ON DHCP SECURITY

被引:0
|
作者
Dinu, Dumitru Daniel [1 ]
Togan, Mihai [1 ]
Bica, Ion [1 ]
机构
[1] Mil Tech Acad, Dept Comp Sci, Bucharest, Romania
来源
PROCEEDINGS OF THE ROMANIAN ACADEMY SERIES A-MATHEMATICS PHYSICS TECHNICAL SCIENCES INFORMATION SCIENCE | 2017年 / 18卷
关键词
DHCP; authentication module; authentication option; trust model; digital signature; replay detection; PKI; PGP;
D O I
暂无
中图分类号
O [数理科学和化学]; P [天文学、地球科学]; Q [生物科学]; N [自然科学总论];
学科分类号
07 ; 0710 ; 09 ;
摘要
Despite the security issues it has, DHCP is one of the most used protocols because it facilitates the automatic allocation of the configuration information in a network. While the number of mobile devices connected to Internet is increasing exponentially, the widespread adoption of IPv6 will take a lot of time. In this context, the need for good security mechanisms that prevents the known attacks against DHCP raises. In this paper we present an overview of the previous solutions to secure the protocol and, in the same time, we identify the reasons why each of these attempts failed. Based on the previous work missteps, we define a set of requirements for a practical and efficient authentication module for DHCP. Then we introduce a simple and flexible module that allows authentication of DHCP messages using two different trust models: PKI and PGP. We implemented and evaluated the proposed authentication module using different key types and sizes in the two trust models. The comprehensive results show that the proposed authentication module does not affect the protocol operation, but provides the so necessary security that DHCP lacks.
引用
收藏
页码:403 / 412
页数:10
相关论文
共 50 条