摘要
Internet(因特网)密钥交换协议(IKE)由于其灵活性和复杂性,不可避免的存在某些安全隐患。简要介绍其工作机制之后,分析了两种中间人攻击的方式,为有效抵御第二种中间人攻击,对基于数字签名的主模式交换过程进行了改进,并提出了密钥签名载荷的概念。最后,给出了改进前后的定量的性能分析,结合freeS/WAN源代码,修改和增加了相应的函数,将改进思想融入其中。
It is inevitable that there are some security limitations in IKE protocol, because of its flexibility and complexity. After the mechanism of IKE is introduced, the two kinds of man-in-middle attack are analyzed. In order to defend the second one, some improvements are presented in the main mode with signature authentication. Moreover the conception of key-signature payload is provided. Finally, the paper makes a quantitative capability analysis on the whole. By combining with the open code of freeS/WAN, it modifies and adds some appropriate functions to integrate the idea of improvement into IKE.
出处
《南京邮电大学学报(自然科学版)》
EI
2007年第1期69-74,共6页
Journal of Nanjing University of Posts and Telecommunications:Natural Science Edition
基金
国家自然科学基金(60573141
70271050)
江苏省自然科学基金(BK2005146)
江苏省高技术研究计划(BG2004004
BG2005037
BG2005038
BG2006001)
国家高技术研究发展计划(863计划)(2006AA01Z439)
南京市高科技项目(2006软资105)
现代通信国家重点实验室基金(9140C1101010603)
江苏省计算机信息处理技术重点实验室基金(kjs050001
kjs0606)资助项目
关键词
IKE
数字签名
主模式
中间人攻击
IKE
Digital signature
Main mode
Man-in-middle attack