The Experts below are selected from a list of 84723 Experts worldwide ranked by ideXlab platform

Kemal Akkaya - One of the best experts on this subject based on the ideXlab platform.

  • an efficient and secure arp for large scale ieee 802 11s based smart grid networks
    Ad Hoc Networks, 2013
    Co-Authors: Nico Saputro, Kemal Akkaya
    Abstract:

    While Wireless Mesh Networks (WMNs) can be attractive in terms of deployment cost, convenience and flexibility, their real-life performance in large-scale is still inadequate due to interference and multi-hop communication. In this paper, we target IEEE 802.11s-based WMNs and propose to revise the way they perform Address Resolution Protocol (ARP) in order to improve their scalability and thus make them better suited for SG Advanced Metering Infrastructure (AMI) applications. Specifically, we utilize the proactive Path Request (PREQ) message of layer-2 path discovery protocol of 802.11s, namely HWMP, for piggybacking ARP information. In this way, the MAC Address Resolution is handled during routing tree creation/maintenance and hence the broadcasting of ARP requests by the smart meters to learn the MAC Address of the data collector (i.e., the gateway node) is completely eliminated. Furthermore, since piggybacking the ARP via PREQ may pose vulnerabilities for possible ARP cache poisoning attacks, we also provide authentication from the data collector by using Elliptic Curve Digital Signature Algorithm (ECDSA). Simulation results with the implementation of IEEE 802.11s in NS-3 simulator show that compared to the original ARP broadcast operations, our approach reduces the end to end delay significantly. The results also demonstrate that the impact of the overhead of authentication on packet delivery ratio is minimal.

  • an efficient arp for large scale ieee 802 11s based smart grid networks
    Local Computer Networks, 2013
    Co-Authors: Nico Saputro, Kemal Akkaya
    Abstract:

    Recently, wireless mesh networks (WMNs) have been touted as one of the suitable communication infrastructure for Smart Grid (SG) Advanced Metering Infrastructure (AMI) applications due to their ease of deployment and reasonable costs. These WMNs are typically based on the upcoming IEEE standard, namely IEEE 802.11s. However, 802.11s has performance related issues regarding scalability. One of the inefficiencies is related to the Address Resolution Protocol (ARP) when creating and maintaining the ARP cache and issuing path discovery within large-scale networks. In this paper, we propose an efficient ARP scheme for large-scale AMI networks. Specifically, we utilize the proactive Path Request (PREQ) message of 802.11s standard to perform the MAC Address Resolution during routing tree creation and maintenance and hence eliminate the broadcasting of ARP requests. Simulation results with the implementation of 802.11s in Network Simulator 3 (NS-3) show that compared to the original broadcast operations our approach improves the packet delivery ratio and throughput significantly.

Nico Saputro - One of the best experts on this subject based on the ideXlab platform.

  • an efficient and secure arp for large scale ieee 802 11s based smart grid networks
    Ad Hoc Networks, 2013
    Co-Authors: Nico Saputro, Kemal Akkaya
    Abstract:

    While Wireless Mesh Networks (WMNs) can be attractive in terms of deployment cost, convenience and flexibility, their real-life performance in large-scale is still inadequate due to interference and multi-hop communication. In this paper, we target IEEE 802.11s-based WMNs and propose to revise the way they perform Address Resolution Protocol (ARP) in order to improve their scalability and thus make them better suited for SG Advanced Metering Infrastructure (AMI) applications. Specifically, we utilize the proactive Path Request (PREQ) message of layer-2 path discovery protocol of 802.11s, namely HWMP, for piggybacking ARP information. In this way, the MAC Address Resolution is handled during routing tree creation/maintenance and hence the broadcasting of ARP requests by the smart meters to learn the MAC Address of the data collector (i.e., the gateway node) is completely eliminated. Furthermore, since piggybacking the ARP via PREQ may pose vulnerabilities for possible ARP cache poisoning attacks, we also provide authentication from the data collector by using Elliptic Curve Digital Signature Algorithm (ECDSA). Simulation results with the implementation of IEEE 802.11s in NS-3 simulator show that compared to the original ARP broadcast operations, our approach reduces the end to end delay significantly. The results also demonstrate that the impact of the overhead of authentication on packet delivery ratio is minimal.

  • an efficient arp for large scale ieee 802 11s based smart grid networks
    Local Computer Networks, 2013
    Co-Authors: Nico Saputro, Kemal Akkaya
    Abstract:

    Recently, wireless mesh networks (WMNs) have been touted as one of the suitable communication infrastructure for Smart Grid (SG) Advanced Metering Infrastructure (AMI) applications due to their ease of deployment and reasonable costs. These WMNs are typically based on the upcoming IEEE standard, namely IEEE 802.11s. However, 802.11s has performance related issues regarding scalability. One of the inefficiencies is related to the Address Resolution Protocol (ARP) when creating and maintaining the ARP cache and issuing path discovery within large-scale networks. In this paper, we propose an efficient ARP scheme for large-scale AMI networks. Specifically, we utilize the proactive Path Request (PREQ) message of 802.11s standard to perform the MAC Address Resolution during routing tree creation and maintenance and hence eliminate the broadcasting of ARP requests. Simulation results with the implementation of 802.11s in Network Simulator 3 (NS-3) show that compared to the original broadcast operations our approach improves the packet delivery ratio and throughput significantly.

Combes Jean-michel - One of the best experts on this subject based on the ideXlab platform.

  • Use of crypto based identifiers for IPv6 security
    2012
    Co-Authors: Combes Jean-michel
    Abstract:

    IPv6, protocole succédant à IPv4, est en cours de déploiement dans l’Internet. Il repose fortement sur le mécanisme Neighbor Discovery Protocol (NDP). Celui-ci permet non seulement à deux nœuds IPv6 de pouvoir communiquer, à l’instar du mécanisme Address Resolution Protocol (ARP) en IPv4, mais il apporte aussi de nouvelles fonctionnalités, telles que l’autoconfiguration d’adresse IPv6. Aussi, sa sécurisation pour le bon fonctionnement de l’Internet en IPv6 est critique. Son mécanisme de sécurité standardisée à l’Internet Engineering Task Force (IETF) se nomme Secure Neighbor Discovery (SEND). Il s’appuie à la fois sur l’utilisation d’identifiants cryptographiques, adresses IPv6 appelées Cryptographically Generated Addresses (CGA) et qui sont générées à partir d’une paire de clés publique/privée, et de certificats électroniques X.509. L’objet de cette thèse est l’étude de ces identifiants cryptographiques, les adresses CGA, ainsi que le mécanisme SEND les employant, et leurs réutilisations potentielles pour la sécurisation IPv6. Dans une première partie de cette thèse, tout d’abord, nous posons l’état de l’art. Dans une deuxième partie de cette thèse, nous nous intéressons à la fiabilité du principal mécanisme connu employant les adresses CGA, le mécanisme SEND. Dans une troisième et dernière partie de cette thèse, nous présentons des utilisations des identifiants cryptographiques pour la sécurisation IPv6IPv6, next Internet protocol after IPv4, is under deployment in the Internet. It is strongly based on the Neighbor Discovery Protocol (NDP) mechanism. First, it allows two IPv6 nodes to communicate, like the Address Resolution Protocol (ARP) mechanism in IPv4, but it brings new functions too, as IPv6 Address autoconfiguration. So, the security of this mechanism is critical for an Internet based on IPv6. The security mechanism standardized by the Internet Engineering Task Force (IETF) is Secure Neighbor Discovery (SEND). It is based on the use of cryptographical identifiers, IPv6 Addresses named Cryptographically Generated Addresses (CGA) and generated from a public/private keys pair, and X.509 certificates. The goal of this PhD thesis is the study of such cryptographical identifiers, CGA Addresses, as well as SEND using them, and their potential re-use to secure IPv6. In a first part of this thesis, we recall the main features of the IPv6 protocol. In a second part of this thesis, we are interested in the reliability of the main known mechanism using the CGA Addresses, SEND. In a third and last part of this thesis, we present different uses of cryptographical identifiers to secure IPv

  • Utilisation d'identifiants cryptographiques pour la sécurisation IPv6
    HAL CCSD, 2012
    Co-Authors: Combes Jean-michel
    Abstract:

    IPv6, next Internet protocol after IPv4, is under deployment in the Internet. It is strongly based on the Neighbor Discovery Protocol (NDP) mechanism. First, it allows two IPv6 nodes to communicate, like the Address Resolution Protocol (ARP) mechanism in IPv4, but it brings new functions too, as IPv6 Address autoconfiguration. So, the security of this mechanism is critical for an Internet based on IPv6. The security mechanism standardized by the Internet Engineering Task Force (IETF) is Secure Neighbor Discovery (SEND). It is based on the use of cryptographical identifiers, IPv6 Addresses named Cryptographically Generated Addresses (CGA) and generated from a public/private keys pair, and X.509 certificates. The goal of this PhD thesis is the study of such cryptographical identifiers, CGA Addresses, as well as SEND using them, and their potential re-use to secure IPv6. In a first part of this thesis, we recall the main features of the IPv6 protocol. In a second part of this thesis, we are interested in the reliability of the main known mechanism using the CGA Addresses, SEND. In a third and last part of this thesis, we present different uses of cryptographical identifiers to secure IPv6IPv6, protocole succédant à IPv4, est en cours de déploiement dans l’Internet. Il repose fortement sur le mécanisme Neighbor Discovery Protocol (NDP). Celui-ci permet non seulement à deux nœuds IPv6 de pouvoir communiquer, à l’instar du mécanisme Address Resolution Protocol (ARP) en IPv4, mais il apporte aussi de nouvelles fonctionnalités, telles que l’autoconfiguration d’adresse IPv6. Aussi, sa sécurisation pour le bon fonctionnement de l’Internet en IPv6 est critique. Son mécanisme de sécurité standardisée à l’Internet Engineering Task Force (IETF) se nomme Secure Neighbor Discovery (SEND). Il s’appuie à la fois sur l’utilisation d’identifiants cryptographiques, adresses IPv6 appelées Cryptographically Generated Addresses (CGA) et qui sont générées à partir d’une paire de clés publique/privée, et de certificats électroniques X.509. L’objet de cette thèse est l’étude de ces identifiants cryptographiques, les adresses CGA, ainsi que le mécanisme SEND les employant, et leurs réutilisations potentielles pour la sécurisation IPv6. Dans une première partie de cette thèse, tout d’abord, nous posons l’état de l’art. Dans une deuxième partie de cette thèse, nous nous intéressons à la fiabilité du principal mécanisme connu employant les adresses CGA, le mécanisme SEND. Dans une troisième et dernière partie de cette thèse, nous présentons des utilisations des identifiants cryptographiques pour la sécurisation IPv

  • Utilisation d'identifiants cryptographiques pour la sécurisation IPv6
    2012
    Co-Authors: Combes Jean-michel, Laurent Maryline
    Abstract:

    IPv6, protocole succédant à IPv4, est en cours de déploiement dans l Internet. Il repose fortement sur le mécanisme Neighbor Discovery Protocol (NDP). Celui-ci permet non seulement à deux nœuds IPv6 de pouvoir communiquer, à l instar du mécanisme Address Resolution Protocol (ARP) en IPv4, mais il apporte aussi de nouvelles fonctionnalités, telles que l autoconfiguration d adresse IPv6. Aussi, sa sécurisation pour le bon fonctionnement de l Internet en IPv6 est critique. Son mécanisme de sécurité standardisée à l Internet Engineering Task Force (IETF) se nomme Secure Neighbor Discovery (SEND). Il s appuie à la fois sur l utilisation d identifiants cryptographiques, adresses IPv6 appelées Cryptographically Generated Addresses (CGA) et qui sont générées à partir d une paire de clés publique/privée, et de certificats électroniques X.509. L objet de cette thèse est l étude de ces identifiants cryptographiques, les adresses CGA, ainsi que le mécanisme SEND les employant, et leurs réutilisations potentielles pour la sécurisation IPv6. Dans une première partie de cette thèse, tout d abord, nous posons l état de l art. Dans une deuxième partie de cette thèse, nous nous intéressons à la fiabilité du principal mécanisme connu employant les adresses CGA, le mécanisme SEND. Dans une troisième et dernière partie de cette thèse, nous présentons des utilisations des identifiants cryptographiques pour la sécurisation IPv6IPv6, next Internet protocol after IPv4, is under deployment in the Internet. It is strongly based on the Neighbor Discovery Protocol (NDP) mechanism. First, it allows two IPv6 nodes to communicate, like the Address Resolution Protocol (ARP) mechanism in IPv4, but it brings new functions too, as IPv6 Address autoconfiguration. So, the security of this mechanism is critical for an Internet based on IPv6. The security mechanism standardized by the Internet Engineering Task Force (IETF) is Secure Neighbor Discovery (SEND). It is based on the use of cryptographical identifiers, IPv6 Addresses named Cryptographically Generated Addresses (CGA) and generated from a public/private keys pair, and X.509 certificates. The goal of this PhD thesis is the study of such cryptographical identifiers, CGA Addresses, as well as SEND using them, and their potential re-use to secure IPv6. In a first part of this thesis, we recall the main features of the IPv6 protocol. In a second part of this thesis, we are interested in the reliability of the main known mechanism using the CGA Addresses, SEND. In a third and last part of this thesis, we present different uses of cryptographical identifiers to secure IPv6EVRY-INT (912282302) / SudocSudocFranceF

Sudipta Sengupta - One of the best experts on this subject based on the ideXlab platform.

  • vl2 a scalable and flexible data center network
    Communications of The ACM, 2011
    Co-Authors: Albert Greenberg, James R Hamilton, Navendu Jain, Srikanth Kandula, Parantap Lahiri, David A Maltz, Parveen Patel, Sudipta Sengupta
    Abstract:

    To be agile and cost effective, data centers must allow dynamic resource allocation across large server pools. In particular, the data center network should provide a simple flat abstraction: it should be able to take any set of servers anywhere in the data center and give them the illusion that they are plugged into a physically separate, noninterfering Ethernet switch with as many ports as the service needs. To meet this goal, we present VL2, a practical network architecture that scales to support huge data centers with uniform high capacity between servers, performance isolation between services, and Ethernet layer-2 semantics. VL2 uses (1) flat Addressing to allow service instances to be placed anywhere in the network, (2) Valiant Load Balancing to spread traffic uniformly across network paths, and (3) end system--based Address Resolution to scale to large server pools without introducing complexity to the network control plane. VL2's design is driven by detailed measurements of traffic and fault data from a large operational cloud service provider. VL2's implementation leverages proven network technologies, already available at low cost in high-speed hardware implementations, to build a scalable and reliable network architecture. As a result, VL2 networks can be deployed today, and we have built a working prototype. We evaluate the merits of the VL2 design using measurement, analysis, and experiments. Our VL2 prototype shuffles 2.7 TB of data among 75 servers in 395 s---sustaining a rate that is 94% of the maximum possible.

  • vl2 a scalable and flexible data center network
    ACM Special Interest Group on Data Communication, 2009
    Co-Authors: Albert Greenberg, James R Hamilton, Navendu Jain, Srikanth Kandula, Parantap Lahiri, David A Maltz, Parveen Patel, Sudipta Sengupta
    Abstract:

    To be agile and cost effective, data centers should allow dynamic resource allocation across large server pools. In particular, the data center network should enable any server to be assigned to any service. To meet these goals, we present VL2, a practical network architecture that scales to support huge data centers with uniform high capacity between servers, performance isolation between services, and Ethernet layer-2 semantics. VL2 uses (1) flat Addressing to allow service instances to be placed anywhere in the network, (2) Valiant Load Balancing to spread traffic uniformly across network paths, and (3) end-system based Address Resolution to scale to large server pools, without introducing complexity to the network control plane. VL2's design is driven by detailed measurements of traffic and fault data from a large operational cloud service provider. VL2's implementation leverages proven network technologies, already available at low cost in high-speed hardware implementations, to build a scalable and reliable network architecture. As a result, VL2 networks can be deployed today, and we have built a working prototype. We evaluate the merits of the VL2 design using measurement, analysis, and experiments. Our VL2 prototype shuffles 2.7 TB of data among 75 servers in 395 seconds - sustaining a rate that is 94% of the maximum possible.

E Rosti - One of the best experts on this subject based on the ideXlab platform.

  • s arp a secure Address Resolution protocol
    Annual Computer Security Applications Conference, 2003
    Co-Authors: Danilo Bruschi, A Ornaghi, E Rosti
    Abstract:

    Tapping into the communication between two hosts on a LAN has become quite simple thanks to tools that can be downloaded from the Internet. Such tools use the Address Resolution protocol (ARP) poisoning technique, which relies on hosts caching reply messages even though the corresponding requests were never sent. Since no message authentication is provided, any host of the LAN can forge a message containing malicious information. We present a secure version of ARP that provides protection against ARP poisoning. Each host has a public/private key pair certified by a local trusted party on the LAN, which acts as a certification authority. Messages are digitally signed by the sender, thus preventing the injection of spurious and/or spoofed information. As a proof of concept, the proposed solution was implemented on a Linux box. Performance measurements show that PKI based strong authentication is feasible to secure even low level protocols, as long as the overhead for key validity verification is kept small.