摘要
云计算的兴起不可避免地带来了一些安全问题,服务资源的非授权访问就是其中的一个重要威胁。对此,基于IPv6地址的新特性,提出一种协同地址碰撞技术,即待认证节点通过多个协同节点的配合,向关键主机所在网络发送在IP地址接口标识部分隐含认证秘密的数据包,以实现对节点的隐蔽认证。理论和实验分析结果表明,该方案可有效提高网络的安全性。
With the development of cloud computing, it is inevitable that many security problems arise. Unauthorized service access is one of the most important threats. Based on the new features of IPv6 address, we proposed a new net- work security technique called cooperative address knocking, which can be seen as an undeteetable authentication. It is a form of host-to-host communication which relies on deliberate communication attempts from some cooperative nodes. These connection attempts are monitored by a daemon which interprets the interface identifier of destination IP addres- ses as information. The theoretical and empirical analysis demonstrate that CAKCA scheme can effectively conduct un- detectable authentication and prevent the exposure of existence of the important host. The theoretical analysis and simu- lation results show that the proposed scheme can effectively improve the level of network security.
出处
《计算机科学》
CSCD
北大核心
2016年第9期175-179,共5页
Computer Science
关键词
云计算
IPV6
地址碰撞
通信认证
Cloud computing, IPv6, Address knocking, Communication authentication