检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
作 者:张兆心[1] 杜跃进[1] 方滨兴[1] 张宏莉[1]
机构地区:[1]哈尔滨工业大学国家计算机网络与信息安全重点实验室,哈尔滨150001
出 处:《高技术通讯》2010年第11期1108-1114,共7页Chinese High Technology Letters
基 金:863计划(2006AA01Z451;2007AA010503)资助项目
摘 要:利用BAN逻辑对会话初始化协议(SIP)网络采用的超文本传输协议(HTTP)摘要认证协议进行了形式化分析和推导。通过严格的逻辑推导,证明HTTP摘要认证协议存在不足,以及由此产生的伪装攻击。通过对逻辑推理结果和推导过程的分析,针对BAN逻辑提出增加消息抗否认性规则和消息新鲜性传递规则,增强了BAN逻辑的逻辑推理能力;针对HTTP摘要认证协议提出增加数字签名、公私钥机制、双向认证和密钥协商,提高了HTTP摘要认证协议的安全性。The formalized amalysis and deduction of the HTFP digest authentication protocol used in session initiation protocol (SIP) networks were conducted by using the BAN logic. The limitations in the HTTP digest authentication protocol and the impersonation attacks caused by the limitations were verified through the strict logic ratiocination. Based on the result of the logic ratiocination and the analysis of the ratiocination process, the message identity validating rule and the message novelty transfer rule were added to the BAN logic, and the ability for logic deduction of the BAN logic was improved. The measures of digital signature, public and private key, two-way authentication, and key negotiation were added to the HTTP Digest authentication protocol, and the security of the protocol was enhanced.
关 键 词:BAN逻辑 SIP HTTP摘要认证协议 双向认证
分 类 号:TP393.08[自动化与计算机技术—计算机应用技术]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.30