通信学报
通信學報
통신학보
JOURNAL OF CHINA INSTITUTE OF COMMUNICATIONS
2013年
1期
171-177
,共7页
陈越%贾洪勇%谭鹏许%邵婧
陳越%賈洪勇%譚鵬許%邵婧
진월%가홍용%담붕허%소청
源地址验证%基于身份的密码%密码生成地址%消息认证码%流认证
源地阯驗證%基于身份的密碼%密碼生成地阯%消息認證碼%流認證
원지지험증%기우신빈적밀마%밀마생성지지%소식인증마%류인증
source addresses verification%identity based cryptography%cryptographically generated address%message authentication codes%stream authentication
提出了一种以密码学方法实现的 IPv6接入子网主机高速源地址验证方案.把主机 MAC 地址作为身份同主机公钥相绑定,利用密码生成地址算法从主机公钥衍生出 IPv6接入子网地址,通过数字签名提供主机真实性的验证,以消息认证码和流认证技术实现接入网关对数据分组流 IPv6地址的快速安全的验证.原型系统实验表明,该方案能够以低开销实现数据分组源地址验证,是一种安全、可行的方案.
提齣瞭一種以密碼學方法實現的 IPv6接入子網主機高速源地阯驗證方案.把主機 MAC 地阯作為身份同主機公鑰相綁定,利用密碼生成地阯算法從主機公鑰衍生齣 IPv6接入子網地阯,通過數字籤名提供主機真實性的驗證,以消息認證碼和流認證技術實現接入網關對數據分組流 IPv6地阯的快速安全的驗證.原型繫統實驗錶明,該方案能夠以低開銷實現數據分組源地阯驗證,是一種安全、可行的方案.
제출료일충이밀마학방법실현적 IPv6접입자망주궤고속원지지험증방안.파주궤 MAC 지지작위신빈동주궤공약상방정,이용밀마생성지지산법종주궤공약연생출 IPv6접입자망지지,통과수자첨명제공주궤진실성적험증,이소식인증마화류인증기술실현접입망관대수거분조류 IPv6지지적쾌속안전적험증.원형계통실험표명,해방안능구이저개소실현수거분조원지지험증,시일충안전、가행적방안.
A cryptographically-implemented high-speed source address verification scheme for the hosts in the IPv6 ac-cess subnet was proposed. The MAC address was used as the identity of the host machine and bounded with the host’s public key. Then the IPv6 address was derived from the host machine’s public key using the cryptographically generated address algorithm. The address authenticity was guaranteed by the digital signature and the fast and secure source address verification for packet stream was achieved through message authentication code algorithm and stream authentication. The experimental system show that the scheme could verify the source addresses of data packets at a loss cost. Thus, it is a secure and feasible scheme.