<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.xu-intarea-challenge-icmpv6" target="https://datatracker.ietf.org/doc/html/draft-xu-intarea-challenge-icmpv6-03">
   <front>
      <title>Enhancing ICMPv6 Error Message Authentication Using Challenge-Confirm Mechanism</title>
      <author initials="K." surname="Xu" fullname="Ke Xu">
         <organization>Tsinghua University &amp; Zhongguancun Laboratory</organization>
      </author>
      <author initials="X." surname="Feng" fullname="Xuewei Feng">
         <organization>Tsinghua University</organization>
      </author>
      <author initials="A." surname="Wang" fullname="Ao Wang">
         <organization>Southeast University</organization>
      </author>
      <date month="April" day="26" year="2026" />
      <abstract>
	 <t>   The Internet Control Message Protocol for IPv6 (ICMPv6) is essential
   for network diagnostics but is vulnerable to off-path spoofing
   attacks, especially when error messages relate to stateless transport
   protocols like UDP.  An attacker can forge these messages to degrade
   performance or enable Man-in-the-Middle attacks.

   This document proposes a robust, stateless challenge-response
   mechanism to authenticate ICMPv6 error messages.  Traditional
   stateful challenge mechanisms are vulnerable to state-exhaustion
   Denial-of-Service (DoS) attacks.  To avoid this, the proposed
   solution is inspired by TCP SYN-Cookies, eliminating the need to
   store per-challenge state by using cryptographic computation.  It
   limits state management to minimal flags on existing sockets or a
   bounded probabilistic data structure.  This approach effectively
   authenticates ICMPv6 error messages while inherently resisting both
   off-path spoofing and state-exhaustion DoS attacks, thus improving
   the robustness of ICMPv6.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-xu-intarea-challenge-icmpv6-03" />
   
</reference>
