An ID-based mutually authenticated edge-to-edge security architecture for bridged provider networks to secure layer-2 communications

IEEE standardized a Layer-2 security, named Media Access Control security (MACsec), for interoperability. It provides link-based security through hop-by-hop operation. The link-constrained security of MACsec eliminates the confidentiality of user data inside bridges. Hence, high-speed Ethernet-based...

Full description

Bibliographic Details
Author: Ferdous Wahid, Khan
Format: doctoral thesis
Status:Published version
Publication Date:2011
Country:España
Institution:CBUC, CESCA
Repository:TDR. Tesis Doctorales en Red
OAI Identifier:oai:www.tdx.cat:10803/32050
Online Access:http://hdl.handle.net/10803/32050
Access Level:Open access
Keyword:Layer-2 Security
Ethernet Security
Service Provider Network
Metro Ethernet Network
Secure Data Transmission
Key Distribution
Scalable Security
Bridged Provider Network
ID-based security
Authenticated Key Agreement
62
id ES_5be5e3b4aa619bd99dbaa338ee9b7fa2
oai_identifier_str oai:www.tdx.cat:10803/32050
network_acronym_str ES
network_name_str España
repository_id_str
dc.title.none.fl_str_mv An ID-based mutually authenticated edge-to-edge security architecture for bridged provider networks to secure layer-2 communications
title An ID-based mutually authenticated edge-to-edge security architecture for bridged provider networks to secure layer-2 communications
spellingShingle An ID-based mutually authenticated edge-to-edge security architecture for bridged provider networks to secure layer-2 communications
Ferdous Wahid, Khan
Layer-2 Security
Ethernet Security
Service Provider Network
Metro Ethernet Network
Secure Data Transmission
Key Distribution
Scalable Security
Bridged Provider Network
ID-based security
Authenticated Key Agreement
62
title_short An ID-based mutually authenticated edge-to-edge security architecture for bridged provider networks to secure layer-2 communications
title_full An ID-based mutually authenticated edge-to-edge security architecture for bridged provider networks to secure layer-2 communications
title_fullStr An ID-based mutually authenticated edge-to-edge security architecture for bridged provider networks to secure layer-2 communications
title_full_unstemmed An ID-based mutually authenticated edge-to-edge security architecture for bridged provider networks to secure layer-2 communications
title_sort An ID-based mutually authenticated edge-to-edge security architecture for bridged provider networks to secure layer-2 communications
dc.creator.none.fl_str_mv Ferdous Wahid, Khan
author Ferdous Wahid, Khan
author_facet Ferdous Wahid, Khan
author_role author
dc.contributor.none.fl_str_mv Sala, Dolors
Universitat Pompeu Fabra. Departament de Tecnologies de la Informació i les Comunicacions
dc.subject.none.fl_str_mv Layer-2 Security
Ethernet Security
Service Provider Network
Metro Ethernet Network
Secure Data Transmission
Key Distribution
Scalable Security
Bridged Provider Network
ID-based security
Authenticated Key Agreement
62
topic Layer-2 Security
Ethernet Security
Service Provider Network
Metro Ethernet Network
Secure Data Transmission
Key Distribution
Scalable Security
Bridged Provider Network
ID-based security
Authenticated Key Agreement
62
description IEEE standardized a Layer-2 security, named Media Access Control security (MACsec), for interoperability. It provides link-based security through hop-by-hop operation. The link-constrained security of MACsec eliminates the confidentiality of user data inside bridges. Hence, high-speed Ethernet-based Broadband networks are susceptible to attacks in large network deployment, where bridges need to be resided in street cabinets, road side poles or public places for easy user access. We propose an ID-based mutually authenticated edge-to-edge security architecture to address this remaining gap (i.e., secure bridging) in layer-2 service provider networks. The major challenge for this scenario is the combination of complete security, simplicity, better performance and scalability in a single solution. Our solution addresses all challenges and simplifies- key distribution by an extension of 802.1x-EAP authentication protocol, key agreement by an ID-based mutually authenticated two-pass key agreement protocol and secure data transmission by a modification of the replay protection mechanism of 802.1AE.
publishDate 2011
dc.date.none.fl_str_mv 2011
2011
2011
dc.type.none.fl_str_mv info:eu-repo/semantics/doctoralThesis
info:eu-repo/semantics/publishedVersion
format doctoralThesis
status_str publishedVersion
dc.identifier.none.fl_str_mv http://hdl.handle.net/10803/32050
url http://hdl.handle.net/10803/32050
dc.language.none.fl_str_mv Inglés
language_invalid_str_mv Inglés
dc.rights.none.fl_str_mv info:eu-repo/semantics/openAccess
eu_rights_str_mv openAccess
dc.format.none.fl_str_mv 100 p.
application/pdf
application/pdf
dc.publisher.none.fl_str_mv Universitat Pompeu Fabra
publisher.none.fl_str_mv Universitat Pompeu Fabra
dc.source.none.fl_str_mv TDX (Tesis Doctorals en Xarxa)
reponame:TDR. Tesis Doctorales en Red
instname:CBUC, CESCA
instname_str CBUC, CESCA
reponame_str TDR. Tesis Doctorales en Red
collection TDR. Tesis Doctorales en Red
repository.name.fl_str_mv
repository.mail.fl_str_mv
_version_ 1869408848344776704
spelling An ID-based mutually authenticated edge-to-edge security architecture for bridged provider networks to secure layer-2 communicationsFerdous Wahid, KhanLayer-2 SecurityEthernet SecurityService Provider NetworkMetro Ethernet NetworkSecure Data TransmissionKey DistributionScalable SecurityBridged Provider NetworkID-based securityAuthenticated Key Agreement62IEEE standardized a Layer-2 security, named Media Access Control security (MACsec), for interoperability. It provides link-based security through hop-by-hop operation. The link-constrained security of MACsec eliminates the confidentiality of user data inside bridges. Hence, high-speed Ethernet-based Broadband networks are susceptible to attacks in large network deployment, where bridges need to be resided in street cabinets, road side poles or public places for easy user access. We propose an ID-based mutually authenticated edge-to-edge security architecture to address this remaining gap (i.e., secure bridging) in layer-2 service provider networks. The major challenge for this scenario is the combination of complete security, simplicity, better performance and scalability in a single solution. Our solution addresses all challenges and simplifies- key distribution by an extension of 802.1x-EAP authentication protocol, key agreement by an ID-based mutually authenticated two-pass key agreement protocol and secure data transmission by a modification of the replay protection mechanism of 802.1AE.IEEE va estandarditzar seguretat a nivell 2, anomenada Media Access Control, que s'enfoca a proporcionar interoperabilitat, seguretat a nivell d'enllaç, i operació salt-a-salt. La seguretat restringida de MACsec elimina la confidencialitat de les dades de l'usuari dins dels dispositius. Per tant, les xarxes d'alta velocitat basades en Ethernet són susceptibles als atacs en grans desplegaments, on els bridges han de ser guardats a distribuïdors a nivell de carrer o llocs públics d'accés fàcil. Per fer front al problema a les xarxes de proveïdors de capa 2 aquí proposem una arquitectura de seguretat extrem-a-extrem, autenticada mútuament i basada en identitat. El principal repte per a aquest escenari és la combinació d'una seguretat completa, simplicitat, millor rendiment i escalabilitat en una única solució. La nostra solució ataca tots els reptes i simplifica- (1) la distribució de claus mitjançant una ampliació del protocol d'autenticació 802.1x-EAP protocol, (2) l'acord de claus amb un protocol de doble passada autenticat mútuament i basat en identitat, i (3) la transmissió segura de dades mitjançant una modificació del mecanisme de 'protecció de resposta' de 802.1AE.Programa de doctorat en Tecnologies de la Informació i les ComunicacionsUniversitat Pompeu FabraSala, DolorsUniversitat Pompeu Fabra. Departament de Tecnologies de la Informació i les Comunicacions201120112011info:eu-repo/semantics/doctoralThesisinfo:eu-repo/semantics/publishedVersion100 p.application/pdfapplication/pdfhttp://hdl.handle.net/10803/32050TDX (Tesis Doctorals en Xarxa)reponame:TDR. Tesis Doctorales en Redinstname:CBUC, CESCAInglésADVERTIMENT. L'accés als continguts d'aquesta tesi doctoral i la seva utilització ha de respectar els drets de la persona autora. Pot ser utilitzada per a consulta o estudi personal, així com en activitats o materials d'investigació i docència en els termes establerts a l'art. 32 del Text Refós de la Llei de Propietat Intel·lectual (RDL 1/1996). Per altres utilitzacions es requereix l'autorització prèvia i expressa de la persona autora. En qualsevol cas, en la utilització dels seus continguts caldrà indicar de forma clara el nom i cognoms de la persona autora i el títol de la tesi doctoral. No s'autoritza la seva reproducció o altres formes d'explotació efectuades amb finalitats de lucre ni la seva comunicació pública des d'un lloc aliè al servei TDX. Tampoc s'autoritza la presentació del seu contingut en una finestra o marc aliè a TDX (framing). Aquesta reserva de drets afecta tant als continguts de la tesi com als seus resums i índexs.info:eu-repo/semantics/openAccessoai:www.tdx.cat:10803/320502026-06-14T12:46:07Z
score 15.301629