CGA as alternative security credentials with IKEv2 : implementation and analysis - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès SAR-SSI '12 : 7th Conference on Network Architectures and Information Systems Security Année : 2012

CGA as alternative security credentials with IKEv2 : implementation and analysis

Résumé

Internet Protocol security (IPsec) is a protocol suite enabling secure IP communications by authentication and/or encryption. Internet Key Exchange version 2 (IKEv2) mechanism is recommended to configure dynamically IPsec between IP nodes and the authentication of each peer is usually based on either pre-shared keys, X.509 certificates or Extensible Authentication Protocol (EAP). However, these methods may have drawbacks. On the other hand, Cryptographically Generated Addresses (CGA), IPv6 addresses with specific security properties, are the main component of the mechanism to secure the IPv6 Neighbor Discovery protocol but these security properties are only used in a local scope. An interesting solution could be the use of CGA as alternative security material for IKEv2. In this paper, we analyze advantages and drawbacks of CGA use compared to classical IKEv2 security materials, decide design choices regarding modifications of IKEv2 to integrate CGA, and finally, describe the resulting implementation.
Fichier principal
Vignette du fichier
SAR-SSI-2012-JMC-IKEv2_CGA.pdf (132.13 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-00747186 , version 1 (30-10-2012)

Identifiants

  • HAL Id : hal-00747186 , version 1

Citer

Jean-Michel Combes, Aurelien Wailly, Maryline Laurent. CGA as alternative security credentials with IKEv2 : implementation and analysis. SAR-SSI '12 : 7th Conference on Network Architectures and Information Systems Security, May 2012, Cabourg, France. pp.53-59. ⟨hal-00747186⟩
113 Consultations
332 Téléchargements

Partager

Gmail Facebook X LinkedIn More