Ағылшыншамен салыстырыңыз: абзацты басыңыз — түпнұсқа терезеде ашылады. Абзац астындағы EN түймесі оны мәтін ішінде көрсетеді.
Кіріспе
Криптографиялық түрде жасалған мекенжай (CGA) — криптографиялық хэш-функциясынан есептелген хост идентификаторына ие Интернет протоколының 6-шы нұсқасы (IPv6) мекенжайы. Бұл процедура Secure Neighbor Discovery Protocol (SEND) протоколында ашық кілтті IPv6 мекенжайымен байланыстырудың бір жолы болып табылады.
A Cryptographically Generated Address (CGA) is an Internet Protocol Version 6 (IPv6) address that has a host identifier computed from a cryptographic hash function. This procedure is a method for binding a public signature key to an IPv6 address in the Secure Neighbor Discovery Protocol (SEND).
Қауіпсіздік
Шабуылшы клиентке шабуылшыға тиесілі емес белгілі бір CGA-дан жарамды хабарлама алды деп сендіру үшін, шабуылшы Hash1 және Hash2-нің тиісті биттері үшін хэш-қосуды табуы керек. Егер шабуылшы CGA параметрлерінің жиынтығын (шабуылшы жеке кілтін білетін ашық кілтін қоса алғанда) тапса, ол мақсатты CGA-мен бірдей CGA-ны құру үшін пайдаланылуы мүмкін, содан кейін шабуылшы CGA-ның иесі болып табылатын хостты байқалмай тұрып, кейіп таныта алады (клиент бұрын хостпен байланысқаннан кейін, бірақ CGA өзгергенін ескермесе, мүмкін). Hash1-дің 64 битінің тек 59-ы интерфейс идентификаторында қолданылады, өйткені 5 бит ауыстырылып жазылады. Sec 0-ге тең CGA үшін, бұл қажетті 59 битті беретін CGA параметрлерінің жиынтығын табудың құны шамамен (үлкен O белгісінде) болады. Алайда, Sec-тің үлкен мәні бұл құнды 1 есеге арттырады, өйткені Hash2-нің алғашқы 16 есе Sec биті маңызды болады (яғни, ол осы биттерді 0-ге тең деп талап ету арқылы хэш кеңейтуді іске асырады). CGA генерациялау процесінде Sec-тің құнына байланысты мекенжайды генерациялау құны бірдей фактормен көбейтіледі, бірақ CGA-ны пайдалану және тексеру құны тұрақты болып қалады. Sec CGA параметрлерінің дерек құрылымының емес, мекенжайдың өзінде болғандықтан, шабуылшы Sec мәнін мақсатты мекенжайдан кішірек (мысалы, 0) пайдалана алмайды. Бұл мақсатты CGA-дан өзгеше CGA-ны береді, өйткені интерфейс идентификаторының ең сол жақтағы үш битінің кем дегенде бірі сәйкес келмейді. Егер мақсатты Sec мәні интерфейс идентификаторына жазылған болса, онда Hash2 (әрине) тексеру процесінде қажетті саны 0-битінің жоқ екені анықталады. CGA генерациялау процесінде үш мекенжай соқтығысуының болуы өте сирек. Егер қайталанған мекенжай үшінші рет анықталса, онда бұл конфигурация немесе іске асыру қатесі немесе қызметтен бас тарту шабуылдарынан болуы мүмкін. Осы себепті collCount үшін жарамды мәндердің саны 0-ден 2-ге дейінгі аралықта шектеледі. Бұл параметрді пайдаланушы шабуылдаушыдан оны пайдалануды және әр түрлі мәнді сынаған сайын Hash2 үшін тағы бір қара күш іздеуді орындаудың қажеті жоқ, әр түрлі мәндерді сынап көруін болдырмау үшін CGA тексеру процесінде осы диапазонда екендігі тексерілуі керек. Hash1 нәтижелерін жинақтау операциясына кіші желі префиксін қосу арқылы шабуылшы әр түрлі кіші желі префикстері бар мекенжайларға шабуыл жасау үшін бір алдын ала есептелген дерекқорды пайдалана алуына жол берілмейді. Тексеруші сонымен қатар ашық кілт дәл осы мекенжайға байланысты екеніне және мүмкін бірдей интерфейс идентификаторы бар, бірақ басқа ішкі желі префиксі бар мекенжайға емес екеніне сенімді бола алады. CGA-ның спецификациясында CGA параметрлері деректерінің құрылымындағы кіші желі префиксін пайдалануды талап еткендіктен, CGA тексеру процесінде оның CGA-ның кіші желі префиксіне сәйкес келетіндігі тексерілуі тиіс.
In order for an attacker to make a client believe it received a valid message from a certain CGA that isn't owned by the attacker, the attacker must find a hash collision for the relevant bits of Hash1 and Hash2 by performing a brute force attack. If the attacker finds a set of CGA Parameters (including a public key for which the attacker knows the private key) that can be used to generate the same CGA as the target CGA, then the attacker can impersonate the host who actually owns the CGA without being detected (except perhaps when the client has contacted the host before and notices that the public key has changed but the CGA has not). Of the 64 bits of Hash1, only 59 are used in the interface identifier since 5 bits are being overwritten. For a CGA with Sec equal to 0, this means that the cost of finding a set of CGA Parameters that yield the desired 59 bits is approximately (in big O notation). A larger value of Sec, however, increases this cost by a factor of to because the first 16 times Sec bits of Hash2 then become relevant (i. e. it implements a hash extension by demanding those bits to be equal to 0). In the CGA generation process, the cost of generating an address is increased by the same factor depending on the value of Sec, but the cost of using and verifying a CGA remains constant. Because Sec is not part of the CGA Parameters data structure but of the address itself, an attacker cannot use a Sec value smaller than that of the target address (like 0) in an attempt to skip (or scale down) the brute force attack on Hash2. This would namely yield a different CGA from the target CGA since at least one of the three leftmost bits of the interface identifier would not match. If the target Sec value is written to the interface identifier anyway, then Hash2 will (almost certainly) be found to lack the required amount of leftmost 0 bits during the verification process. During the CGA generation process, it is very unlikely that three address collisions occur. If a duplicate address would be detected for the third time, then this would most likely be due to a configuration or implementation error or a denial of service attack. For this reason, the number of valid values for collCount is limited to the range from 0 to 2. This parameter must be verified to be in this range during the CGA verification process in order to prevent an attacker from exploiting it and trying all different values without the need to perform another brute force search for Hash2 each time a different value is tried. By including the subnet prefix in the digest operation that results in Hash1, it can be prevented that an attacker is able to use a single pre computed database to attack addresses with different subnet prefixes. A verifier can also be sure that the public key has been bound to this exact address and not possibly to an address with the same interface identifier but a different subnet prefix. Since the CGA specification prescribes to use the subnetPrefix from the CGA Parameters data structure for the digest operations, it must be verified that it matches the subnet prefix of the CGA during the CGA verification process.