 - 806
  • [2] [Anonymous], 2013, J ENG COMPUTER SCI
  • [3] [Anonymous], 2018, STAT IPV6 DEPL 2018
  • [4] [Anonymous], INT J SOFTW ENG COMP
  • [5] [Anonymous], IOSR J COMPUT ENG
  • [6] Asadi A, 2015, 2015 IEEE 16TH INTERNATIONAL SYMPOSIUM ON A WORLD OF WIRELESS, MOBILE AND MULTIMEDIA NETWORKS (WOWMOM), DOI 10.1109/WoWMoM.2015.7158141
  • [7] Atlasis A, 2015, IPV6 ROUTER ADVERTIS
  • [8] Beeharry J, 2016, 2016 IEEE INTERNATIONAL CONFERENCE ON EMERGING TECHNOLOGIES AND INNOVATIVE BUSINESS PRACTICES FOR THE TRANSFORMATION OF SOCIETIES (EMERGITECH), P336, DOI 10.1109/EmergiTech.2016.7737362
  • [9] Dinu D. D., 2014, P 10 INT C COMM COMM, P1
  • [10] Droms R., 2001, AUTHENTICATION DHCP