Browse > Article
http://dx.doi.org/10.13089/JKIISC.2008.18.6A.85

A Study on the Performance Improvement in SEcure Neighbor Discovery (SEND) Protocol  

Park, Jin-Ho (Hanyang University)
Im, Eul-Gyu (Hanyang University)
Abstract
Neighbor Discovery(ND) protocol is used to exchange an information of the neighboring nodes on the same link in the IPv6 protocol environment. For protecting the ND protocol, firstly utilizing Authentication Header(AH) of the IPsec protocol was proposed. But the method has some problems-uses of key exchange protocol is not available and it is hard to distribute manual keys. And then secondly the SEcure Neighbor Discovery(SEND) protocol which protects all of the ND message with digital signature was proposed. However, the digital signature technology on the basis of public key cryptography system is commonly known as requiring high cost, therefore it is expected that there is performance degradation in terms of the availability. In the paper, to improve performance of the SEND protocol, we proposed a modified CGA(Cryptographically Generated Address) which is made by additionally adding MAC(Media Access Control) address to the input of the hash function. Also, we proposed cache mechanism. We compared performance of the methods by experimentation.
Keywords
SEcure Neighbor Discovery;
Citations & Related Records
Times Cited By KSCI : 2  (Citation Analysis)
연도 인용수 순위
1 S. Kent, "IP Encapsulating Security Payload (ESP)", RFC4303, Dec 2005
2 T. Aura, "Cryptographically Generated Addresses (CGA)". RFC 3972, Mar 2005
3 J. Arkko, Ed., J. Kempf, B. Zill, P. Nikander, "SEcure Neighbor Discovery (SEND)", RFC 3971, Mar 2005
4 "RDTSC--Read Time-Stamp Counter", http:// softwarecommunity.intel.com/isn/Community/ en-US/forums /thread/30235396.aspx
5 "Intel Software Network-RDTSC Latency", http://www.intel.com/software/products/documentation/ vlin/ mergedprojects/analyzer_ec/ mergedprojects/ reference_olh/mergedProjects/instructions/ instruct32_hh/vc275.htm
6 경계현, 고광선, 엄영익, "IPv6 환경에서 해쉬함수 기반 강건한 주소 생성 및 검증 기법", 정보보호학회논문지 제17권 제1호, 2007. 2   과학기술학회마을
7 RSA Laboratories, "RSA Encryption Standard, Version 2.1", PKCS 1, Nov 2002
8 안개일, 나재훈, "IPv6 네트워크에서 SEND 프로토콜의 구현", 한국통신학회논문지 제32권 제7호, 2007. 7   과학기술학회마을
9 T. Narten, E. Nordmark, W. Simpson, "Neighbor Discovery for IP Version 6 (IPv6)", RFC 2461, Dec 1998
10 S. Kent, K. Seo, "Security Architecture for the Internet Protocol", RFC4301, Dec 2005
11 http://openssl.org/
12 R. Hinden, S. Deering, "IP Version 6 Addressing Architecture", RFC 4291, Feb 2006
13 C. Kaufman, Ed., "Internet Key Exchange (IKEv2) Protocol", RFC4306, Dec 2005
14 S. Thomson, T. Narten, "IPv6 Stateless Address Autoconfiguration", RFC 2462, Dec 1998
15 S. Deering, R. Hinden, "Internet Protocol, Version 6 (IPv6) Specification", RFC 2460, Dec 1998
16 P.Nikander, J.Kempf, E.Nordmark, "IPv6 Neighbor Discovery (ND) Trust Models and Threats", RFC 3756, May 2004
17 S. Kent, "IP Authentication Header", RFC4302, Dec 2005
18 A. Conta, S. Deering, M. Gupta, Ed., "Internet Control Message Protocol (ICMPv6) for the Internet Protocol Version 6 (IPv6) Specification", RFC4443, Mar 2006