摘要
移动IP中绑定更新机制的引入带来了新的安全威胁.由于绑定更新过程相当于节点的重新接入过程,绑定信息成为了新的攻击对象.攻击节点可以通过重放节点绑定信息的形式来冒充此节点;通过修改绑定消息中的地址部分来提供虚假地址;还可以通过大量重放监听到的绑定消息进行拒绝服务攻击.为了保护绑定更新过程,引入对绑定更新消息的加密机制,提出了用公开密钥加密的方式来保护移动节点的一种地址绑定过程,并从安全性以及处理时间方面与现有的方式进行了分析和比较.
Binding updates mechanisms in mobile IP give rise to new threats. Now, binding messages are attacked more often than not. An attacking node can personate other nodes through replaying their binding messages, changing the address field to provide wrong return address, and achieving DoS (Denial of Service) attack by replaying binding messages. To secure the safety of binding updates, public-key encryption was used to protect binding updates, and compare the procedure with the current method.
基金
国家"863"项目(2001AA121041).