DocumentCode
1904460
Title
Sender Access Control in IP Multicast
Author
Islam, Salekul ; Atwood, J. William
Author_Institution
Concordia Univ., Montreal
fYear
2007
fDate
15-18 Oct. 2007
Firstpage
79
Lastpage
86
Abstract
Multicasting has not been widely adopted until now, due to lack of access control over the group members. The authentication, authorization and accounting (AAA) protocols are being used successfully, in unicast communication scenarios, to control access to network resources. AAA protocols can be used for multicast applications in a similar way. However, without an effective sender access control, an adversary may exploit the existing IP multicast model, where a sender can send multicast data without prior authentication and authorization. Even a group key management protocol that efficiently distributes the encryption and the authentication keys to the receivers will not be able to prevent an adversary from spoofing the sender address and hence, flooding the data distribution tree. This can create an efficient Denial of Service attack. In previous work, we have proposed a framework for the use of AAA protocols to manage IP Multicast group membership. To prevent DoS attacks and other known attacks (e.g., replay attack), we propose in this paper an extension for sender access control. Our solution will authenticate and authorize each sender, and account for sender behavior by deploying AAA protocols. Moreover, a multicast packet will be forwarded to the distribution tree only if it is cryptographically authenticated at the entry point by the Access Router. The proposal we have presented provides a flexible authentication framework, supporting different authentication mechanisms, and is independent of the underlying routing protocol. Finally, we have extended our model to support inter-domain multicast groups.
Keywords
IP networks; cryptographic protocols; multicast communication; routing protocols; telecommunication security; AAA protocols; IP multicast; access router; authentication authorization and accounting; authentication keys; data distribution tree; denial of service attack; encryption; group key management protocol; multicasting; network resources control access; receivers; routing protocol; sender access control; Access control; Access protocols; Authentication; Authorization; Communication system control; Computer crime; Cryptographic protocols; Cryptography; Multicast protocols; Unicast;
fLanguage
English
Publisher
ieee
Conference_Titel
Local Computer Networks, 2007. LCN 2007. 32nd IEEE Conference on
Conference_Location
Dublin
ISSN
0742-1303
Print_ISBN
0-7695-3000-1
Electronic_ISBN
0742-1303
Type
conf
DOI
10.1109/LCN.2007.53
Filename
4367811
Link To Document