Abstract
In this paper, we present a novel source address spoofing prevention method for IPv6 access network called CGA based source address authentication (CSAA). It makes use of CGA (cryptographically generated address) to generate an unspoofable identifier of host without PKI, and bind it to the authorized address of the host. Then all the packets sent out by the host can be validated in the first-hop router by a light-weight method.