IPv6 address obfuscation by intermediate middlebox in coordination with connected devices - INRIA - Institut National de Recherche en Informatique et en Automatique Accéder directement au contenu
Communication Dans Un Congrès Année : 2013

IPv6 address obfuscation by intermediate middlebox in coordination with connected devices

Résumé

Privacy is a major concern on the current Internet, but transport mechanisms like IPv4 and more specifically IPv6 do not offer the necessary protection to users. However, the IPv6 address size allows designing privacy mechanisms impossible in IPv4. Nevertheless existing solutions like Privacy Extensions are not optimal, still only one address is in use for several communications over time. And it does not offer control of the network by the administrator (end devices use randomly generated addresses). Our IPv6 privacy proposal uses ephemeral addresses outside the trusted network but stable addresses inside the local network, allowing the control of the local network security by the administrator. Our solution is based on new opportunities of IPv6: a large address space and a new flow label field. In combination with Cryptographically Generated Addresses, we can provide protection against spoofing on the local network and enhanced privacy for Internet communication.
Fichier principal
Vignette du fichier
papier.pdf (314.05 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)

Dates et versions

hal-00861078 , version 1 (11-09-2013)

Identifiants

  • HAL Id : hal-00861078 , version 1

Citer

Florent Fourcot, Laurent Toutain, Frédéric Cuppens, Nora Cuppens-Bouhlahia, Stefan Köpsell. IPv6 address obfuscation by intermediate middlebox in coordination with connected devices. EUNICE 2013 : 19th EUNICE/IFIP WG 6.6 International Workshop, Aug 2013, Chemnitz, Germany. pp.148 - 160. ⟨hal-00861078⟩
387 Consultations
187 Téléchargements

Partager

Gmail Facebook X LinkedIn More