节点文献

无线局域网AP中嵌入802.1x的研究

Study on the Integrating 802.1x to WLAN AP

【作者】 彭伟

【导师】 王能;

【作者基本信息】 华东师范大学 , 计算机应用技术, 2004, 硕士

【摘要】 基于802.11标准的无线局域网,其典型AP结构中的安全性主要有共享密钥认证、SSID(Service Set Identifier)认证、MAC地址认证和一个被称为WEP(Wired Equivalent Privacy)的安全协议来保证。但这些认证方法和WEP协议存在巨大的安全漏洞,无法保证无线网络的安全。 802.1x是基于端口进行网络访问控制的安全性标准,它提供了一种安全结构框架,通过使用各种认证方法和加密机制可以保障网络的安全。为了克服802.11的安全缺陷,802.11引入了802.1x协议。 本文分析了原有系统在安全上的不足,研究了在无线局域网AP中引入802.1x协议的方法和结构,包括802.1x相关层次的功能、为实现这些功能需要定义的主要数据结构和主要函数。在此基础上,进行了嵌入802.1x的AP结构在HostAP环境下的模拟实现,并对该实现的MAC层的报文进行了抓取,说明嵌入802.1x的AP是如何确保数据通信的安全的。

【Abstract】 The wireless LAN based on 802.11 standard has its typical safety in AP structure :shared key authentication, SSID, MAC address authentication and a safety protocol called WEP. However, those above-mentioned authentication methods and wep protocoal exist grave safety loophole,and the safety of the wireless network can not be guaranteed.802.1x, a safety port-based network access control standard ,provides a safety framework, and ensures the safety of the network through various authentication methods and encryption mechanisms ?To overcome the safety drawbacks of 802.11, 802.1 x is introduced.The thesis analyses the weak points in the aspects of the safety in the pevious system, and studies the methods and the structure of introducing 802.1x in the AP of the wireless LAN, including the function of the related aspects of 802.1x, the data structures and functions needed to be defined to fulfill those functions. The thesis also put stress on simulated fulfillment of the AP architecture embedded with 802.1x against the HostAP background and the capture of messages on the MAC level, so as to show how AP architecture embedded with 802.1x guarantees the safety of data communication in the wireless environment.

【关键词】 无线局域网802.11端口802.1x扩展认证协议EAPOLRadiusEAP-TLSEAP-MD5认证
【Key words】 WLAN802.11Port802.1xEAPEAPOLRadiusEAP-TLSEAP-MD5Authentication
  • 【分类号】TP393.08
  • 【被引频次】3
  • 【下载频次】283
节点文献中: