In charge of several critical functionalities, the Neighbor Discovery Protocol (NDP) is used by IPv6 nodes to find out nodes on the link, to learn their link-layer addresses to discover routers, and to preserve reachability information about the paths to active neighbors. Given its important and multifaceted role, security and efficiency must be ensured. However, NDP is vulnerable to critical attacks such as spoofing address, denial-of-service (DoS) and reply attack. Thus, in order to protect the NDP protocol, the Secure Neighbor Discovery (SEND) was designed. Nevertheless, SEND’s protection still suffers from numerous threats and it is currently incompatible with the context of mobility and especially with the proxy Neighbor Discovery function used in Mobile IPv6. To overcome these limitations, this article defines a new protocol named Improved Secure Neighbor Discovery (ISEND) which adapt SEND protocol to the context of mobility and extend it to new functionalities. The proposed protocol (ISEND) has been modeled and verified using the Security Protocol ANimator software (SPAN) for the Automated Validation of Internet Security Protocols and Applications (AVISPA) which have proved that authentication goals are achieved. Hence, the scheme is safe and efficient when an intruder is present.
[1]
Jonathan Wood,et al.
IP Address Authorization for Secure Address Proxying Using Multi-key CGAs and Ring Signatures
,
2006,
IWSEC.
[2]
Thomas Narten,et al.
Neighbor Discovery for IP Version 6 (IPv6)
,
1996,
RFC.
[3]
Adriano Valenzano,et al.
Tools for cryptographic protocols analysis: A technical and experimental comparison
,
2009,
Comput. Stand. Interfaces.
[4]
Tony Cheneau,et al.
Using SEND Signature Algorithm Agility and Multiple-Key CGA to Secure Proxy Neighbor Discovery and Anycast Addressing
,
2011,
2011 Conference on Network and Information Systems Security.
[5]
Sebastian Mödersheim,et al.
The AVISPA Tool for the Automated Validation of Internet Security Protocols and Applications
,
2005,
CAV.
[6]
Ronnie D. Caytiles,et al.
Threats and Security Analysis for Enhanced Secure Neighbor Discovery Protocol (SEND) of IPv6 NDP Security
,
2011
.
[7]
Pekka Nikander,et al.
Delegation of Signalling Rights
,
2002,
Security Protocols Workshop.
[8]
Danny Dolev,et al.
On the security of public key protocols
,
1981,
22nd Annual Symposium on Foundations of Computer Science (sfcs 1981).