| 摘要: |
| IKE(Internet key exchange,RFC2409)提供了一组Internet密钥交换协议,目的是在IPSec(IP security)通信双方之间建立安全联盟和经过认证的密钥材料.随后有学者发现IKE协议存在一个安全缺陷,并给出相应的修改建议.指出了修改后的IKE协议仍然存在类似的安全缺陷,并描述了一个成功的攻击.在给出修改建议的同时,成功地利用BAN逻辑分析了导致这两个安全缺陷的原因. |
| 关键词: Internet密钥交换协议 安全联盟 认证 主模式 认证者 |
| DOI: |
| 分类号: |
| 基金项目: |
|
| Analyzing the Security Flaws of Internet Key Exchange Protocols |
|
ZHANG Yong,FENG Dong-lei,CHEN Han-sheng,BAI Ying-cai
|
| Abstract: |
| IKE (Internet key exchange, RFC2409) describes a suite of Internet key exchange protocols for establishing security associations and obtaining authenticated keying material. A security flaw in these IKE protocols is observed and a simple modification is proposed. In this paper, it is pointed out that there is a neglected security flaw in the amended IKE protocols. And a successful attack on the amended IKE protocols is also provided. A new amendment to IKE protocols is proposed, and the reasons which cause the two security flaws are analyzed by using BAN logic successfully. |
| Key words: Internet key exchange protocols security association authenticate main mode authenticators |