计算机应用 ›› 2005, Vol. 25 ›› Issue (03): 563-564.DOI: 10.3724/SP.J.1087.2005.0563

• 信息安全 • 上一篇    下一篇

IKEv2协议安全性分析与改进

高翔,李亚敏,郭玉东,马红途   

  1. 信息工程大学信息工程学院
  • 发布日期:2005-03-01 出版日期:2005-03-01

Security analysis and improvements of IKEv2 protocol

GAO Xiang,LI Ya-min,GUO Yu-dong,MA Hong-tu   

  1. ollege of Information Engineering, Information Engineering University
  • Online:2005-03-01 Published:2005-03-01

摘要: 简单介绍了新一版密钥交换协议草案IKEv2,对IKEv2密钥协商机制的安全性进行分析。通过分析,发现其EAP交换过程繁琐且身份信息不易隐藏;证书验证中可能受到假冒证书攻击;为避免安全隧道非授权访问而需要重新认证等几处安全问题。针对这几处安全问题提出了改进建议和解决方法。

关键词: IKEv2, EAP, 认证

Abstract: IETF put forward a new version of IKE, IKEv2.Different from the old IKE,IKEv2 combines and redefines key exchange process. This paper introduced IKEv2, and analysed the security of key negotiation mechanism of IKEv2.Aiming at some security problems in EAP exchange, such as authentication with digital certificate and reauthentication to avoid accessing VPN tunnel with unauthorized identity, some improvement advice and solutions were given.

Key words: IKEv2, EAP, authentication

中图分类号: