Securing Group Management in IPv6 with Cryptographically Generated Addresses

  • Authors:
  • Claude Castelluccia;Gabriel Montenegro

  • Affiliations:
  • -;-

  • Venue:
  • ISCC '03 Proceedings of the Eighth IEEE International Symposium on Computers and Communications
  • Year:
  • 2003

Quantified Score

Hi-index 0.00

Visualization

Abstract

Currently, group membership management in IP Multicastand Anycast can be abused in order to launch denial-of-service (DoS) attacks. The root of the problem is thatrouters cannot determine if a given host is authorized tojoin a group (this is sometimes referred to as the Proof-of-MembershipProblem [1]). We propose a solution for IPv6based on Group Cryptographically Generated Addresses(G-CGA). These addresses have characteristics of statisticaluniqueness and cryptographic verifiability that lendthemselves to severely limiting certain classes of DoS attacks.Our scheme is fully distributed and does not requireany trusted third party or pre-established security associationbetween the routers and the hosts. This is not only ahuge gain in terms of scalability, reliability and overhead,but also in terms of privacy.