期刊文献+

基于加密接入令牌的IGMP安全机制 被引量:2

Secure IGMP Mechanism Based on Encrypted Access Token
下载PDF
导出
摘要 在 IP组播中当前使用的组管理协议 IGMP不提供接入控制 ,任何端点用户可自由地加入组播组 ;此外 ,IGMP报文在传输时没有加密措施 ,无法保证其安全性 .因此 ,对 IGMP报文的认证和接入控制策略便成为亟待解决的重要课题 .在 IGMP报文后附加接入令牌的方法虽然可以解决 IGMP协议存在的一些安全问题 ,但其仍存在一些缺陷 .在此基础上 ,提出了一种加密接入令牌的方法 ,阐述了如何申请、产生、传输和使用令牌 .加密接入令牌可以安全的传输认证和接入控制信息 ,并且可以多次使用 ,不需要在用户和组播路由器之间建立安全关联 SA。 IGMP, the multicast management protocol, provides no access control of join members, thus any host can join a certain multicast group. Moreover, due to lack of encryption measures, IGMP messages cannot ensure their confidentiality in the communication process. Thus Authentication of IGMP messages and policy of access control are indicated as the key problems. The Access Token attached to the IGMP messages can solve some problems, but it still has some limitations. Presented a solution utilizing the Encrypted Access Token (EAT) and introduced a way to request, issue, transport and apply the token. The EAT can securely transport authentication and access control information, and can be applied several times without the establishment of security association (SA) between user and multicast router, so that its efficiency is enhanced.
出处 《小型微型计算机系统》 CSCD 北大核心 2004年第12期2186-2189,共4页 Journal of Chinese Computer Systems
基金 国家"8 63"信息技术领域 ( 2 0 0 2 AA12 10 67)资助 国家自然科学基金 ( 60 2 72 0 43 )资助
关键词 IGMP 接入令牌 认证 接入控制 IGMP access token authenticate access control
  • 相关文献

参考文献10

  • 1Deering S. Host extension for IP multicasting[S]. RFC1112, August 1989.
  • 2Fenner W. Internet group management protocol version 2[S]. RFC2236, November 1997.
  • 3Cain B, Deering S, Fenner B, Thyagarajan A. Internet group management protocol, version 3[S]. RFC3376,October 2002.
  • 4Thomas Hardjono, Brad Cain, Key establishment for IGMP authentication in IP multicast[J]. IEEE European Conference on Universal Multiservice Networks(ECUMN), CERF, Colmar, France, September 2000.
  • 5Moy J. OSPF: anatomy of an internet routing protocol[M]. Addison-Wesley,1998.
  • 6Wei L.Authentication PIM version 2 message[Z]. IETF internet draft, work in progress.
  • 7He Hai-xiang, Thomas Hardjono. Simple multicast receiver access control[Z]. draft-irtf-gsec-smrac-00.txt, November 2001.
  • 8Van A, Paridaens O. Security issues in internet group management protocol version 3 (IGMPv3)[Z].draft-irtf-gsec-igmpv3-security-issues-01.txt,February, 2002.
  • 9Wallner D, Harder E, Agee R. Key management for multicast: issues and architectures[S].RFC2627,June 1999.
  • 10Mark Baugher,Thomas Hardjono,Hugh Harney,Brian Weis,The group domain of interpretation[Z].draft-ietf-msec-gdoi-07.txt,December, 2002.

同被引文献4

引证文献2

二级引证文献2

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部