宽带卫星网络安全协议分析-analysis of broadband satellite network security protocol.docxVIP

  • 11
  • 0
  • 约15.07万字
  • 约 132页
  • 2018-05-29 发布于上海
  • 举报

宽带卫星网络安全协议分析-analysis of broadband satellite network security protocol.docx

总结已有文献的基础上,提出了适应 SIKE 密钥交换抽取算法的 HMAC-DH 基础假设。研究指出 HMAC-DH 假设弱于 DDH 假设,HMAC-DH 假设成立只要求 DH 群包含一个足够大并支持 DDH 的子群,因而归约到 HMAC-DH 假设难题的 安全协议相对 DDH 假设具有更强的安全性。证明得到 SIKE 会话密钥具有一致 性,并得到协议攻击者对会话密钥与随机选择密钥无法区分。会话密钥一致性和 会话密钥与随机选择密钥的不可区分性表明 SIKE 协议具有会话密钥安全属性。 第四,设计宽带卫星网络支持 CZ-IPSec 可证明安全的三方认证密钥交换协议 STIKE 与四方认证密钥交换协议 SQIKE。与现有文献研究不同,根据 CZ-IPSec 要求,协议设计具有三方、四方密钥交换融合两端参与成员的两方密钥交换的特 殊性。因此,对于这种特殊认证密钥交换协议的可证明安全形式化设计分析具有 开创性。为达到减少消息传输数量,尤其是卫星链路消息传输数量的目的,协议 设计利用了 TCP 性能增强代理的消息窥探功能。STIKE 与 SQIKE 的设计与形式 化分析验证分别基于扩展 CK 模型和扩展 BCP 模型。证明得到 STIKE 与 SQIKE 满足会话密钥安全要求,并满足其它各项安全属性要求。本文对 STIKE、SQIKE、 IKEv2 和 SIKE 协议的消息传输量与计算量进行了比较与讨论。关键词:宽带卫星网络;安全协议;TCP 增强;CZ-IPSec;认证密钥交换AbstractIn recent years, accessing to Internet via satellite, as an essential component of air-space-ground integrated information networks in the future, has become a trend of satellite communication development. The integration of satellite communication and Internet expands Internet utilization districts and enriches functions and attributes of satellite communication. There are some technical chanllenges existing in interoperations between satellite communication system and terrestrial Internet infrastructure. The performance deterioration of TCP/IP applying to satellite networks has been researched in detail, and different kinds of effective TCP performance enhancing techniques have been proposed. However, IPSec and IKE matching TCP/IP and supplying security service in terrestrial Internet have still some applicable problems when transplanting to broadband satellite networks, such as incompatibility with TCP performance enhancing techniques. So, designing and analysing applicable security protocol are key points of broadband satellite network researches.The dissertation researches security methods of broadband satellite networks with supporting TCP performance enhancing technique in depth by referring to the latest researches. It enriches security framework of broadband satellite networks which implements TCP performance enhanc

您可能关注的文档

文档评论(0)

1亿VIP精品文档

相关文档