节点文献
基于802.1x的认证技术在校园网中的应用
Application of Authentication Technology Based on 802.1x in Campus Network
【摘要】 IEEE802.1x是基于端口的访问控制协议,802.1x的体系结构由申请者系统(SupplicantSystem)、认证者系统(AuthenticatorSystem)、认证服务器(AuthenticationServer)三部分组成,采用"可控端口"和"不可控端口"的逻辑功能,实现了认证与业务的分离,保证了网络传输的效率。结合本校校园网的实际情况,提出了在校园网改造中使用802.1x作为接入认证协议的网络拓扑方案。针对校园网中未授权用户盗用校园网资源的现象,分析了合法用户私自设置代理服务器或提供NAT服务的代理行为。根据代理服务器和NAT的工作原理提出了检测用户代理行为的途径,设计和实现了能够检测用户代理行为的802.1x客户端程序。
【Abstract】 IEEE 802.1x is a control protocol of port-based network access. The 802.1x architecture consists of supplicant system, authenticator system and authentication server. It uses "controlled port" and "uncontrolled port" logic function to realize authentication and business data stream and ensure the efficiency of network transfer. According to situation of our campus network, 802.1x network topology scheme is presented. In the campus network, resource stealing is a serious phenomenon. An authenticated user can offer proxy service by privately opening proxy server or offer NAT service. Based on the principle of the proxy server and NAT, the author designs and implements the 802.1x client application which can detect users’ proxy actions.
- 【文献出处】 安徽理工大学学报(自然科学版) ,Journal of Anhui University of Science and Technology(Natural Science) , 编辑部邮箱 ,2005年01期
- 【分类号】TP393.08
- 【被引频次】9
- 【下载频次】138