2002 Linux Symposium
navigation



related

contact:

An implementation of HIP for Linux

Catharina L Candolin

One of the the main problems with IP has been its lack of security. Although IPSec and DNSSec have provided some levels of security to IP, the notion of a true identity for hosts is still missing. Typically, the IP address has been used to provide the host with an identity, regardless of the fact that the IP address is nothing more than routing information. The purpose of the Host Identity Payload/Protocol (HIP) architecture is to add a cryptographically based namespace, the Host Identity, to the IP protocol. Each host (or more specifically, its networking kernel or stack) is assigned at least one Host Identity, which can be either public or anonymous. The host identity can be used for authentication purposes to support trust between systems, enhance mobility and dynamic IP renumbering, aid in protocol translation/transition and reduce denial-of-service attacks. Furthermore, as all of the higher protocols are bound to the Host Identity instead of to the IP address, the IP address can now be used solely for routing purposes. The purpose of this paper is to present our IPv6 based implementation of HIP for Linux. We first give a short introduction to HIP as a concept and motivate why it is needed in the first place. Then we present our implementation as well as the design choices we have made during the implementation process. Our implementation has been successfully tested for interoperability with other HIP implementations for other platforms, and we will briefly describe the compatibility tests performed.
2004
© 1999-2003 Linux Symposium.  All Rights Reserved.