首页 | 官方网站   微博 | 高级检索  
     

通用可组合安全的Internet密钥交换协议
引用本文:彭清泉,裴庆祺,杨超,马建峰.通用可组合安全的Internet密钥交换协议[J].西安电子科技大学学报,2009,36(4):714-720.
作者姓名:彭清泉  裴庆祺  杨超  马建峰
作者单位:(西安电子科技大学 计算机网络与信息安全教育部重点实验室,陕西 西安710071)
基金项目:国家自然科学基金资助 
摘    要:通过对新一代Internet密钥交换协议(IKEv2)进行分析,指出了其初始交换过程中存在发起者身份暴露和认证失败问题.而在无线接入网络环境下,对发起者身份等敏感信息进行主动保护是十分必要的.提出了一种适用于无线网络环境下的Internet密钥交换协议,该协议让响应者显式地证明自己的真实身份,实现了对发起者主动身份保护.并通过重新构造认证载荷,有效防止了认证失败问题.在通用可组合安全模型下,证明了该协议达到了通用可组合安全.性能分析和仿真实验表明,该协议具有较少的计算量和通信量.

关 键 词:Internet协议安全  密钥交换  Internet密钥交换协议  可证安全  通用可组合  
收稿时间:2008-11-21

Universally composable secure Internet key exchange protocol
PENG Qing-quan,PEI Qing-qi,YANG Chao,MA Jian-feng.Universally composable secure Internet key exchange protocol[J].Journal of Xidian University,2009,36(4):714-720.
Authors:PENG Qing-quan  PEI Qing-qi  YANG Chao  MA Jian-feng
Affiliation:(Ministry of Education Key Lab. of Computer Network and Information Security, Xidian Univ., Xi'an  710071, China)
Abstract:The new Internet key exchange protocol (IKEv2) is analyzed, and it is found that the protocol can not achieve active identity protection to the initiator and has the security flaw of authentication failure in its initial exchange. However, it is necessary to protect the identity information to the initiator under the environment of a wireless access network. In this paper, a novel key exchange protocol for the wireless network based on IKEv2 initial exchange is proposed, which realizes active identity protection to the initiator by the responder explicitly proving his true identity, and achieves successful authentication by reconstructing the authentication payload. With the Universally Composable (UC) security model, this new protocol is analyzed in detail, with the analytical results showing that it affords provably UC security. Performance analysis and simulation results show that the proposed protocol has less computation and communication overhead.
Keywords:Internet protocol security  key exchange  Internet key exchange protocol  provably secure  universally composable  
本文献已被 万方数据 等数据库收录!
点击此处可从《西安电子科技大学学报》浏览原始摘要信息
点击此处可从《西安电子科技大学学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号