节点文献

支持可信认证的移动IPSec VPN系统设计

Design of trusted authentication-enabled mobile IPSec VPN system

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 王剑梁灵飞俞卫华

【Author】 WANG Jian,LIANG Ling-fei,YU Wei-hua(College of Electronic Information Engineering.Henan University of Science and Technology,Luoyang 471023,China)

【机构】 河南科技大学电子信息工程学院

【摘要】 基于IPSec协议的移动VPN系统为移动终端的远程接入提供了可行的解决方案,但IPSec协议的普通身份认证没有考虑移动终端系统的完整性和可信性,造成终端安全漏洞,给被接入系统和被访问信息带来安全隐患。针对这个问题,提出支持可信认证的移动IPSec VPN系统,并给出其系统架构和关键技术。该系统在实现了普通IPSec VPN系统的安全功能之外,增加了多因子与可信证明相结合的复合认证功能、基于信任的动态访问控制功能。并对其进行了原型实现和性能测试及分析,表明了在将时间代价合理控制的前提下,该系统有效确保了终端的可信接入、通信信道中数据传输的安全可靠以及被接入网络的资源安全及应用服务的可用性和可管控性。

【Abstract】 The mobile VPN based on IPSec is a practical scheme for mobile terminals to access remote information systems.However,the identity authentication of IPSec does not consider the integrity and creditability of the mobile terminals.It leads to the terminal security leakage and brings potential dangers to the accessed system and information.To this problem,a mobile IPSec VPN system supporting trusted authentication is presented with its configuration and key design issues.The system implements not only the security functions of common IPSec VPNs,but also following functions as multi-factor authentication with trusted attestation,dynamic access control based on trust value,etc.Then,the implementation of a prototype as well as its performance test and analysis is presented to prove it can ensure terminal’s trusted access,data secure transmission,and accessed network resources/services availability and manageability.

【基金】 国家自然科学基金项目(61003234);河南省高等学校科技创新人才计划基金项目(2011HASTIT015);河南省科技创新人才计划基金项目(134100510011)
  • 【文献出处】 计算机工程与设计 ,Computer Engineering and Design , 编辑部邮箱 ,2013年07期
  • 【分类号】TP393.08
  • 【被引频次】7
  • 【下载频次】173
节点文献中: 

本文链接的文献网络图示:

本文的引文网络