| 摘要: |
| 为了解决深化“互联网+先进制造业”进程中网络可信互连问题,引入了可信连接架构(trusted connect architecture,简称TCA)技术.基于TCA技术思想,针对网络间可信认证需求,设计了一种支持网络间互连的可信连接协议(TCA-SNI).引入了网络间双向认证过程,给出了TCA-SNI协议的交互过程;使用扩展的SVO逻辑系统对协议进行逻辑推理,证明该协议是安全可靠的;使用Dolev-Yao攻击者模型对协议进行攻击测试,实验结果表明,协议的安全目标均已达成,证明该协议可以抵御真实网络中的攻击. |
| 关键词: 可信连接架构 可信计算 可信连接协议 SVO AVISPA |
| DOI:10.13328/j.cnki.jos.005603 |
| 分类号:TP393 |
| 基金项目:青海省自然科学基金(2017-ZJ-912);北京市自然科学基金(4162006) |
|
| Trusted Connection Protocol Between Networks |
|
LAI Ying-Xu, LIU Yan, LIU Jing
|
|
College of Computer Science, Faculty of Information Technology, Beijing University of Technology, Beijing 100124, China
|
| Abstract: |
| Trusted connect architecture (TCA) technology was introduced to solve the problem of trusted connect between networks in "Pushing Forward the Internet plus Advanced Manufacturing" plan. Based on the idea of TCA technology, this study proposed a trusted connection protocol (TCA-SNI) for trusted authentication and evaluation between networks. The two-way authentication process is introduced and the interaction of TCA-SNI is given. The extended SVO logic system is used to infer the protocol logicalness, which proves that the protocol is safe and reliable. The protocol is detected using the Dolev-Yao model. Experimental results show that the proposed protocol has achieved the security goal, and can withstand attacks in the real network. |
| Key words: trusted connect architecture (TCA) trust computing trusted connection protocol SVO AVISPA |