摘要
IKE协议作为IPsec协议簇中的重要组成部分,引起了广泛的关注和研究。本文在研究已有IKE协议的基础上,将公钥基础设施PKI体系引入其中,并在PKI现有RSA算法外应用高强度的椭圆曲线密码ECC算法,提出将ECC、PKI同IKE协议相结合,设计了一个基于PKI身份认证的高安全强度IKE协议,从而提高了VPN网关的安全性和可扩展性,有效保护了VPN网络资源的安全。最后提出了实现方案。
Internet key exchange (IKE) protocol is a key component of the IP security suite, which draws great attentions and investigations. The current IKE protocol is researched, and the public key infrastructure is introduced, which is applied with high-tensile elliptic curve cryptography besides existed RSA cryptography, and the techniques of ECC and PKI are combined with IKE, an high intensity IKE protocol based on PKI authentication is designed, to improve the security and extensibility of IPsec VPN gateway and to protect VPN network resources effectively. Finally, an implementation approach is given.
出处
《计算机工程与设计》
CSCD
北大核心
2006年第15期2767-2769,共3页
Computer Engineering and Design
基金
江苏省自然科学基金项目(BK2004039)