论文部分内容阅读
传统IPSec协议在建立安全通信连接时,没有考虑终端自身安全问题,而可信计算的远程证明机制就是为被接入方提供接入方的自身安全证明,将其引入IPSec协议可以弥补建立IPSec连接时的终端安全漏洞。首先分析了IPSec协议的IKE协商过程和可信计算技术的远程证明机制,然后以基于数字签名的IKE主模式流程为例,提出在IKE协商阶段引入远程证明机制的IPSec远程证明扩展协议流程及安全分析。该协议引入带有SKAE扩展项的身份证书,实现对终端身份和系统完整性的双重认证,确保端到端的安全连接。协议在保证通信信息的机密性、完整性、新鲜性之外,也充分保护终端平台隐私性。
When establishing a secure communication connection, the traditional IPSec protocol does not consider the terminal’s own security problem. The trusted authentication remote authentication mechanism provides the access side with its own security certificate. Introducing it into the IPSec protocol can make up the IPSec connection When the terminal security vulnerabilities. First, I analyze the IPSec protocol IKE negotiation process and trusted computing technology remote authentication mechanism, and then based on the digital signature IKE master mode process as an example, the introduction of remote authentication mechanism in the IKE negotiation phase of the remote certification of IPSec protocol protocol flow and security analysis. The protocol introduces an identity certificate with the SKAE extension to enable dual authentication of terminal identity and system integrity to ensure end-to-end secure connections. Agreement to ensure the confidentiality of communications, integrity, freshness, but also fully protect the privacy of the terminal platform.