作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2006, Vol. 32 ›› Issue (9): 139-140,143.

• 安全技术 • 上一篇    下一篇

IKE 中的安全性分析与改进

顾小卓,杨建祖,兰巨龙   

  1. 解放军信息工程大学信息工程学院,郑州 450002
  • 出版日期:2006-05-05 发布日期:2006-05-05

Analysis and Improvement of Security in IKE

GU Xiaozhuo, YANG Jianzu, LAN Julong   

  1. Institute of Information Engineering, PLA Information Engineering University, Zhengzhou 450002
  • Online:2006-05-05 Published:2006-05-05

摘要: 分析了IKE 中存在的两类安全问题:(1)响应者在未证实发起者IP 地址的情况下,需要保存双方的状态从而不能避免遭受存储资源耗尽攻击;在身份没有得到认证的情况下进行大量的运算,不能防止CPU 资源耗尽攻击。两方面结合起来使得IKE 不能有效地防止Dos攻击。(2)在签名认证和预共享认证的主模式和野蛮模式中,IKE 不能有效地保护通信双方的身份。该文的改进在一定程度上解决了这两类问题。

关键词: Cookie;Dos 攻击;身份认证;身份保护

Abstract: This paper analyzes two security problems existing in IKE. First, before verifying the IP address of initiator, responder needs to store state and before verifying the identity of the initiator, responder needs to operate expensive computation. These two defaults in IKE combines together lead to ineffectively protection against Dos attack. Second, in the main mode or in the aggressive mode authenticated with digital signatures or with pre-shared key, IKE can’t protect the identities of both correspond sides efficiently. The improvement solves these problems existing in IKE.

Key words: Cookie; Dos attack; Identity authentication; Identity protection