Author Login Editor-in-Chief Peer Review Editor Work Office Work

Computer Engineering ›› 2007, Vol. 33 ›› Issue (17): 153-155,. doi: 10.3969/j.issn.1000-3428.2007.17.052

• Security Technology • Previous Articles     Next Articles

Research and Improvement of Internet Key Exchange Protocol

YUAN Zhi-yong1,2, XIONG Hui-lin1, CHEN Mian-yun2   

  1. (1. School of Computer, Wuhan University, Wuhan 430079; 2. Dept. of Control Science and Engineering, Huazhong University of Science and Technology, Wuhan 430074 )
  • Received:1900-01-01 Revised:1900-01-01 Online:2007-09-05 Published:2007-09-05

IKE协议的研究与改进

袁志勇1,2,熊惠林1,陈绵云2   

  1. (1. 武汉大学计算机学院,武汉430079;2. 华中科技大学控制科学与工程系,武汉430074)

Abstract: This paper gives an analysis of Internet key exchange (IKE) protocol and identifies its security holes and design weaknesses and proposes an efficient and improved secure key exchange protocol. Compared with existing key exchange protocol, the proposed protocol is more secure, robust to DoS attacks and has less key exchange time and messages.

Key words: Internet key exchange (IKE), security association(SA), denial of service attack, phase, mode

摘要: 分析并指出了因特网密钥交换协议的安全漏洞和设计缺陷,提出了一种安全高效的密钥交换协议。对比现有的几种密钥交换协议,改进的协议具有更好的安全性、抗DoS攻击能力、较少的密钥交换时间和消息数。

关键词: 因特网密钥交换, 安全联盟, 拒绝服务攻击, 阶段, 模式

CLC Number: