Abstract
Many organizations are introducing the new IPv6 internet protocol. The new protocol promises to tackle IP address and routine issues. In addition, the IPv6 promises to address security problems that the IPv4 exhibits. This paper has examined the network security features that the IPv6 architecture introduces. The analysis found that the IPv6 is more effective in providing security services at the network layers as it incorporates the IP security protocol. The IPv6 security protocol uses two main security mechanisms; the authentication header and the encapsulating security payload. These mechanisms are effective in addressing security issues of confidentiality, non-repudiation, authentication and integrity.
Introduction
IPv6 (Internet Protocol Version 6) is the most recent version of internet communication protocol. The internet community is shifting from the traditional IPv4 to the new IPv6. The IPv6 protocol offers a location and identification system for computers on networks and directs traffic across the internet (Park, Nah, & Chung, 2005). The IPv6 is more effective that the IPv4 in providing security service from the network layer because it has in inbuilt IP security protocol that offers two main security mechanisms; authentication header and the Encapsulating Security Payload.
Internet Protocol Version 6 Architecture
IPv6 is a networking protocol that allows internet users to communicate using Doman Name Systems. The protocol uses security technologies such as Internet Protocol Security (IPSec) to facilitate the secure and successful transfer of data packets between computers. IPv6 can also work in a pure environment and requires computers that run windows and routers that support IPv6. The IPv6 architecture comprises of the Neighbor Discovery, Multicast Listener Discovery (MLD) and the Internet Control Message Protocol version 6. The three main protocols take the place of the Internet Layer Protocols in the DARPA model. All protocols above the internet layer depend on the basic services that IPv6 offers.
Network security issues
Information security is one of the vital elements for network users. However, information security is a lucid term that refers to various issues. The first issue is integrity of information. Integrity is an information security element that refers to the extent to which information reaches the intended recipient without alteration (Durdagi & Buldu, 2010). The internet standard should enhance the integrity of user’s information so as to protect them from fraud and other security threats. Another component of internet security is confidentiality. Confidentiality is an information security element that refers to the extent to which information is protected from unauthorized users (Park, Nah & Chung, 2005). Often, internet users convey sensitive information such as financial data, health records, and proprietary information over the internet. Users suffer huge losses when such information is accessed by unauthorized users. Therefore, is important for the internet communication protocol to guarantee the confidentiality of data.
Another network security issue is the availability. Availability refers to the extent to which information is available when users need them (Durdagi & Buldu, 2010). A good internet protocol should protect the availability of data by ensuring that unauthorized people do not tamper or sabotage the information or its source. Non-repudiation is also a vital network security issue. Non-repudiation is the extent to which receivers can verify that the sender of some information did actually send the message even when the sender denies ever having sent the message (Park, Nah & Chung, 2005). A good internet communication protocol should promote non-repudiation by making it hard for people to impersonate others within the network. The final network security issue is traffic analysis. Traffic analysis is an attack on a network where the attacker can make deductions about users by analyzing the network traffic patterns of these users.
IPv6 Network Security
At present, over 90% of internet users are using the IPv4 standard (Herman & Fabian, 2014). This internet protocol standard has more than a few limitations including limited IP address space and low routing performance. The internet assigns an IP address to every device that connects for identification purpose. The rapid expansion of internet usage has created a problem as the existing standard (IPv4) requires far more address than the available space. The IPv6 overcomes this challenge by offering increased IP address size, simplified host addressing, improved scalability of multicast routing, increased addressing hierarchy support and improved security.
The IPv6 also offers an additional benefit of enhanced security. The IPv6 integrates the IP security (IPsec) in its protocol making it fundamentally more secure that IPv4 (Zhang & Sampalli, 2008). It is not an application specific security mechanism; hence, they eliminate the need to modify application programs of the upper layer (Park, Nah & Chung, 2005). The architecture also provides the same security service to the transport and application layers. The IPv6 also incorporate additional security mechanism; hence, it enhances the security of network users.
Security mechanism in the IPv6
- Authentication Header
Authentication is one of the security mechanisms present in the IPv6 architecture. The authentication mechanism focuses on verifying whether the data reaching the recipient is the same as the data that the sender sent. The IPv6 incorporates an authentication header that offers authentication and integrity without confidentiality (Park, Nah & Chung, 2005). IPv6’s authentication header protects the integrity and authenticity of the information that people share through the network, but does not protect the data against unauthorized access. This mechanism provides authentication and integrity by computing a cryptographic authentication function above the IPv6 datagram and utilizing a secret authentication key in the process. In this mechanism, the sender inputs the authentication data prior to sending a message and the receiver confirms the accuracy of the authentication data upon reception (Zhang & Sampalli, 2008). The mechanism omits the Hop Limit Field because this field changes in transit. However, this omission does not have an adverse effect on the security of the network. The authentication header can also provide non-repudiation when used together with some authentication algorithms. The authentication header does not provide protection for traffic analysis and confidentiality.
- Encapsulating Security Payload
Another security mechanism that the IPv6 employs is the encapsulating security payload (ESP). The ESP focuses on providing confidentiality and integrity to IPv6 datagrams. This mechanism provides these security features by encapsulating the entire datagram or the upper-layer of the datagram inside the ESP (Park, Nah & Chung, 2005). This action encrypts a significant portion of the ESP content and appends a new cleartext IPv6 header to the encrypted ESP. The cleartext IPv6 header conveys the encrypted data through the network. At the recipient’s end, the recipient eliminates and discards the cleartext IPv6 header and options, decrypts the ESP, remove the ESP headers and process the original IPv6 datagram (Herman & Fabian, 2014). IPv6 has two ESP modes; the IP-mode and the transport-mode. The IP-mode summarizes the entire IP datagram within the IP header while the transport-mode summarizes a TCP or UDP frame inside the IP.
- Combining Security Mechanisms
The authentication header and the ESP are the main security mechanisms in IPv6. However, the IPv6 can also create other security mechanisms by combining the ESP with the authentication header (Herman & Fabian, 2014). The authentication header offers authentication and integrity but can also provide non-repudiation when it combines with certain algorithms of the ESP. The ESP provides confidentiality and integrity but can also offer authentication when it combines with certain authenticating encryptions from the authentication header.
Challenges
A significant challenge of switching to the IPv6 is increased cost. The use of the authentication header is bound to increase the processing costs of IPv6 protocol among the participating systems (Herman & Fabian, 2014). The authentication header will also increase the latency of communication. The latency of communication is bound to increase because the authentication processes at the sender and receiver’s ends (Zhang & Sampalli, 2008). Another challenge of the IPv6 is that it does not offer protection against traffic analysis. The IPv6 cannot offer this protection economically at the internet layer.
Conclusion
The IPv6 is the newest internet communication protocol. This protocol is designed to overcome the challenges of IP address and routing that characterized the IPv4. The IPv6 also provide addition security features by integrating the IP security protocol. The architecture offers to main security mechanisms; authentication header and the encapsulating security payload. These two mechanisms provide users with non-repudiation, integrity, authentication, and confidentiality.
References
Durdagi, E., & Buldu, A., (2010). IPv4 and IPv6 security and threat comparison. Social and Behavioral Sciences. 2 (1), 5285- 5291
Hermann, S., & Fabian, B., (2014). A comparison of Internet Protocol (IPv6) security guideline. Future Internet. 6 (1),
Park, S., Nah, J., & Chung, K., (2005). The execution of IPsec-based network security system in IPv6 Network. Lectures Notes in Computer Science. 3397 (1), 109- 116
Zhang, J., & Sampalli, S., (2008). Enhanced security mechanism for mobile IPv6. International Journal of Network Security. 16 (3), 291- 300
Carolyn Morgan is the author of this paper. A senior editor at MeldaResearch.Com in custom research paper services. If you need a similar paper you can place your order from urgent essay writing service.

