首页 | 本学科首页   官方微博 | 高级检索  
     

IPSec协议的远程证明扩展
引用本文:王剑,汪海航,杨健. IPSec协议的远程证明扩展[J]. 计算机科学, 2011, 38(6): 49-53
作者姓名:王剑  汪海航  杨健
作者单位:1. 同济大学电子与信息工程学院,上海,201804;河南科技大学电子与信息工程学院,洛阳,471003
2. 同济大学电子与信息工程学院,上海,201804
3. 同济大学电子与信息工程学院,上海,201804;大理学院数学与计算机学院,大理,671003
基金项目:本文受国家863计划项目(2006AA01Z438)资助。
摘    要:传统IPScc协议在建立安全通信连接时,没有考虑终端自身安全问题,而可信计算的远程证明机制就是为被接入方提供接入方的自身安全证明,将其引入IPSec协议可以弥补建立IPSe。连接时的终端安全漏洞。首先分析了IPScc协议的IKE协商过程和可信计算技术的远程证明机制,然后以基于数字签名的IKE主模式流程为例,提出在IKE协商阶段引入远程证明机制的IPScc远程证明扩展协议流程及安全分析。该协议引入带有SKAE扩展项的身份证书,实现对终端身份和系统完整性的双重认证,确保端到端的安全连接。协议在保证通信信息的机密性、完整性、新鲜性之外,也充分保护终端平台隐私性。

关 键 词:PSec   IKE协商  远程证明  可信计算  完整性度量

Remote Attestation Extension for IPSec
WANG Jian,WANG Hai-hang,YANG Jian. Remote Attestation Extension for IPSec[J]. Computer Science, 2011, 38(6): 49-53
Authors:WANG Jian  WANG Hai-hang  YANG Jian
Affiliation:(School of Electronics and Information,Tongji University,Shanghai 201804,China)(School of Electronics and Information Engineering,Henan University of Science and "Technology,Luoyang 471003,China)(School of Mathematics and Computer Sscience,Dali University,Dali 671003,China)
Abstract:Standard IPSec doesn't provide any guarantees about the integrity of the endpoints when an IPSec linkage is established. And the remote attestation in trusted computing is to provide security evidence of the user for the accessed server. So it can avoid terminal security vulnerability in IPSec to introduce the remote attestation into IPSec. IKE negotianon of IPSec and remote attestation mechanism were analyzed firstly. Then taking IKE main mode based on figure signature for example, an extended IPSec protocol based on remote attestation and its security analysis were presented. In the extended IPSec protocol,remote attestation mechanism was introduced into IKE negotiation. hhis protocol can complete double authentications including identity and system integrity by using a certificate with a SKAE extension to ensure an end-to-end secure linkage. Besides, the protocol can guarantee not only information' s confidentiality, integrity and freshness,but also endpoints' privacy.
Keywords:IPSec   IKE negotiation   Remote attestation   Trusted computing   Integrity measurement
本文献已被 万方数据 等数据库收录!
点击此处可从《计算机科学》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号