Computer Science ›› 2011, Vol. 38 ›› Issue (6): 49-53.
Previous Articles Next Articles
WANG Jian,WANG Hai-hang,YANG Jian
Online:
Published:
Abstract: Standard IPSec doesn't provide any guarantees about the integrity of the endpoints when an IPSec linkage is established. And the remote attestation in trusted computing is to provide security evidence of the user for the accessed server. So it can avoid terminal security vulnerability in IPSec to introduce the remote attestation into IPSec. IKE negotianon of IPSec and remote attestation mechanism were analyzed firstly. Then taking IKE main mode based on figure signature for example, an extended IPSec protocol based on remote attestation and its security analysis were presented. In the extended IPSec protocol,remote attestation mechanism was introduced into IKE negotiation. hhis protocol can complete double authentications including identity and system integrity by using a certificate with a SKAE extension to ensure an end-to-end secure linkage. Besides, the protocol can guarantee not only information' s confidentiality, integrity and freshness,but also endpoints' privacy.
Key words: IPSec, IKE negotiation, Remote attestation, Trusted computing, Integrity measurement
WANG Jian,WANG Hai-hang,YANG Jian. Remote Attestation Extension for IPSec[J].Computer Science, 2011, 38(6): 49-53.
0 / / Recommend
Add to citation manager EndNote|Reference Manager|ProCite|BibTeX|RefWorks
URL: https://www.jsjkx.com/EN/
https://www.jsjkx.com/EN/Y2011/V38/I6/49
Cited