• Article
  • | |
  • Metrics
  • |
  • Reference [6]
  • |
  • Related
  • |
  • Cited by [3]
  • | |
  • Comments
    Abstract:

    IKE (Internet key exchange, RFC2409) describes a suite of Internet key exchange protocols for establishing security associations and obtaining authenticated keying material. A security flaw in these IKE protocols is observed and a simple modification is proposed. In this paper, it is pointed out that there is a neglected security flaw in the amended IKE protocols. And a successful attack on the amended IKE protocols is also provided. A new amendment to IKE protocols is proposed, and the reasons which cause the two security flaws are analyzed by using BAN logic successfully.

    Reference
    [1] Harkings, D., Carrel, D. The Internet key exchange (IKE). RFC 2409, 1998.
    [2] Zhou, Jian-ying. Fixing of security flaw in IKE protocols. Electronics Letters, 1999,35(13):1072~1073.
    [3] Maughan, D., Schertler, M., Schneider, M., et al. Internet Security Association and key management protocol (ISAKMP). RFC 2408, 1998.
    [4] Orman, H. The Oakley key determination protocols. RFC2412, 1998.
    [5] Krawczyk, H. SKEME: a versatile secure key exchange mechanism for Internet. In: IEEE ed. Proceedings of the 1996 Symposium on Network and Distributed System Security (SNDSS'96). 1996.
    [6] Burrows, M., Abadi, M., Needham, R. A logic of authentication. ACM Transactions on Computer Systems, 1990,8(1):18~36.
    Related
    Comments
    Comments
    分享到微博
    Submit
Get Citation

张勇,冯东雷,陈涵生,白英彩. Internet密钥交换协议的安全缺陷分析.软件学报,2002,13(6):1173-1177

Copy
Share
Article Metrics
  • Abstract:
  • PDF:
  • HTML:
  • Cited by:
History
  • Received:August 15,2000
  • Revised:March 01,2001
You are the first2045205Visitors
Copyright: Institute of Software, Chinese Academy of Sciences Beijing ICP No. 05046678-4
Address:4# South Fourth Street, Zhong Guan Cun, Beijing 100190,Postal Code:100190
Phone:010-62562563 Fax:010-62562533 Email:jos@iscas.ac.cn
Technical Support:Beijing Qinyun Technology Development Co., Ltd.

Beijing Public Network Security No. 11040202500063