首页 | 本学科首页   官方微博 | 高级检索  
     

用密钥封装机制实现IPSec密钥建立
引用本文:刘湘疆,张世武.用密钥封装机制实现IPSec密钥建立[J].计算机工程与设计,2008,29(4):816-817,881.
作者姓名:刘湘疆  张世武
作者单位:解放军外国语学院军事情报系,河南,洛阳,471003
摘    要:出在网络层的安全协议IPSec中引入密钥封装机制(KEM),通过密钥传输实现IPSec密钥建立.在目前基于密钥交换的IKEv2协议之外,提供了另一种密钥建立的方法.对所给协议的分析表明,在同样需要交换证书进行消息认证的情况下,KEM密钥传输协议与IKEv2协议同样安全,并且更加有效.

关 键 词:Internet密钥交换协议  密钥封装机制  密钥传输  密钥交换  证书
文章编号:1000-7024(2008)04-0816-02
收稿时间:2007-03-12
修稿时间:2007年3月12日

Key establishment in IPSec protocol through key encapsulation mechanism
LIU Xiang-jiang,ZHANG Shi-wu.Key establishment in IPSec protocol through key encapsulation mechanism[J].Computer Engineering and Design,2008,29(4):816-817,881.
Authors:LIU Xiang-jiang  ZHANG Shi-wu
Abstract:A key transport protocol through key encapsulation mechanism (KEM) is presented for key establishment in IPSec,the security protocol in IP layer.Unlike the current IKEv2 protocol based on key exchange,the new protocol provides another way to establish shared secret between two IPSec users.The analysis of the proposed protocol shows that in the same circumstance that the two users have to exchange certificates to authenticate messages,the KEM key transport protocol is as secure as the IKEv2 protocol and more efficient than it.
Keywords:IKEv2  KEM  key transport  key exchange  certificate
本文献已被 CNKI 维普 万方数据 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号