Jacques Demerjian, Ahmed Serhrouchni, Mohammed Achemlal


In the current Dynamic Host Configuration Protocol, security is not considered. DHCP itself does support neither an access control for a proper user nor the mechanism with which clients and servers authenticate each other. In this paper, we introduce a novel authentication and access control mechanism for DHCP systems. This solution defines a new DHCP option that provides the authentication of both, entities (client/server) and DHCP messages. We built up our mechanism on the use of public key cryptography, X.509 identity certificates and attribute certificates. In addition, the PMI (Privilege Management Infrastructure) functionalities are attributed to a new server that groups DHCP server and AA (Attributes Authority) server. The resulting server creates an attribute certificate to the client that will be used then in the access control.


