Uppsats
Integrating Multi-Party Key Exchange into Host Identity Protocol Base Exchange : Establishing conference keys in Industrial Networks
Kandidat-uppsats
Linköpings universitet/Institutionen för datavetenskap
Publicerad: 2025
Språk: Engelska
Nyckelord
klicka för att sökaSammanfattning
The increasing need for secure interconnection of geographically distributed industrial sites has set Virtual Private LAN Service (VPLS) as an effective solution for providing Layer 2 VPNs with low latency and simplicity. However, traditional VPLS implementations rely on trusting the provider’s network, creating risks of unauthorised access and data compromise. Integrating the Host Identity Protocol (HIP) into VPLS introduces a new security paradigm by decoupling endpoint identity from location and leveraging cryptographic host identifiers for authentication and secure communication. HIP enhances the security of VPLS by mitigating IP spoofing, supporting mobility, and enabling strong, identity-based trust without relying on IP addresses alone. In this project, we explore how HIP-enabled VPLS can improve the confidentiality, integrity, and resilience of Layer 2 VPNs, aligning with zero-trust principles by minimising dependency on provider trust. Specifically, while customer edge (CE) devices use encryption at the customer side to ensure end-to-end data confidentiality, provider edge (PE) routers establish a multi-party group key using a modified HIP Base Exchange protocol. This group key secures packet integrity and provides replay protection across the provider's network. To protect the key agreement process against dishonest participants, the protocol incorporates a robust two-round Burmester–Desmedt variant within the HIP handshake, enabling efficient detection and rejection of malicious nodes. The resulting architecture offers a scalable, zero-trust Layer 2 VPN solution that combines the operational simplicity of VPLS with provable security guarantees and enhanced protection against insider and outsider threats. This approach reduces reliance on the security of provider networks, increases customer data autonomy, and ensures compliance with data protection regulations by securing sensitive data before it enters the provider network.
Information
- Författare
- Janzon, Linus, Johansson, Lukas
- Lärosäte / institution
- Linköpings universitet/Institutionen för datavetenskap
- Publiceringsdatum
- 2025
- Uppsatstyp
- Kandidat-uppsats
- Språk
- Engelska
- Nyckelord
- ⌕Industrial Internet of Things (IIoT)⌕Mininet⌕Host Identity Protocol (HIP)⌕HIP Base Exchange (BEX)⌕Multi-Party Key Exchange⌕Conference Keys⌕Burmester–Desmedt protocol⌕Elliptic Curve Cryptography (ECC)⌕Virtual Private LAN Service (VPLS)⌕Layer 2 VPN⌕Zero Trust Networks⌕Cybersecurity in industrial networks⌕Software Defined Networking (SDN)⌕Governor node architecture⌕Cryptographic identities⌕Identity-based trust⌕IP Spoofing mitigation⌕Group key establishment⌕Replay protection⌕Performance analysis of cryptographic protocols
Utforska vidare
Liknande uppsatser
Uppsatser med liknande ämnen och nyckelord.
Kandidat-uppsats, Högskolan i Halmstad/Akademin för informationsteknologi
Bodeklint, John, Jörgensen, Kasper
Publicerad: 2026
Kandidat-uppsats, Mittuniversitetet/Institutionen för data- och elektroteknik (2023-)
Hellzén, Philip
Publicerad: 2026
Master-uppsats, KTH/Industriell ekonomi och organisation (Inst.)
Eriksson, Alexander, Mirza, Rahel
Publicerad: 2025
Yrkesexamen på grundnivå, Mälardalens universitet/Akademin för innovation, design och teknik
Ayoub, Majd
Publicerad: 2025
Yrkesexamen på avancerad nivå, Karlstads universitet/Institutionen för matematik och datavetenskap (from 2013)
Solaiman, Ari
Publicerad: 2025
Magister-uppsats, Högskolan i Halmstad/Akademin för informationsteknologi
Joseph, Augustine
Publicerad: 2026