[sidr] FW: I-D Action: draft-rafiee-6man-ssas-05.txt

"Murphy, Sandra" <Sandra.Murphy@sparta.com> Tue, 16 July 2013 15:28 UTC

I just noticed this and thought it might be of interest.  This draft proposes a new mechanism to generate IPv6 interface identifiers (IID). Please note the reference to the use of the RPKI - described in section 4.3.

--Sandy, speaking as regular ol' member

A New Internet-Draft is available from the on-line Internet-Drafts directories.

        Title           : A Simple Secure Addressing Scheme for IPv6 AutoConfiguration (SSAS)
        Author(s)       : Hosnieh Rafiee
                          Christoph Meinel
        Filename        : draft-rafiee-6man-ssas-05.txt
        Pages           : 19
        Date            : 2013-07-15

   The default method for IPv6 address generation uses an
   Organizationally Unique Identifier (OUI) assigned by the IEEE
   Standards Association and an Extension Identifier assigned to the
   hardware manufacturer [1] (section 2.5.1 RFC-4291) [RFC4291]. This
   fact thus means that a node will always have the same Interface ID
   (IID) whenever it connects to a new network. Because the node's IP
   address does not change, the node will be vulnerable to privacy
   related attacks. Currently this problem is addressed by the use of
   two mechanisms that do not make use of the MAC address, or other
   unique values that can be used for ID generation, for randomizing the
   IID; Cryptographically Generated Addresses (CGA) [RFC3972] and
   Privacy Extension [RFC4941]. The problem with the former approach is
   the computational cost involved for the IID generation and in the
   verification process. The problem with the latter approach is that it
   lacks necessary security mechanisms and provides the node with only
   partial protection against privacy related attacks. This document
   proposes the use of a new algorithm for use in the generation of the
   IID while, at the same time, securing the node against some types of
   attack, like IP spoofing. These attacks are prevented by the addition
   of a signature to messages sent over the network and by finding a
   binding with the nodes' IP address and its public key. The use of
   theResource Public Key Infrastructure (RPKI), introduced in this
   document, is based on the centralized version explained in RFC 6494
   and RFC 6495.

