期刊文献+

IEEE 802.1X的安全性分析及改进 被引量:7

Security analysis and improvement of IEEE 802.1X
下载PDF
导出
摘要 IEEE 802.1X标准存在一些设计缺陷,为消除拒绝服务攻击(DoS)、重放攻击、会话劫持、中间人攻击等安全威胁,从状态机运行角度对协议进行了分析,指出产生这些问题的根源在于协议状态机的不平等和不完备,缺乏对消息完整性和源真实性的保护。提出并实现了一种双向挑战握手及下线验证的改进方案,并用一种改进的BAN逻辑对其进行了形式化分析。经验证,该方案能有效抵御上述安全威胁。 It has been proved in many researches that there are some design flaws in IEEE 802.1X standard.In order to eliminate the Denial of Service(DoS) attack,replay attack,session hijack,Man-In-the-Middle(MIM) attack and other security threats,the protocol was analyzed in view of the state machines.It is pointed out that the origin of these problems is the inequality and incompleteness of state machines as well as the lack of integrity protection and source authenticity on messages.However,an improvement proposal called Dual-way Challenge Handshake and Logoff Authentication was proposed,and a formal analysis was done on it with an improved BAN logic.It is proved that the proposal can effectively resist the security threats mentioned above.
出处 《计算机应用》 CSCD 北大核心 2011年第5期1265-1270,共6页 journal of Computer Applications
关键词 网络访问控制 IEEE 802.1X标准 可扩展认证协议 状态机 形式化分析 BAN逻辑 Network Access Control(NAC) IEEE 802.1X standard Extensible Authentication Protocol(EAP) state machine formal analysis BAN logic
  • 相关文献

参考文献10

二级参考文献20

  • 1IEEE Std. 802.11i/D2.0. Specification for Enhanced Security[S]. 2002-03. 被引量:1
  • 2IEEE Std. 802.1X. IEEE Standard for Local and Metropolitan Area Network Port Based Network Access Control[S]. 2001. 被引量:1
  • 3Blunk L, Vollbrecht J. PPP Extensible Authentication Protocol[S]. RFC 2284, 1998-03. 被引量:1
  • 4Aboba B, Simon D. PPP EAP TLS Authentication Protocol[S]. RFC 2716, 1998-10. 被引量:1
  • 5Wang Xiaoyun, Yu Hongbo. How to Break MD5 and Other Hash Function[C]//Proc. of Advances in EUROCRYPT'05. Santa Barbara, USA: [s. n.], 2005. 被引量:1
  • 6BRAWN S K,KOA R M,CAYE K.Secure in an insecure world:802.1X secure wireless computer connectivity for students,faculty,and staff to the camp-us network[C] // Proceedings of the 32nd Annual ACM SIGUCCS Conference on User Services.New York,USA,ACM,2004:273-277. 被引量:1
  • 7CROW B P,WIDJAJA I,KIM J G,et al.IEEE 802.11 wireless local area networks[J].IEEE Communications Magazine,1997,35(9).116-126. 被引量:1
  • 8JEFFREET,CONGDON P,SALA D,et al.P802.1X/D11-2001 IEEE standard for local and metropolitan area networks:standard for portbase network access control[S].Piscataway,NJ,USA:IEEE,2001. 被引量:1
  • 9ABOBA B,BLUNK L,VOLLBRECHT J,et al.RFC 3748-2004 Extensible authentication protocol (EAP)[S].Piscataway,NJ,USA:IETF,2004. 被引量:1
  • 10MISHRA A,ARBAUGH W A.An initial security analysis of the IEEE 802.1X standard[R].Maryland,USA; University of Maryland.Department of Computer Science,2002. 被引量:1

共引文献25

同被引文献50

引证文献7

二级引证文献31

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部