首页> 外文会议>European symposium on research in computer security >Plug-and-Play IP Security: Anonymity Infrastructure instead of PKI
【24h】

Plug-and-Play IP Security: Anonymity Infrastructure instead of PKI

机译:即插即用IP安全:匿名基础架构而不是PKI

获取原文

摘要

We present the Plug-and-Play IP Security (PnP-IPsec) protocol. PnP-IPsec automatically establishes IPsec security associations between gateways, avoiding the need for manual administration and coordination between gateways, and the dependency on IPsec public key certificates - the two problems which are widely believed to have limited the use of IPsec mostly to intra-organization communication. PnP-IPsec builds on Self-validated Public Data Distribution (SvPDD), a protocol that we present to establish secure connections between remote peers/networks, without depending on pre-distributed keys or certification infrastructure. Instead, SvPDD uses available anonymous communication infrastructures such as Tor, which we show to allow detection of MitM attacker interfering with communication. SvPDD may also be used in other scenarios lacking secure public key distribution, such as the initial connection to an SSH server.We provide an open-source implementation of PnP-IPsec and SvPDD; and show that the resulting system is practical and secure.
机译:我们介绍了即插即用的IP安全(PNP-IPSEC)协议。 PNP-IPSec自动建立网关之间的IPsec安全关联,避免了网关之间的手动管理和协调,以及对IPSec公钥证书的依赖 - 广泛认为主要是在组织内部使用IPsec的两个问题沟通。 PNP-IPSEC构建在自验证的公共数据分发(SVPDD)上,这是我们出示的协议,以便在远程对等体/网络之间建立安全连接,而无需根据预分布式的键或认证基础架构。相反,SVPDD使用可用的可用匿名通信基础架构,例如Tor,我们展示允许检测MITM攻击者干扰通信。 SVPDD也可以用于缺乏安全公钥分发的其他方案,例如与SSH服务器的初始连接.WE提供PNP-IPSec和SVPDD的开源实现;并表明所产生的系统是实用和安全的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号