期刊文献+

基于ZooKeeper的全网统一信任锚模型研究 被引量:3

Research on unified trust anchor model based on ZooKeeper
下载PDF
导出
摘要 由于现有的TCP/IP没有对地址、身份等信息进行认证,造成源地址欺骗、路由劫持等大量攻击的发生,严重威胁到网络安全。而现有基于PKI体系的CA认证机构的管理效率低、没有统一性,不适合在全网统一范围进行认证。为了能够高效地管理、认证和存储公钥信息,建立全网统一的网络层可信身份认证与管理机制,提出了基于ZooKeeper的全网统一信任锚模型。该模型利用ZooKeeper的负载均衡、数据一致性等优点,采用分布式架构来共同管理信任锚,以一种全网统一的ID标志信息来解决身份与地址真实性鉴别问题,实现网络的平等互联、安全可信。 Because of the existing TCP/IP protocol does not authenticate the address and identity,a large number of attacks such as source address spoofing and route hijacking occur,which seriously threaten the security of the network.And the CA based on the PKI system has low management efficiency and no uniformity,and is not suitable for authentication in the entire network.In order to efficiently manage the storage of public key information and establish a network-wide trusted identity authentication and management mechanism,this paper proposed a unified trust anchor model based on ZooKeeper.This model utilized ZooKeeper load balancing,high availability and other advantages to jointly manage the trust anchor,solved the identity and address authenticity identification problem with a unified ID identification information of the entire network,and achieved equal network interconnection,security and credibility.
作者 史博轩 章峰 蒋文保 Shi Boxuan;Zhang Feng;Jiang Wenbao(School of Information Management,Beijing Information Science&Technology University,Beijing 100192,China)
出处 《计算机应用研究》 CSCD 北大核心 2020年第12期3722-3725,共4页 Application Research of Computers
基金 网络空间安全学科创新平台建设资助项目(77F1910917) 国家重点研发计划资助项目(2018YFB1800100)。
关键词 信任锚 可信认证 信任链 ZooKeeper 分布式 trust anchor trusted authentication chain of trust ZooKeeper distributed
  • 相关文献

参考文献4

二级参考文献13

  • 1昝风彪,徐明伟,吴建平.主机标识协议(HIP)研究综述[J].小型微型计算机系统,2007,28(2):224-228. 被引量:18
  • 2GB/T20518-2006,信息安全技术公钥基础设施数字证书格式[s]. 被引量:4
  • 3Terence Spies. Public Key Infrastructure [ M ]// Vacca J R. Computer and Information Security Handbook. San Francisco: Morgan Kaufmann, 2009 : 433-451. 被引量:1
  • 4Hartini Saripan, Zaiton Hamin. The application of the digital signature law in securing internet banking: Some preliminary evidence from Malaysia [ J ]. Procedia Com- puter Science, 2011, 3 : 248-253. 被引量:1
  • 5ITU-T X. 509. Information Technology-Open Systems In- terconnection-The Directory: Public-Key and Attribute Certificate Frameworks [ M J. [ s. 1. ] : ITU-T Recom- mendation X. 509, 2000. 被引量:1
  • 6Barbara Miller. Electronic government, concepts, methodolo- gies, tools, and applications [ J ]. Government Informa- tion Quarterly, 2010, 27( 1 ) : 109-110. 被引量:1
  • 7Taekyoung Kwon. Privacy preservation with X. 509 stand- ard certificates [ J]. Information Sciences, 2011, 181 (13) : 2906-2921. 被引量:1
  • 8LD/T30-2009.人力资源和社会保障电子认证体系[S]. 被引量:1
  • 9吴建平,吴茜,徐恪.下一代互联网体系结构基础研究及探索[J].计算机学报,2008,31(9):1536-1548. 被引量:70
  • 10张宇,韩军,汪伦伟,张来顺.安全网络模型研究[J].计算机安全,2009(7):4-6. 被引量:1

共引文献39

同被引文献22

引证文献3

二级引证文献8

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部