DocumentCode :
2038828
Title :
Certificate path generating protocol (CPGP) for authenticated signaling in ATM networks
Author :
Xu, Jun ; Singhal, Mukesh
Author_Institution :
Dept. of Comput. & Inf. Sci., Ohio State Univ., Columbus, OH, USA
fYear :
1998
fDate :
13-16 Oct 1998
Firstpage :
282
Lastpage :
289
Abstract :
Authenticated signaling is an important security service to be provided by ATM networks to guard against threats of spoofing and impersonation. The ATM Forum specifies public key cryptography to be the default ATM authentication mechanism and directory services like X.509 to be the infrastructure for public key distribution and certification. With public key cryptography, authenticated signaling requires the signaling message to be authenticated with a digital signature signed by the private key of the calling party. To verify the digital signature, the called party needs to obtain the public key of the calling party and a proof of the calling party´s ownership to that public key. In X.509, the standard form of such a proof is a chain of public key certificates, called the certificate path between two parties. The certificate exchange protocol (CEP), proposed by the ATM Forum, requires that another bi-directional connection be established between two parties to change public keys and certificate paths before an authenticated connection can be established, which is not an ideal approach. We propose a certificate path generating protocol (CPGP), which is embedded into ATM signaling and routing protocols to generate a certificate path inside a signaling message on-the-fly as the signaling message travels through the ATM network. In CPGP all that a calling party needs to do for authenticated signaling is to put into the signaling message its own public key certificate and the digital signature of the signaling message signed using its private key. The CPGP builds the rest of the certificate path for it. The proposed protocol is embedded into the ATM signaling and routing protocol so that no performance overhead is incurred to establish the certificate path
Keywords :
asynchronous transfer mode; message authentication; public key cryptography; telecommunication network routing; telecommunication signalling; transport protocols; ATM Forum; ATM networks; ATM signaling protocols; CPGP; X.509; authenticated signaling; authentication mechanism; bi-directional connection; called party; calling party; certificate exchange protocol; certificate path generating protocol; digital signature; directory services; impersonation; private key; public key certificates; public key certification; public key cryptography; public key distribution; routing protocols; security service; spoofing; Authentication; Computer networks; Computer security; Information science; Information security; Intelligent networks; Protocols; Public key; Public key cryptography; Signal generators;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Network Protocols, 1998. Proceedings. Sixth International Conference on
Conference_Location :
Austin, TX
Print_ISBN :
0-8186-8988-9
Type :
conf
DOI :
10.1109/ICNP.1998.723749
Filename :
723749
Link To Document :
بازگشت