作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2007, Vol. 33 ›› Issue (17): 153-155,. doi: 10.3969/j.issn.1000-3428.2007.17.052

• 安全技术 • 上一篇    下一篇

IKE协议的研究与改进

袁志勇1,2,熊惠林1,陈绵云2   

  1. (1. 武汉大学计算机学院,武汉430079;2. 华中科技大学控制科学与工程系,武汉430074)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2007-09-05 发布日期:2007-09-05

Research and Improvement of Internet Key Exchange Protocol

YUAN Zhi-yong1,2, XIONG Hui-lin1, CHEN Mian-yun2   

  1. (1. School of Computer, Wuhan University, Wuhan 430079; 2. Dept. of Control Science and Engineering, Huazhong University of Science and Technology, Wuhan 430074 )
  • Received:1900-01-01 Revised:1900-01-01 Online:2007-09-05 Published:2007-09-05

摘要: 分析并指出了因特网密钥交换协议的安全漏洞和设计缺陷,提出了一种安全高效的密钥交换协议。对比现有的几种密钥交换协议,改进的协议具有更好的安全性、抗DoS攻击能力、较少的密钥交换时间和消息数。

关键词: 因特网密钥交换, 安全联盟, 拒绝服务攻击, 阶段, 模式

Abstract: This paper gives an analysis of Internet key exchange (IKE) protocol and identifies its security holes and design weaknesses and proposes an efficient and improved secure key exchange protocol. Compared with existing key exchange protocol, the proposed protocol is more secure, robust to DoS attacks and has less key exchange time and messages.

Key words: Internet key exchange (IKE), security association(SA), denial of service attack, phase, mode

中图分类号: