DocumentCode
3644300
Title
Deploying new hash algorithms in Secure Neighbor Discovery
Author
Valter Vasić;Ana Kukec;Miljenko Mikuc
Author_Institution
University of Zagreb
fYear
2011
Firstpage
1
Lastpage
5
Abstract
IP protocol version 6 (IPv6), a successor of IP protocol version 4 (IPv4), puts a significant effort in enhancing security facilities. Secure Neighbor Discovery (SEND) is an optional IPv6 protocol that counters threats in link-local communication allowed by Neighbor Discovery protocol (NDP). It protects from attacks against the integrity and authentication capabilities, relying on trustworthiness of cryptographic hash functions. After a recent discovery of reduced hash function resistance, their efficiency has been called into question. Attacks against the collision-free property of hash functions lead to the reexamination of how Internet protocols use hashes. In the paper we contribute with analyzes of attacks on hash functions, use of hashes in SEND, impact of hash attacks on each use of hash functions in SEND, propose and evaluate possible approaches to allowing hash agility, and finally propose the most efficient solution - a solution for SEND hash agility based on a negotiation approach.
Keywords
"Protocols","Digital signatures","Public key","Internet","Authorization"
Publisher
ieee
Conference_Titel
Software, Telecommunications and Computer Networks (SoftCOM), 2011 19th International Conference on
Print_ISBN
978-1-4577-1439-9
Type
conf
Filename
6064420
Link To Document