作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2012, Vol. 38 ›› Issue (15): 114-118. doi: 10.3969/j.issn.1000-3428.2012.15.033

• 安全技术 • 上一篇    下一篇

移动节点间安全关联管理方案设计

孙 凌1,田 源1,邢洪智2   

  1. (1. 河南商业高等专科学校计算机应用系,郑州 450044;2. 解放军信息工程大学电子技术学院,郑州 450004)
  • 收稿日期:2011-09-14 出版日期:2012-08-05 发布日期:2012-08-05
  • 作者简介:孙 凌(1976-),女,副教授、硕士、CCF会员,主研方向:无线网络安全;田 源、邢洪智,硕士
  • 基金资助:
    现代通信国家重点实验室基金资助项目(9140C110702090);河南省高等学校青年骨干教师资助计划基金资助项目

Design of Security Association Management Scheme Between Mobile Nodes

SUN Ling 1, TIAN Yuan 1, XING Hong-zhi 2   

  1. (1. Department of Computer Application, Henan Business College, Zhengzhou 450044, China; 2. Institute of Electronic Technology, PLA Information Engineering University, Zhengzhou 450004, China)
  • Received:2011-09-14 Online:2012-08-05 Published:2012-08-05

摘要: 在IETF的IKEv2方案中,离线移动后的安全关联(SA)更新过程中可能存在无法通信的情况,而MOBIKE方案的SA更新效率低,且无法抵御恶意反射攻击。为此,通过改进SA的建立过程,减少移动节点的SA重协商次数,采取安全关联与移动节点家乡地址相关联的方法,提出一种安全管理方案。分析结果表明,与MOBIKE方案相比,该方案可以在离线移动情况下确保安全关联的更新,并具有更高的切换效率和安全性。

关键词: 安全关联, IKEv2方案, 安全关联数据库, 家乡地址, 切换, 绑定更新

Abstract: There are disconnection problems in Internet Key Exchange version2(IKEv2) scheme of IETF standards when nodes changing IP address during Security Association(SA) update. Mobile IKE(MOBIKE) has low efficiency and is unable to resist malicious reflection attack during SA update. So this paper presents a new management scheme by improving the creation of SA, decreasing renegotiation processing on mobile nodes SA, creating relativity between security association and mobile node’s home address. Analysis result shows that the new scheme guarantees the SA update when mobile nodes changing address off-line and behaves better in efficiency and security compared with MOBIKE.

Key words: Security Association(SA), Internet Key Exchange version2(IKEv2) scheme, Security Association Database(SAD), home address, handover, Binding Update(BU)

中图分类号: