摘要
为解决数据分发服务安全规范中身份认证与密钥协商协议存在共享密钥建立缺乏公平性、缺乏验证密钥一致性机制及会话过程缺乏完整性等安全问题,以协议为基础,设计一种新的高安全数据分发服务身份认证与密钥协商协议。新协议引入了ACK机制,并利用D-H密钥交换和非对称密码体制特点解决了原协议存在的安全问题,具备实用性和更高的安全性。
Authentication and shared secret establishment protocol of Data Distribution Service Security Specification has some security problems,such as lack of fairness in shared secret establishment,lack of mechanism to validate the consistency of secret key,and lack of integrity in the whole session. Based on this protocol,we design a new protocol named authentication protocol for high- security data distribution service. The new protocol introduces ACK mechanism,which solves above problems by using the new mechanism and features of D- H key exchange and asymmetric cryptography,and it' s a more secure and practical protocol.
出处
《航空计算技术》
2015年第1期103-107,共5页
Aeronautical Computing Technique
基金
中航工业技术创新基金项目资助(2013D63125R)
关键词
数据分发服务
协议安全性
身份认证
密钥协商
D-H密钥交换
data distribution service
security of protocol
authentication
shared secret establishment
D-H key exchange