计算机应用 ›› 2013, Vol. 33 ›› Issue (04): 926-930.DOI: 10.3724/SP.J.1087.2013.00926

• 网络与通信 • 上一篇    下一篇

基于包验证的面向IPv6翻译机制的IP追溯方法

朱田1,2,田野1,3,马迪1,3,毛伟1,2   

  1. 1. 中国互联网络信息中心,北京 100190
    2. 中国科学院 计算机网络信息中心,北京 100190
    3. 中国科学院 计算机网络信息中心
  • 收稿日期:2012-10-19 修回日期:2012-12-03 出版日期:2013-04-01 发布日期:2013-04-23
  • 通讯作者: 朱田
  • 作者简介:朱田(1985-),男,湖北监利人,硕士研究生,主要研究方向:下一代互联网、可信网络;田野(1979-),男,重庆人,博士,主要研究方向:下一代互联网、可信网络;马迪(1984-),男,安徽六安人,博士研究生,主要研究方向:下一代互联网、可信网络;毛伟(1968-),男,四川自贡人,研究员,博士生导师,主要研究方向:下一代互联网、网络寻址与定位。
  • 基金资助:

    国家自然科学基金资助项目(61005029)

Packet verification based traceback method for IPv6 translation mechanism

ZHU Tian1,2,3,TIAN Ye1,2,3,MA Di1,2,3, 1,2,3   

  1. 1. China Internet Network Information Center, Beijing 100190, China
    2. Computer Network Information Center, Chinese Academy of Sciences, Beijing 100190, China
    3. Computer Network Information Center, Chinese Academy of Sciences, Beijing 100190, China
  • Received:2012-10-19 Revised:2012-12-03 Online:2013-04-01 Published:2013-04-23
  • Contact: ZHU Tian

摘要: IP地址安全一直是互联网面临的核心问题,在IPv6过渡时期,多种IP地址分配方式,IPv6过渡技术和IP欺骗引起的IP地址不确定性向IP地址资源安全提出了挑战。新兴IPv6家庭网络、小企业网、校园网与传统IPv4网络互联互通的IPv6翻译场景是典型的IPv6过渡场景,然而,传统的IP追溯技术无法直接应用于IPv6翻译场景。基于这种现状,提出一种IP追溯方案来解决IPv6翻译场景下的IP追溯问题,该方案打通了IPv6翻译网关,实现了目的网络对源网络的可知性,进而保证了互联网的IP地址资源安全。

关键词: IP地址管理, IP追溯, IPv6过渡, 数据包验证, IPv6翻译机制

Abstract: IP address security is always a critical Internet security issue. As the transition from IPv4 to IPv6, multiple allocation modes of IP address, IPv6 translation techniques and IP spoofing increase the uncertainty of IP address of the host and the host has multiple IP addresses, which makes IP address resource more insecure. The emerging IPv6 home network, small enterprise network and campus network interconnect with traditional IPv4 network, which is typical and inevitable IPv6 translation scenario, and traditional IP traceback techniques cannot directly be applied to these scenarios. Therefore, this paper presented a new approach to solve IP traceback issue under these scenarios, which is able to go across the gateway that interconnects between IPv4 network and IPv6 network, and makes the destination network knowable for the source network. The traceback method guarantees the Internet fundamental resource safe.

Key words: IP address management, IP traceback, IPv6 transition, packet verification, IPv6 translation mechanism

中图分类号: