Decentralized Distribution of PCP Mappings Over Blockchain for End-to-End Secure Direct Communications

Decentralized Distribution of PCP Mappings Over Blockchain for End-to-End Secure Direct Communications
复制标题

DOI:
10.1109/access.2019.2934049
复制
发表时间:
2019-08
期刊:
影响因子:
3.9
通讯作者:
Elie F. Kfoury;Ignacio Aguaded;J. Crichigno;E. Bou-Harb;David J. Khoury
Elie F. Kfoury;Ignacio Aguaded;J. Crichigno;E. Bou-Harb;David J. Khoury
中科院分区:
计算机科学3区
文献类型:
--
作者:
Elie F. Kfoury;Ignacio Aguaded;J. Crichigno;E. Bou-Harb;David J. Khoury

文献摘要

被引文献

相似文献

网络地址转换(NAT)是一种使具有私有IP地址的设备能够通过共享公共IP地址连接到Internet的方法。穿越NAT设备对于IP语音(VoIP)和物联网(IoT)等广泛的应用来说仍然是一个挑战。端口控制协议(PCP)是一个相对较新的协议,由互联网工程任务组(IETF)标准化,以解决NAT穿越问题。它允许NAT设备请求和管理其私有IP地址和传输层端口到公共IP地址和端口之间的映射。由于PCP需要依赖于应用程序的方法将映射分发到远程主机,因此有几种攻击可以针对分发服务器并使通信通道易受攻击。在本文中,我们提出并实现了一种分散的基于区块链的方法来分发PCP映射,从而实现安全的端到端(e2e)直接通信,而无需任何可信的第三方服务器。NAT设备将其PCP映射和公钥注册到区块链中,然后其他对等方可以了解这些映射,以建立端到端的安全直接通信。实现验证了该系统在交易费用方面是可行的,可以简化和保护端到端的直接通信,并且可以与传统的安全方法互通。
Network Address Translation (NAT) is a method that enables devices with private IP addresses to connect to the Internet by sharing a public IP address. Traversing the NAT device remains a challenge for a wide range of applications such as Voice over IP (VoIP) and Internet of Things (IoT). The Port Control Protocol (PCP) is a relatively new protocol standardized by the Internet Engineering Task Force (IETF) to solve the NAT traversal issues. It allows a NATed device to request and manage a mapping between its private IP address and transport-layer port to a public IP address and port. As PCP requires an application-dependent method for distributing the mappings to remote hosts, several attacks can target the distributing server and render the communication channel vulnerable. In this paper, we propose and implement a decentralized Blockchain-based approach for distributing PCP-mappings, enabling secure end-to-end (e2e) direct communications without any trusted third party server. NATed devices register their PCP mappings and public keys into the Blockchain, and other peers can then learn about these mappings to establish end-to-end secure direct communications. The implementation verifies that the system is feasible in terms of transactions fees, can simplify and secure end-to-end direct communications, and can interwork with conventional security methods.