Authors:
Jacques Demerjian
1
;
Ahmed Serhrouchni
1
and
Mohammed Achemlal
2
Affiliations:
1
GET-Télécom Paris – LTCI-UMR 5141 CNRS, France
;
2
France Telecom R&D, France
Keyword(s):
Access Control, Attribute Certificate, Authentication, DHCP, PKI, PMI, X.509 Identity Certificate.
Related
Ontology
Subjects/Areas/Topics:
Communication and Software Technologies and Architectures
;
Data and Application Security and Privacy
;
Data Communication Networking
;
Data Engineering
;
Data Privacy and Security
;
Databases and Data Security
;
e-Business
;
Enterprise Information Systems
;
Information and Systems Security
;
Network and Service Management
;
Network Management
;
Network Security
;
Telecommunications
;
Wireless Information Networks and Systems
Abstract:
In the current Dynamic Host Configuration Protocol, security is not considered. DHCP itself does support neither an access control for a proper user nor the mechanism with which clients and servers authenticate each other. In this paper, we introduce a novel authentication and access control mechanism for DHCP systems. This solution defines a new DHCP option that provides the authentication of both, entities (client/server) and DHCP messages. We built up our mechanism on the use of public key cryptography, X.509 identity certificates and attribute certificates. In addition, the PMI (Privilege Management Infrastructure) functionalities are attributed to a new server that groups DHCP server and AA (Attributes Authority) server. The resulting server creates an attribute certificate to the client that will be used then in the access control.