计算机应用 ›› 2011, Vol. 31 ›› Issue (05): 1265-1270.DOI: 10.3724/SP.J.1087.2011.01265

• 信息安全 • 上一篇    下一篇

IEEE 802.1X的安全性分析及改进

周超1,周城2,郭亮1   

  1. 1.重庆通信学院 研究生管理大队,重庆400035
    2.重庆通信学院 机动作战通信系,重庆400035
  • 收稿日期:2010-11-10 修回日期:2011-01-17 发布日期:2011-05-01 出版日期:2011-05-01
  • 通讯作者: 周超
  • 作者简介:周超(1984-),男,湖南望城人,硕士研究生,主要研究方向:军事信息安全;周城(1963-),男,江苏无锡人,副教授,主要研究方向:信息安全;郭亮(1984-),男,湖南湘潭人,硕士研究生,主要研究方向:信号设计与编码。

Security analysis and improvement of IEEE 802.1X

ZHOU Chao1, ZHOU Cheng2, GUO Liang1   

  1. 1. Graduate School, Chongqing Communication Institute, Chongqing 400035, China
    2. Department of Maneuvering Fighting Communication, Chongqing Communication Institute, Chongqing 400035, China
  • Received:2010-11-10 Revised:2011-01-17 Online:2011-05-01 Published:2011-05-01
  • Contact: Chao ZHOU

摘要: IEEE 802.1X标准存在一些设计缺陷,为消除拒绝服务攻击(DoS)、重放攻击、会话劫持、中间人攻击等安全威胁,从状态机运行角度对协议进行了分析,指出产生这些问题的根源在于协议状态机的不平等和不完备,缺乏对消息完整性和源真实性的保护。提出并实现了一种双向挑战握手及下线验证的改进方案,并用一种改进的BAN逻辑对其进行了形式化分析。经验证,该方案能有效抵御上述安全威胁。

关键词: 网络访问控制, IEEE 802.1X标准, 可扩展认证协议, 状态机, 形式化分析, BAN逻辑

Abstract: It has been proved in many researches that there are some design flaws in IEEE 802.1X standard. In order to eliminate the Denial of Service (DoS) attack, replay attack, session hijack, Man-In-the-Middle (MIM) attack and other security threats, the protocol was analyzed in view of the state machines. It is pointed out that the origin of these problems is the inequality and incompleteness of state machines as well as the lack of integrity protection and source authenticity on messages. However, an improvement proposal called Dual-way Challenge Handshake and Logoff Authentication was proposed, and a formal analysis was done on it with an improved BAN logic. It is proved that the proposal can effectively resist the security threats mentioned above.

Key words: Network Access Control (NAC), IEEE 802.1X standard, Extensible Authentication Protocol (EAP), state machine, formal analysis, BAN logic

中图分类号: