节点文献

一种改进的基于PKI/ECC的IKE协议设计

An Improved Design of IKE Protocol Based on PKI/ECC

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 杜春燕; 黄宪; 陆建德;

【Author】 DU Chun-yan, HUANG Xian, LU Jian-de (School of Computer, Soochow University, Suzhou 215006 China)

【机构】 苏州大学计算机学院; 苏州大学计算机学院 江苏苏州215006; 江苏苏州215006;

【摘要】 IKE协议是IPsec协议簇的重要组成部分,用来动态地建立和维护安全关联SA,是IPsecVPN安全传输的先决条件和保证。文章在研究现有IKE协议的基础上,将公钥基础设施PKI体系引入其中,提出将ECC技术、X.509数字证书、访问控制技术同IKE协议相结合,设计了一个基于PKI身份认证和访问控制的增强型IKE协议,从而提高了IPsecVPN网关的安全性和可扩展性,有效保护了VPN网络资源的安全。最后给出了基于最新Linux2.6内核的实现方案,并对由此构建的IPsecVPN安全网关原型系统的工作过程作了说明。

【Abstract】 Internet Key Exchange (IKE) is one of the important protocols in IPsec protocol suite. As used to dynamically establish and maintain security associations (SAs), IKE is the prerequisite and guarantee for secure communication with IPsec VPN. This paper has researched on current IKE protocol, and proposed to introduce the public key infrastructure and to combine the techniques of ECC, X.509 digital certificate and access control with IKE, so as to design an enhanced IKE protocol based on authentication and access control with PKI, improving the security and extensibility of IPsec VPN gateway and protecting VPN network resources effectively. In the end, the paper has given out an implementing scheme based on the latest Linux kernel 2.6 and some explanations for processing on this IPsec VPN security gateway prototype.

【关键词】 IKE; PKI; ECC; X.509证书;
【Key words】 IKE; PKI; ECC; X.509 certificate;
【基金】 江苏省自然科学基金项目(BK2004039)
  • 【文献出处】 微电子学与计算机 ,Microelectronics & Computer , 编辑部邮箱 ,2006年05期
  • 【分类号】TP393.08
  • 【被引频次】4
  • 【下载频次】87
节点文献中: 

本文链接的文献网络图示:

本文的引文网络