作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2006, Vol. 32 ›› Issue (16): 130-132. doi: 10.3969/j.issn.1000-3428.2006.16.049

• 安全技术 • 上一篇    下一篇

IKE协议的简化及安全性分析

陈华兴1;鲁士文2   

  1. 1. 中国科学院研究生院,北京100040;2. 中国科学院计算技术研究所,北京 100080
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2006-08-20 发布日期:2006-08-20

Simplification and Security Analysis of IKE Protocol

CHEN Huaxing1; LU Shiwen2   

  1. 1. Graduate School, Chinese Academy of Sciences, Beijing 100040; 2. Institute of Computing Technology, Chinese Academy of Sciences, Beijing 100080)
  • Received:1900-01-01 Revised:1900-01-01 Online:2006-08-20 Published:2006-08-20

摘要: IKE协议的复杂性和安全性一直备受关注,文献[1]对IKE协议交换过程进行了简化,该文对简化后的IKE协议进行了安全性分析,并针对拒绝服务攻击DOS和中间人攻击的身份泄露,提出了改进建议。测试表明,该文提出的方法是可行的、有效的,大大降低了攻击的影响。

关键词: IPSec, IKE, 密钥交换, 安全性

Abstract: The complexity and security of IKE protocol is always paid close attention by many researchers. Reference[1] simplifies the exchange of IKE. This paper discusses the security properties of the simplified IKE and presents some suggestions to solve the problems of denial of service attack and identification leak for man-in-the-middle attack. It is proved that the design is available and feasible. It reduces the influence of attack.

Key words: IPSec, Internet Key Exchange (IKE), Key exchange, Security