摘要
针对IKEv2协议在系统开销和发起方身份保护方面的不足,提出了一种改进协议的方案。新的协议采用基于超椭圆曲线的W eil对技术进行数字签名认证,并且首先认证响应方身份。通过该方案,改进后的协议降低了系统开销,实现了对发起方身份的主动保护。最后,基于应用pi演算的方法对协议进行了建模,并定义和分析了协议的安全属性。结果表明,改进后的协议具有更好的安全性和实用性。
IKEv2 protocol had some flaw in protecting initiator' s identity and system requirement, so this paper presented an improved protocol. In the new protocol, used Weil pairing technology, based on hyperelliptic curves, in digital signature authentication, and first authenticated the responder. By those means, the protocol had reduced the system cost and actively protected the initiator' s identity. At last, formally analyzed the improved protocol' s security property based on applied pi calculus. Analysis result shows that the protocol has a better performance in secure and application.
出处
《计算机应用研究》
CSCD
北大核心
2010年第2期707-711,共5页
Application Research of Computers
基金
国家"863"计划资助项目(2007AA01Z472)