期刊文献+

802.1x协议安全性能的改进 被引量:3

Improvement in security of 802.1x protocol
在线阅读 下载PDF
导出
摘要 在宽带接入认证方案中,802.1x以其实现简单、高认证效率、高安全性正在被广泛的使用,特别是在校园网络应用非常普遍。同时用户口令失窃和口令扩散的情况非常多,由于MAC、IP地址假冒所发生的网络安全问题也非常突出。业界普遍采用IP+MAC绑定的做法,但此方案由于未能彻底防止MAC假冒,有待提高。本文分析了IEEE802.1x的体系结构,认证过程及协议报文结构。在此基础上,提出了一套解决方案。即通过专有的802.1x认证客户端在传送EAP的Response报文时,在Identity字段中携带认证端通过特殊加密处理的真实MAC。同时在Radius认证服务器端做相应解密处理,确保只有专有的认证客户端才能认证成功,从而彻底解决上述问题。 802. 1x protocol,as a new access authentication method, becomes more and more popular for its simplicity, efficiency, security, esp. on campus. But the user name and user password are easily stolen or missed, thus the security problems produced by MAC, IP-personating pop out. To overcome these, binding the IP and MAC is a commonly problem-solving, but for it cannot prevent MAC-personating thoroughly, this way need to be improved. This paper gives a brief introduction to the architecture and authentication mechanism of the 802. 1x protocol. Based on these, it presents a thorough solution. That is, when sending EAP response packets in client software side, we put the encrypted real MAC in the identity field. While receiving response packets in radius server side, we decrypt the identity field. It can ensue that only by the specific client software the authentication may success, thus resolve the above problem thoroughly.
出处 《电子测量技术》 2007年第1期107-109,共3页 Electronic Measurement Technology
关键词 802.1x协议 身份认证 加密 宽带接入 802. 1x protocol identity authentication encryption
  • 相关文献

参考文献6

二级参考文献12

  • 1[1]Kohl J, C Neuman. The Kerberos Network Authentication Service (V5)[J]. RFC 1510, Digital Equipment Corporation, USC/Information Sciences Institute, September 1993.
  • 2[2]ITU-T, Recommendation X.509. The Directory-authentication Framework[J]. Consultation Committee, International Telephone and Telegraphm, Inernational Telecommunications Union.
  • 3[3]R L Rivest. RFC 1321. The MD5 Message-digest Algorithm[J]. Internet Request for Comments 1321, Apr. 1992.
  • 4[4]C Rigney, A Rubens, W Simpson, S Willens. RFC 2138, Remote Authentication Dial in User Service (RADIUS)[J]. 1997-04-18.
  • 5[2]GT-48510 Converged Voice/Data Network Switch Processor Data Sheet
  • 6[3]Intel Media Switch IXE 2424 10/100+Gigabit L2/3/4 Advanced Device Developer's Manual
  • 7IEEE802.1x Standard for Local and Metropolitian Area Networks Port-based Network Access Control[S].
  • 8RFC2865. Remote Authentication Dial In User Service(RADIUS)[S].
  • 9RFC2869. RADIUS Extensions [S].
  • 10RFC1334-PPP Authentication Protocols [S].

共引文献46

同被引文献17

引证文献3

二级引证文献14

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部