期刊文献+

Internet密钥交换协议的安全缺陷分析 被引量:2

Analyzing the Security Flaws of Internet Key Exchange Protocols
下载PDF
导出
摘要 IKE(Internet key exchange,RFC2409)提供了一组Internet密钥交换协议,目的是在IPSec(IP security)通信双方之间建立安全联盟和经过认证的密钥材料.随后有学者发现IKE协议存在一个安全缺陷,并给出相应的修改建议.指出了修改后的IKE协议仍然存在类似的安全缺陷,并描述了一个成功的攻击.在给出修改建议的同时,成功地利用BAN逻辑分析了导致这两个安全缺陷的原因. IKE (Internet key exchange, RFC2409) describes a suite of Internet key exchange protocols for establishing security associations and obtaining authenticated keying material. A security flaw in these IKE protocols is observed and a simple modification is proposed. It is pointed out that there is a neglected security flaw in the amended IKE protocols. And a successful attack on the amended IKE protocols is also provided. A new amendment to IKE protocols is proposed, and the reasons which cause the two security flaws are analyzed by using BAN logic successfully.
出处 《软件学报》 EI CSCD 北大核心 2002年第6期1173-1177,共5页 Journal of Software
关键词 INTERNET 密钥交换协议 安全缺陷分析 安全联盟 认证 主模式 认证者 网络安全 Artificial intelligence Cryptography Internet Modification Security of data
  • 相关文献

参考文献6

  • 1Harkings, D., Carrel, D. The Internet key exchange (IKE). RFC 2409, 1998.
  • 2Zhou, Jian-ying. Fixing of security flaw in IKE protocols. Electronics Letters, 1999,35(13):1072~1073.
  • 3Maughan, D., Schertler, M., Schneider, M., et al. Internet Security Association and key management protocol (ISAKMP). RFC 2408, 1998.
  • 4Orman, H. The Oakley key determination protocols. RFC2412, 1998.
  • 5Krawczyk, H. SKEME: a versatile secure key exchange mechanism for Internet. In: IEEE ed. Proceedings of the 1996 Symposium on Network and Distributed System Security (SNDSS'96). 1996.
  • 6Burrows, M., Abadi, M., Needham, R. A logic of authentication. ACM Transactions on Computer Systems, 1990,8(1):18~36.

同被引文献7

  • 1柴晓路.为什么需要Web服务[J].IBM developerWorks专刊,2003,.
  • 2King S. CLSSP,threat and Solutions to Web Services Security.Network Security,2003,9:8~11.
  • 3Wahlin D. XML for ASP.NET Developers.SAMS,2001.
  • 4柴晓路.SOAP Header扩展:WS-Routing和WS-Referral,IBM Corporation,2001.http:∥www-900.ibm.com/developerWorks/cn/webservices/ws-soapheadext/part2/index.shtml.
  • 5Harking D,Carrel D.The Internet key exchange(IKE)[S/OL].RFC2049,IETF,1998,11.http://www.ietf.org/rfc/rfc2049.txt.
  • 6William S.密码编码学与网络安全-原理与实践[M].3版.北京:电子工业出版社,2004:373-380.
  • 7刘怡文,李伟琴.密码协议的分层安全需求及验证[J].北京航空航天大学学报,2002,28(5):589-592. 被引量:5

引证文献2

二级引证文献5

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部