An ID-based mutually authenticated edge-to-edge security architecture for bridged provider networks to secure layer-2 communications
IEEE standardized a Layer-2 security, named Media Access Control security (MACsec), for interoperability. It provides link-based security through hop-by-hop operation. The link-constrained security of MACsec eliminates the confidentiality of user data inside bridges. Hence, high-speed Ethernet-based...
| Autor: | |
|---|---|
| Tipo de recurso: | tesis doctoral |
| Estado: | Versión publicada |
| Fecha de publicación: | 2011 |
| País: | España |
| Institución: | CBUC, CESCA |
| Repositorio: | TDR. Tesis Doctorales en Red |
| OAI Identifier: | oai:www.tdx.cat:10803/32050 |
| Acceso en línea: | http://hdl.handle.net/10803/32050 |
| Access Level: | acceso abierto |
| Palabra clave: | Layer-2 Security Ethernet Security Service Provider Network Metro Ethernet Network Secure Data Transmission Key Distribution Scalable Security Bridged Provider Network ID-based security Authenticated Key Agreement 62 |
| Sumario: | IEEE standardized a Layer-2 security, named Media Access Control security (MACsec), for interoperability. It provides link-based security through hop-by-hop operation. The link-constrained security of MACsec eliminates the confidentiality of user data inside bridges. Hence, high-speed Ethernet-based Broadband networks are susceptible to attacks in large network deployment, where bridges need to be resided in street cabinets, road side poles or public places for easy user access. We propose an ID-based mutually authenticated edge-to-edge security architecture to address this remaining gap (i.e., secure bridging) in layer-2 service provider networks. The major challenge for this scenario is the combination of complete security, simplicity, better performance and scalability in a single solution. Our solution addresses all challenges and simplifies- key distribution by an extension of 802.1x-EAP authentication protocol, key agreement by an ID-based mutually authenticated two-pass key agreement protocol and secure data transmission by a modification of the replay protection mechanism of 802.1AE. |
|---|