期刊文献+

IP Sec下安全关联协商的实现环境

Conditions for negotiating security associations on IP Sec
下载PDF
导出
摘要 IPSec是IP协议层的安全体系结构,是构筑虚拟专网(VirtualPrivateNetworks,VPNs)的基本规范;它是通过安全关联(SecurityAssociation,SA)的约定和协商来实现对通信实体间通信过程的保护.目前,在该领域中尚有诸如IPSec下安全关联的协商机制等问题有待进一步探讨.首先分析IPSec安全关联及其协商的实现条件和相应的保护环境,即ISAKMPSA,然后讨论在IKE协议中协商ISAKMPSA过程存在的安全关联载荷认证缺陷,并以主模式下预共享密钥方式交换过程为例,针对该缺陷对IKE协议交换过程中验证参数的计算提出了改进方案. IP Sec is the protocol set in the IP layer and one of the basic specifications that are contributed to the virtual private networks(VPNs). The secure communications about two entities will be protected by the definition & negotiation of security associations (SAs). Nowadays, a lot of questions, the mechanism of negotiating SAs on IP Sec, will be further debated. The article discusses IP Sec's association and its negotiating condition, which will protect the negotiating procedure of IP Sec's association. Then, we point out an amendment on the security flaws, in which HASH-parameter definition is wrong, in the negotiating ISAKMP SA by the pre-shared key authentication under the main mode on IKE protocols.
出处 《安徽工程科技学院学报(自然科学版)》 CAS 2002年第2期20-23,共4页 Journal of Anhui University of Technology and Science
基金 安徽省教育厅自然科学基金资助项目(2002KJ3282C)
关键词 安全关联 IKE协议 IP协议 协商 共享密钥 安全体系结构 VPN 主模 虚拟专网 通信 IP Sec security association IKE protocol
  • 相关文献

参考文献5

  • 1Christian Huitema. IPv6 the new internet protocol. 2nd edit.[M], New Jersey: Prentice Hall PTR, 1998.
  • 2D.Maughan, M. Schertler, M. Schneider, J.Turner. Internet security association and key management protocol (ISAKMP)[Z], RFC2408. 1998.
  • 3D.Harkins, D.Carrel. The internet key exchange(IKE)[Z], RFC2409.1998.
  • 4王焕宝,张佑生.IKE协议的安全属性[J].计算机工程,2002,28(5):152-154. 被引量:1
  • 5J.Zhou. Further analysis of the internet key exchange protocol[J]. Computer Communication, 2000,(23):1606- 1612

二级参考文献5

  • 1[1]Maughan D,Schertler M,Schneider M,et al. Intemet Security A ssociation and Key Management Protocol (ISAKMP).RFC2408. 1998-11
  • 2[2]Huitema C.IPv6:The New Intemet Protocol(Second Edition). PrenticeHall PTR, 1998
  • 3[3]Harkins D, Carrel D. The Intemet Key Exchange (IKE) . RFC2409,1998-11
  • 4[4]Matasuura K, Imai H . Modified Aggressive Mode of Intemet KeyExchange Resistant Against Denial-of-Service Attacks.IEICE TRANS.INF.&SYST., 2000, E83-D(5)
  • 5[5]AuraT,Nikander P.Stateless Connection. In Information and Communications Security, eds.,Y Han.Okamoto T,and S Qing,Bcrlin, SpringerVerlag, 1997-11

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部