地址解析协议由于缺少认证机制而容易受到攻击,比如中间人攻击,Do S攻击等,因此其安全问题长久以来一直受到人们的关注。本文对地址解析有关的两个问题进行了研究。首先,证明了地址解析问题的不可判定性,这表明所有采用判定的方式来保障地址解析过程的方法都是不完美的;其次,证明了地址解析过程与重复地址检测过程的等价性。这个结论表明地址解析过程与重复地址检测过程可以互相替代,甚至由同一过程来完成,这将大大简化地址解析协议的设计与实现。
Given the lack of authentication mechanisms,the address resolution protocols( ARPs)( address resolution protocol,neighbor discovery protocol,and so on) are vulnerable to attack,such as man in the middle and denial of service among others. Therefore,the safety problem of the address resolution( AR) has been significantly given focus,and,in this paper,two problems related to AR have been investigated. First,the indecisiveness of the AR is proven. Therefore,all decision methods adopted to ensure the AR are imperfect; second,the equivalence between the AR and the duplicate address detection( DAD) process is proven. Thus,the AR and the DAD process can be replaced by each other,and can even be completed by the same process which will significantly simplify the design and implementation of the ARPs.