摘要
身份认证是P2P(peer to peer)网络安全的重要组成部分,但传统的PKI(金钥基础设施)认证方式因为具有静态的集中化控制和固定的证书内容等特点,不能很好地满足P2P网络安全认证的需要,且在公钥的分发过程中容易遭受中间人攻击。为此,提出了一种新型的公钥管理架构和身份认证方案,每个节点可以自己产生并分发公私钥,认证服务器仅在节点加入网络时参与完成公钥的分发。超级节点负责管理本组内全部节点的公钥,节点在相互认证时无需认证服务器的参与,仅通过超级节点来完成。分析结果表明,这种认证方案可以有效地抵抗中间人攻击,在保持高效率的基础上又保证了认证的安全性。
Identity authentication is an important part of P2P network security. Traditional PKI authenticaton method can not adapt to the demand of P2P network security authentication due to its characteristics such as static centralized control and fixed certificate features. It is also vulnerable to man-in-the-middle attack during the process of common key distribution. In this paper, we propose a new common key management framework and identity authentication scheme. Each node can generate and distribute its own common key and private key. The certificate server works only during the process of common key distribution. The super node can manage the common keys of all the nodes in its group. When the nodes certificate each other, the super-node instead of the certificate server will manage the process. The analysis result shows that this authentication scheme can effectively resist man-in-the-middle attack and has higher security performance while keeping high efficiency.
出处
《信息化研究》
2009年第12期58-60,共3页
INFORMATIZATION RESEARCH
基金
中兴通讯高校合作基金
关键词
P2P
认证
公钥管理架构
中间人攻击
P2P
authentication
public key management framework
man-in-the-middle attack