摘要
传统密钥恢复协议采取增加密钥恢复字段的方法,恶意攻击者容易辨别具备密钥恢复功能的数据包,并进行过滤阻挠。该文将潜信道密钥恢复与具体协议相结合,提出基于IPSec协议的密钥恢复方案。该方案易于实施,数据包具有不可过滤性,可避免恶意攻击者的过滤阻挠,进行有效的网络监控。
The key recovery schemes available usually use the method of adding a key recovery field at the end of the protocol packet. So the intruder can easily distinguish the data packet with key recovery functions from the others and filtrate them in order to prevent key recovery. The paper describes an IPSec key recovery scheme based on subliminal channel. The scheme is easy to implement, and the packets are not filterable which can avoid the intruder's filtration, This scheme provides efficient network monitor and control.
出处
《计算机工程》
CAS
CSCD
北大核心
2008年第2期100-102,110,共4页
Computer Engineering
关键词
密钥恢复
潜信道
密钥管理
key recovery
subliminal channel
key management