Back to Search Start Over

Securing IPv6 Neighbor Discovery Address Resolution with Voucher-Based Addressing.

Authors :
Puhl, Zachary T.
Guo, Jinhua
Source :
Network (2673-8732); Sep2024, Vol. 4 Issue 3, p338-366, 29p
Publication Year :
2024

Abstract

The majority of local IPv6 networks continue to remain insecure and vulnerable to neighbor spoofing attacks. The Secure Neighbor Discovery (SEND) standard and its concomitant Cryptographically Generated Addressing (CGA) scheme were accepted by large standard bodies to codify practical mitigations. SEND and CGA have never seen widespread adoption due to their complexities, obscurity, costs, compatibility issues, and continued lack of mature implementations. In light of their poor adoption, research since their standardization has continued to find new perspectives and proffer new ideas. The orthodox solutions for securing Neighbor Discovery have historically struggled to successfully harmonize three core ideals: simplicity, flexibility, and privacy preservation. This research introduces Voucher-Based Addressing, a low-configuration, low-cost, and high-impact alternative to IPv6 address generation methods. It secures the Neighbor Discovery address resolution process while remaining simple, highly adaptable, indistinguishable, and privacy-focused. Applying a unique concoction of cryptographic key derivation functions, link-layer address binding, and neighbor consensus on the parameters of address generation, the resolved address bindings are verifiable without the need for complex techniques that have hindered the adoption of canonical specifications. [ABSTRACT FROM AUTHOR]

Details

Language :
English
ISSN :
26738732
Volume :
4
Issue :
3
Database :
Complementary Index
Journal :
Network (2673-8732)
Publication Type :
Academic Journal
Accession number :
180069792
Full Text :
https://doi.org/10.3390/network4030016