Secure Neighbor Discovery

From Wikipedia, the free encyclopedia

Template:Short description

Page Module:Message box/ambox.css has no content.

The Secure Neighbor Discovery (SEND) protocol is a security extension of the Neighbor Discovery Protocol (NDP) in IPv6 defined in Template:IETF RFC and updated by Template:IETF RFC.

The Neighbor Discovery Protocol (NDP) is responsible in IPv6 for discovery of other network nodes on the local link, to determine the link layer addresses of other nodes, and to find available routers, and maintain reachability information about the paths to other active neighbor nodes (Template:IETF RFC). NDP is insecure[1] and susceptible to malicious interference. It is the intent of SEND to provide an alternate mechanism for securing NDP with a cryptographic method that is independent of IPsec, the original and inherent method of securing IPv6 communications.

SEND uses Cryptographically Generated Addresses (CGA) and other new NDP options for the ICMPv6 packet types used in NDP.

SEND was updated to use the Resource Public Key Infrastructure (RPKI) by RFC 6494 and Template:IETF RFC which define the use of a SEND Certificate Profile utilizing a modified RFC 6487 RPKI Certificate Profile which must include a single RFC 3779 IP Address Delegation extension.

There have been concerns with algorithm agility vis-à-vis attacks on hash functions used by SEND expressed in Template:IETF RFC, as CGA currently uses the SHA-1 hash algorithm and PKIX certificates and does not provide support for alternative hash algorithms.

Implementations

See also

References

Page Template:Refbegin/styles.css has no content.

  • Script error: No such module "template wrapper".
  • Script error: No such module "template wrapper".
  • Script error: No such module "template wrapper".


Template:Asbox

Lua error in package.lua at line 80: module 'Module:Navbox/configuration' not found.