Personal tools
You are here: Home Team René Hummen Publications René Hummen End-host Authentication and Authorization for Middleboxes based on a Cryptographic Namespace
Document Actions

Tobias Heer, René Hummen, Miika Komu, Stefan Götz, and Klaus Wehrle (2009)

End-host Authentication and Authorization for Middleboxes based on a Cryptographic Namespace

In: Proceedings of the IEEE International Conference on Communications 2009 (ICC 2009), IEEE, Dresden, Germany.

Today, middleboxes such as firewalls and network address translators have advanced beyond simple packet forwarding and address mapping. They also inspect and filter traffic, detect network intrusion, control access to network resources, and enforce different levels of quality of service. The cornerstones for these security-related network services are end-host authentication and authorization. Using a cryptographic namespace for end-hosts simplifies these tasks since it gives them an explicit and verifiable identity. The Host Identity Protocol (HIP) is a key-exchange protocol that introduces such a cryptographic namespace for secure end-to-end communication. Although HIP was designed with middleboxes in mind, these cannot securely use its namespace because the on-path identity verification is susceptible to replay attacks. Moreover, the binding between HIP as an authentication protocol and IPsec as payload transport is insufficient because on-path middleboxes cannot securely map payload packets to a HIP association. In this paper, we propose to prevent replays attack by treating packet-forwarding middleboxes as first-class citizens that directly interact with end-hosts. Also we propose a method for strengthening the binding between the HIP authentication process and its payload channel with hash-chain-based authorization tokens for IPsec. Our solution allows on-path middleboxes to efficiently leverage cryptographic end-host identities and integrates cleanly into existing protocol standards.



Download PDF
by Klaus Wehrle last modified 2009-06-25 12:23
« November 2009 »
Su Mo Tu We Th Fr Sa
1234567
891011121314
1516 1718192021
22232425262728
2930
How does the Internet work?
Wie funktioniert das Internet?
Wie funktioniert das Internet? - Explaining the Internet to Kids
P2P'08 at RWTH
The 8th International Conference on Peer-to-Peer Computing (P2P'08)
www.p2p08.org
 

Powered by Plone