端点不可知地址跳变通信——一种充分利用IPv6巨大空间优势的基于网络的设计

Shen YAN , Pei ZHANG , Yan MA , Tian-le YANG
{"title":"端点不可知地址跳变通信——一种充分利用IPv6巨大空间优势的基于网络的设计","authors":"Shen YAN ,&nbsp;Pei ZHANG ,&nbsp;Yan MA ,&nbsp;Tian-le YANG","doi":"10.1016/S1005-8885(14)60513-6","DOIUrl":null,"url":null,"abstract":"<div><p>Network address hopping (NAH) proposed a mechanism to enhance data protection in communications across untrusted networks. It spread the data stream of a communication session across multiple channels, which tried to obstruct information interception in the first place by obscuring the fact that communication takes place between certain end-points. However, the time-stamped packets between two peers would provide a hint for correlating the intercepted packets in case the encryption of the counter got compromised. Furthermore, due to synchronization, the Internet Protocol version 6 (IPv6) addresses pair of the channel ends would appear and disappear strictly, which would perform time-relevance character. A Network-based hopping communication mechanism (NetHop) is proposed in this paper. The address hopping function is deployed on the network side instead of endpoint, which can support secure hopping communication function for universal endpoints without any restriction of Operating System or hardware. By using IPv6 to IPv6 network address translation (NAT), NetHop fully exploits the superiority of IPv6 huge address space. The hopping addresses are generated by hash function and the hopping addresses pair can be chosen randomly. Consequently, NetHop performs better on randomness and concealment than channel-rule NAH.</p></div>","PeriodicalId":35359,"journal":{"name":"Journal of China Universities of Posts and Telecommunications","volume":"21 ","pages":"Pages 46-51, 58"},"PeriodicalIF":0.0000,"publicationDate":"2014-07-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://sci-hub-pdf.com/10.1016/S1005-8885(14)60513-6","citationCount":"1","resultStr":"{\"title\":\"Endpoint-agnostic address hopping communication — a network-based design by fully exploiting IPv6 huge space superiority\",\"authors\":\"Shen YAN ,&nbsp;Pei ZHANG ,&nbsp;Yan MA ,&nbsp;Tian-le YANG\",\"doi\":\"10.1016/S1005-8885(14)60513-6\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<div><p>Network address hopping (NAH) proposed a mechanism to enhance data protection in communications across untrusted networks. It spread the data stream of a communication session across multiple channels, which tried to obstruct information interception in the first place by obscuring the fact that communication takes place between certain end-points. However, the time-stamped packets between two peers would provide a hint for correlating the intercepted packets in case the encryption of the counter got compromised. Furthermore, due to synchronization, the Internet Protocol version 6 (IPv6) addresses pair of the channel ends would appear and disappear strictly, which would perform time-relevance character. A Network-based hopping communication mechanism (NetHop) is proposed in this paper. The address hopping function is deployed on the network side instead of endpoint, which can support secure hopping communication function for universal endpoints without any restriction of Operating System or hardware. By using IPv6 to IPv6 network address translation (NAT), NetHop fully exploits the superiority of IPv6 huge address space. The hopping addresses are generated by hash function and the hopping addresses pair can be chosen randomly. Consequently, NetHop performs better on randomness and concealment than channel-rule NAH.</p></div>\",\"PeriodicalId\":35359,\"journal\":{\"name\":\"Journal of China Universities of Posts and Telecommunications\",\"volume\":\"21 \",\"pages\":\"Pages 46-51, 58\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2014-07-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"https://sci-hub-pdf.com/10.1016/S1005-8885(14)60513-6\",\"citationCount\":\"1\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Journal of China Universities of Posts and Telecommunications\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://www.sciencedirect.com/science/article/pii/S1005888514605136\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q4\",\"JCRName\":\"Computer Science\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of China Universities of Posts and Telecommunications","FirstCategoryId":"1085","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S1005888514605136","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q4","JCRName":"Computer Science","Score":null,"Total":0}
引用次数: 1

摘要

网络地址跳变(Network address hopping, NAH)提出了一种增强非可信网络通信数据保护的机制。它将通信会话的数据流分散到多个通道上,这首先试图通过模糊通信发生在某些端点之间的事实来阻止信息拦截。但是,对等体之间带有时间戳的数据包可以在计数器加密被破坏的情况下提供关联截获数据包的提示。此外,由于同步,信道两端的IPv6地址对会严格地出现和消失,从而表现出时间相关性。提出了一种基于网络的跳通信机制(NetHop)。地址跳变功能部署在网络端而不是终端,可以在不受操作系统和硬件限制的情况下,支持通用终端的安全跳变通信功能。NetHop利用IPv6到IPv6的NAT (network address translation)技术,充分利用了IPv6巨大地址空间的优势。跳地址由哈希函数生成,跳地址对可以随机选择。因此,NetHop在随机性和隐蔽性方面优于通道规则的NAH。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Endpoint-agnostic address hopping communication — a network-based design by fully exploiting IPv6 huge space superiority

Network address hopping (NAH) proposed a mechanism to enhance data protection in communications across untrusted networks. It spread the data stream of a communication session across multiple channels, which tried to obstruct information interception in the first place by obscuring the fact that communication takes place between certain end-points. However, the time-stamped packets between two peers would provide a hint for correlating the intercepted packets in case the encryption of the counter got compromised. Furthermore, due to synchronization, the Internet Protocol version 6 (IPv6) addresses pair of the channel ends would appear and disappear strictly, which would perform time-relevance character. A Network-based hopping communication mechanism (NetHop) is proposed in this paper. The address hopping function is deployed on the network side instead of endpoint, which can support secure hopping communication function for universal endpoints without any restriction of Operating System or hardware. By using IPv6 to IPv6 network address translation (NAT), NetHop fully exploits the superiority of IPv6 huge address space. The hopping addresses are generated by hash function and the hopping addresses pair can be chosen randomly. Consequently, NetHop performs better on randomness and concealment than channel-rule NAH.

求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
CiteScore
0.50
自引率
0.00%
发文量
1878
期刊最新文献
Survey of outdoor and indoor architecture design in TVWS networks Effect of non-spherical atmospheric charged particles and atmospheric visibility on performance of satellite-ground quantum link and parameters simulation Novel high PSRR high-order temperature-compensated subthreshold MOS bandgap reference Anomaly detection in smart grid based on encoder-decoder framework with recurrent neural network Palm vein recognition method based on fusion of local Gabor histograms
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1