The Design and Implementation of Secure Socket SCTP

被引:0
作者
Lindskog, Stefan [1 ]
Brunstrom, Anna [2 ]
机构
[1] Norwegian Univ Sci & Technol, Ctr Quantifiable Qual, Serv Commun Syst, N-7034 Trondheim, Norway
[2] Karlstad Univ, Dept Comp Sci, karlstad, Sweden
来源
TRANSACTIONS ON COMPUTATIONAL SCIENCE VI | 2009年 / 5730卷
关键词
SCTP; end-to-end security; protocol design; implementation; packet protection; security differentiation; message complexity; TRANSPORT;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
This paper describes the design and implementation of secure socket SCTP ((SSCTP)-S-2). (SSCTP)-S-2 is a new multi-layer, end-to-end security solution for SCTP. It uses the AUTH protocol extension of SCTP for integrity protection of both control and user messages; TLS is the proposed solution for authentication and key agreement; Data confidentiality is provided through encryption and decryption at the socket library layer. (SSCTP)-S-2 is designed to offer as much security differentiation support as possible using standardized solutions and mechanisms. En the paper, (SSCTP)-S-2 is also compared to SCTP over IPsec and TLS over SCTP in terms of packet protection, security differentiation, and message complexity. The following main conclusions can be draw from the comparison. (SSCTP)-S-2 compares favorably in terms of offered security differentiation and message overhead. Confidentiality protection of SCTP control information is, however, only offered by SCTP over IPsec.
引用
收藏
页码:180 / +
页数:4
相关论文
共 30 条
  • [1] [Anonymous], IETF STANDARDS
  • [2] [Anonymous], 5062 RFC
  • [3] [Anonymous], 5061 RFC
  • [4] [Anonymous], 2007, STREAM CONTROL TRANS
  • [5] [Anonymous], 2005, 4301 RFC
  • [6] [Anonymous], 2006, RFC 4347
  • [7] BELLOVIN S, 2003, 3554 RFC
  • [8] Daemen Joan, 2020, The Design Of Rijndael, V2nd
  • [9] Dierks T., 1999, 2246 RFC, DOI 10.17487/RFC2246
  • [10] Dierks Tim, 2006, 4346 RFC, V4346, P1