• DocumentCode
    1904460
  • Title

    Sender Access Control in IP Multicast

  • Author

    Islam, Salekul ; Atwood, J. William

  • Author_Institution
    Concordia Univ., Montreal
  • fYear
    2007
  • fDate
    15-18 Oct. 2007
  • Firstpage
    79
  • Lastpage
    86
  • Abstract
    Multicasting has not been widely adopted until now, due to lack of access control over the group members. The authentication, authorization and accounting (AAA) protocols are being used successfully, in unicast communication scenarios, to control access to network resources. AAA protocols can be used for multicast applications in a similar way. However, without an effective sender access control, an adversary may exploit the existing IP multicast model, where a sender can send multicast data without prior authentication and authorization. Even a group key management protocol that efficiently distributes the encryption and the authentication keys to the receivers will not be able to prevent an adversary from spoofing the sender address and hence, flooding the data distribution tree. This can create an efficient Denial of Service attack. In previous work, we have proposed a framework for the use of AAA protocols to manage IP Multicast group membership. To prevent DoS attacks and other known attacks (e.g., replay attack), we propose in this paper an extension for sender access control. Our solution will authenticate and authorize each sender, and account for sender behavior by deploying AAA protocols. Moreover, a multicast packet will be forwarded to the distribution tree only if it is cryptographically authenticated at the entry point by the Access Router. The proposal we have presented provides a flexible authentication framework, supporting different authentication mechanisms, and is independent of the underlying routing protocol. Finally, we have extended our model to support inter-domain multicast groups.
  • Keywords
    IP networks; cryptographic protocols; multicast communication; routing protocols; telecommunication security; AAA protocols; IP multicast; access router; authentication authorization and accounting; authentication keys; data distribution tree; denial of service attack; encryption; group key management protocol; multicasting; network resources control access; receivers; routing protocol; sender access control; Access control; Access protocols; Authentication; Authorization; Communication system control; Computer crime; Cryptographic protocols; Cryptography; Multicast protocols; Unicast;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Local Computer Networks, 2007. LCN 2007. 32nd IEEE Conference on
  • Conference_Location
    Dublin
  • ISSN
    0742-1303
  • Print_ISBN
    0-7695-3000-1
  • Electronic_ISBN
    0742-1303
  • Type

    conf

  • DOI
    10.1109/LCN.2007.53
  • Filename
    4367811