作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2008, Vol. 34 ›› Issue (20): 187-189. doi: 10.3969/j.issn.1000-3428.2008.20.068

• 安全技术 • 上一篇    下一篇

一种改进的TCP连接迁移安全机制

洪小亮,郭义喜   

  1. (解放军信息工程大学电子技术学院,郑州 450004)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2008-10-20 发布日期:2008-10-20

Improved TCP Connection Migratory Secure Mechanism

HONG Xiao-liang, GUO Yi-xi   

  1. (Institute of Electronic Technology, PLA Information Engineering University, Zhengzhou 450004)
  • Received:1900-01-01 Revised:1900-01-01 Online:2008-10-20 Published:2008-10-20

摘要: TCP连接迁移技术使网络可以在主服务器发生故障的情况下稳定地提供服务。该文分析基于椭圆曲线Diffie-Hellman密钥协商的连接迁移安全机制中存在的中间人攻击问题,利用改进的Helsinki协议进行连接密钥的协商,提出一种新的安全机制。该机制有效地保证了迁移选项的安全,利用安全哈希算法的抗碰撞性和安全性使攻击者难以猜测出连接标志和请求。

关键词: TCP连接迁移, 迁移选项, Helsinki协议, 安全性

Abstract: The service can be provided steadily when primary server goes wrong by using TCP connection migratory technology. This paper analyzes the problem of man-in-the-middle attack existing in secure mechanism of the connection migratory based on ellipse curve Diffie-Hellman key negotiation. With the improved Helsinki protocol which is applied to negotiate the connection key, a novel secure mechanism is presented. This mechanism can protect the migratory options effectively. The function of resisting collision and the security of hash-algorithm make it hard for attackers to guess the connection symbol and request.

Key words: TCP connection migratory, migrate options, Helsinki protocol, security

中图分类号: