摘要
JFK(just fast keying)协议是一种新型的Internet密钥交换协议,具有高效、安全和较好的防DoS(denial of services)攻击的特点。但是JFK协议也有自身的缺陷,比如没有实现PFS(perfect forward secrecy)。对JFK协议进行了详细的分析,通过增加循环DH队列、改变消息的内容和改进消息处理方式的方法对JFK协议进行了改进,改进后的JFK协议在不牺牲效率的情况下实现了PFS,并且具有更好的防DoS攻击和重放攻击的能力。
JFK protocol is a new type of Internet key exchange protocol, it is efficient, secure and DoS-resistant. But JFK protocol has its own defectiveness, for example, JFK compromises on PFS. JFK protocol is analyzed, the JFK protocol is improved via adding circular DH queue, changing messages' content and improving the method of managing messages. After improvement, JFK protocol achieve PFS without losing efficiency, and has better capability in defense DoS attack and replay attack.
出处
《计算机工程与设计》
CSCD
北大核心
2006年第13期2446-2448,2475,共4页
Computer Engineering and Design