首页|IPv6地址驱动的云网络内生安全机制研究

IPv6地址驱动的云网络内生安全机制研究

扫码查看
云网络可以根据不同业务场景对云平台虚拟网络资源快速部署与配置,是现代数据中心性能和安全的重要保障.但传统云网架构中IPv4 支撑能力有限,无法实现网络端到端的透明传输,多租户特性使得云管理者对租户子网进行流量管理和约束异常困难,外挂式的安全方案缺乏对不同租户流量的追溯能力,无法在源头对攻击行为进行限制.IPv6 具有地址空间大、编址能力强、安全性高的特点,基于此,文章提出一种IPv6 地址驱动的云网络内生安全机制,包括地址生成层、地址验证层和地址利用层.地址生成层以对称加密算法为基础,将租户身份信息嵌入IPv6 地址后 64 位,修改DHCPv6 地址分配策略,并基于Openstack Neutron进行实现.地址验证层设计实现了云网络动态源地址验证方法,针对不同端口状态集合设计针对性转移方法和安全策略.地址利用层基于IPv6 真实地址的特性,实现了基于IPv6 地址的数据包溯源机制和访问控制策略.
Research on Endogenous Security Mechanism of Cloud Network Driven by IPv6 Address
Cloud networking can rapidly deploy and configure virtual network resource on cloud platform according to different business scenarios,which is an important guarantee for performance and security in modern data center.However,traditional cloud network cannot make transparent end-to-end transmission due to the limitation of IPv4.The multi-tenant feature makes it difficult for cloud manager to constrain traffic on tenant subnets,and external security solutions lack of traceability of traffic from different tenants,making it impossible to restrict attack at the source.IPv6 has large address space,strong addressing ability,and high security.Guided by the endogenous security concept and centered on IPv6 address driven,this article proposed an IPv6 address driven cloud network endogenous security hierarchy architecture,including address generation layer,address verification layer,and address utilization layer.At the address generation layer,the tenant identity was embedded into the last 64 bits of IPv6 address using symmetric encryption algorithm,and the DHCPv6 address allocation strategy was modified.The implementation was based on Openstack Neutron.At the address verification layer,a dynamic source address verification method was designed and implemented for cloud networks.Specific transition methods and security policies were designed for different port status sets.At the address utilization layer,based on the characteristics of real IPv6 address,a packet tracing mechanism and an access control policy based on IPv6 addresses were implemented.

cloud networkendogenous securitysource address validationaddress generationIPv6

张博文、李冬、赵贻竹、于俊清

展开 >

华中科技大学网络空间安全学院,武汉 430074

华中科技大学网络与计算中心,武汉 430074

云网络 内生安全 源地址验证 地址生成 IPv6

国家重点研发计划中国高校产学研创新基金

2020YFB18056012021FNA02005

2024

信息网络安全
公安部第三研究所 中国计算机学会计算机安全专业委员会

信息网络安全

CSTPCDCHSSCD北大核心
影响因子:0.814
ISSN:1671-1122
年,卷(期):2024.(1)
  • 5