WAN Ming, LIU Ying, ZHANG Hong-ke. New mapping approach based on reputation model under locator/ID separation protocol[J]. 2011, 32(7): 133-145.DOI:
位置与身份分离协议下一种基于信任度模型的新型映射机制
摘要
通过分析位置与身份分离协议中可能存在的映射欺骗所带来的安全隐患
提出了一种缓解映射欺骗威胁的新型映射机制。该机制在映射理论中引入了基于反馈评判的信任度模型
通过对信任度的动态评判
增加了映射信息的可信性。同时
采用自证明标识代表隧道路由器的身份信息
有效地保障了映射信息源的真实性。性能分析和仿真实验表明
该机制为位置与身份分离协议的映射理论提供了良好的安全保障
通过设定不同的信任度门限
能够有效缓解隧道路由器对虚假映射信息的使用
从而进一步降低了映射欺骗的危害。
Abstract
Through analyzing mapping spoofing which may exist or happen in the incoming mapping theory under loca-tor/ID separation protocol
a new mapping approach to relieve the thread of mapping spoofing was proposed.This ap-proach introduced the reputation model based on feedback evaluation into the mapping theory and increased the trust-worthiness of the mapping information by means of the dynamic trust evaluation.Meanwhile
the self-certifying identifi-ers represented the identity information of tunnel routers
and guaranteed the authenticity of the mapping sources.Per-formance analysis and simulation results have shown that the approach provides a satisfying safeguard for the mapping theory.By setting the threshold of different trust value
this approach can effectively inhibit the tunnel routers from em-ploying the mendacious mapping information
and further reduces the hazards of mapping spoofing.