An ID-based mutually authenticated edge-to-edge security architecture for bridged provider networks to secure layer-2 communications

IEEE standardized a Layer-2 security, named Media Access Control security (MACsec), for interoperability. It provides link-based security through hop-by-hop operation. The link-constrained security of MACsec eliminates the confidentiality of user data inside bridges. Hence, high-speed Ethernet-based...

Descripción completa

Detalles Bibliográficos
Autor: Ferdous Wahid, Khan
Tipo de recurso: tesis doctoral
Estado:Versión publicada
Fecha de publicación:2011
País:España
Institución:CBUC, CESCA
Repositorio:TDR. Tesis Doctorales en Red
OAI Identifier:oai:www.tdx.cat:10803/32050
Acceso en línea:http://hdl.handle.net/10803/32050
Access Level:acceso abierto
Palabra clave:Layer-2 Security
Ethernet Security
Service Provider Network
Metro Ethernet Network
Secure Data Transmission
Key Distribution
Scalable Security
Bridged Provider Network
ID-based security
Authenticated Key Agreement
62
Descripción
Sumario:IEEE standardized a Layer-2 security, named Media Access Control security (MACsec), for interoperability. It provides link-based security through hop-by-hop operation. The link-constrained security of MACsec eliminates the confidentiality of user data inside bridges. Hence, high-speed Ethernet-based Broadband networks are susceptible to attacks in large network deployment, where bridges need to be resided in street cabinets, road side poles or public places for easy user access. We propose an ID-based mutually authenticated edge-to-edge security architecture to address this remaining gap (i.e., secure bridging) in layer-2 service provider networks. The major challenge for this scenario is the combination of complete security, simplicity, better performance and scalability in a single solution. Our solution addresses all challenges and simplifies- key distribution by an extension of 802.1x-EAP authentication protocol, key agreement by an ID-based mutually authenticated two-pass key agreement protocol and secure data transmission by a modification of the replay protection mechanism of 802.1AE.