摘要
针对Split场景下,家乡代理不支持EAP协议的问题,提出了一种基于diameter-EAP协议的认证方案。认证服务器在对移动节点进行认证时,通过支持EAP协议的接入路由器对移动节点进行身份认证,为移动节点和MIP6服务提供者配置共享密钥,用于服务提供者对移动节点的认证。采用BAN逻辑对协议的安全性进行了形式化证明,并比较分析了该方案的性能,分析结果表明,该协议的密钥性能达到了RFC4004的水平。
According to the issue that the home agent does not support EAP protocol in split scenario, an authentication solution based on diameter/EAP protocol is given. When the authentication server wants to authenticate the mobile node, it uses the ASP as the EAP authenticator. After authentication, it distributes the IKEv2 pre-shared key between the mobile node and home agent to the home agent. The security of IKEv2 pre-shared key distribution is proven using BAN logic, and the performance of this solution is analyzed.
出处
《计算机工程与设计》
CSCD
北大核心
2011年第5期1593-1596,共4页
Computer Engineering and Design