Font Size: a A A

Research And Implementation Of IPv6Stateless Address Auto-configuration System Based On Authentication

Posted on:2013-10-31Degree:MasterType:Thesis
Country:ChinaCandidate:L ZhaoFull Text:PDF
GTID:2268330425997344Subject:Computer application technology
Abstract/Summary:PDF Full Text Request
With the rapid development of Internet technology. IPv6replaces IPv4as the main protocol in the next generation internet is an inevitable trend. Meanwhile, the potential security danger caused by the openness of IPv6and the inherent vulnerability of network takes place constantly in the network. In the access stage of IPv6network, IPv6node can realize the IPv6stateless address auto-configuration without any manual configuration of address or parameter in configuration process, which makes the address configuration process of IPv6node out of control. It is prohibited that illegal users access the network and get vital information freely. So, controlling the users’ secure access becomes an urgent problem.This thesis put forward a new scheme that IPv6stateless address auto-configuration based on authentication, which takes the IPv6module of the Linux kernel as foundation and according to the routing discovery process of IPv6stateless address auto-configuration. In this scheme.ICMPv6router solicitation message and router advertisement message are used to carry the authentication information, which forms authentication-based router solicitation and router advertisement technology. In order to guarantee the confidential and security of the authentication information, this system uses the RSA asymmetric encryption algorithm information to encrypt the authentication. This scheme realizes a lightweight security access IPv6system, in which only authorized nodes can obtain IPv6address. It not only keeps the function of plug and play of IPv6working well, but also solves the problem that IPv6monitor the node on the lowest level. All these guarantee the security of the network from the beginning.Firstly, this thesis begins with detailed description of the current solutions and the characteristic of IPv6, at the same. ICMPv6and other relevant protocols was given. This thesis focuses on stateless address auto-configuration theory, RSA asymmetric encryption algorithm, tools of Linux kernel module programming. In the introduction of overall design and function implementation, first of all, the overall design and solution are introduced. And also the process of setting up system environment is described. Next, the scheme and structure of secure IPv6accessing system based on authentication are discussed, and the framework of the system is constructed. In addition, the design of each module and the working relationship between each module are introduced and the modified router discovery technology is introduced in detail. In the end, the system constructed in this thesis is tested in experimental environment, and obtaines satisfactory results.
Keywords/Search Tags:IPv6, Address auto-configuration, Authentication mechanism, Informationsecurity
PDF Full Text Request
Related items