期刊文献+

基于可信计算技术的OSPF路由协议研究 被引量:2

Study of OSPF based on trusted computing
在线阅读 下载PDF
导出
摘要 为了解决目前路由安全方案中只对路由器身份进行认证,而未对路由器平台的完整性进行验证的问题,在基于LSU数字签名的OSPF协议基础上,借鉴可信计算的完整性度量思想,提出了一种新的可信路由协议TC-OSPF(OSPF based on tru-sted computing)。分析了LSU数字签名过程,指出了在LSU签名过程中加入路由平台完整性度量的可行性,在此基础上设计了具有完整性度量功能的LSU报文结构。安全性分析表明,TC-OSPF协议不仅可以对路由器身份进行认证,同时也能对路由平台的完整性进行验证。仿真实验结果表明,TC-OSPF在保证了OSPF协议安全性的同时也兼顾了路由性能。 In order to slove the problems on presented routing secure solutions only to resolve the identity authentication,but no resolve the integrity verification.In order to conquer limitations above-mentioned,a new trusted routing protocol is proposed that is based on trusted computing and the digital signature OSPF using LSU.The new protocol can be called TC-OSPF(OSPF based on trusted computing).Firstly,the LSU digital signature process is analysed and the feasibility can be given for adding the router platform integrity measurement to the LSU digital signature process.Then,LSU packet is designed which can measure integrity of router platform.The security analysis shows that TC-OSPF can resolve not only the identity authentication,but also the integrity verification.The simulation results show that the TC-OSPF can achieve the goal of OSPF security compatible with routing performance.
出处 《计算机工程与设计》 CSCD 北大核心 2011年第9期2946-2949,共4页 Computer Engineering and Design
基金 国家自然科学基金项目(60951001) 国家科技支撑重点基金项目(2009BAH52B06) 北京市自然科学基金项目(4102057)
关键词 安全路由 开放式最短路径优先协议 链路状态更新数据包 可信计算 完整性 secure routing OSPF LSU packet trusted computing integrity
  • 相关文献

参考文献14

二级参考文献187

共引文献344

同被引文献15

  • 1Tavemier W, Papadimitriou D, Colle D, et al. Optimizing the IP router update process with traffie-dHven updates. Proe of the 7th IEEE Conference on Design of Reliable Communication Networks. 2009 : 115-122.
  • 2Bonaventure O, Filsfils C, Francois P. Achieving sub-50 milliseconds recovery upon BGP peering link failures. Proc. of IEEE/ACM Trans- actions on Networking. [S. 1. ] : IEEE Press, 2007:1123-1135.
  • 3Katz D, Ward D. Intemet-draft draft-ietf-bfd-base-08, Bidirectional Forwarding Detection, [ S. 1. ] : IETF, 2008.
  • 4Shand M. draft-ieff-rtgwg-ipfrr-framework-08. IP Fast Reroute Frame- work, [S. 1. ]: IETF, 2008.
  • 5Nelakuditi S, Lee S, Yu Y, et al. Fast local rerouting for handling transient link failures. Proc of IEEE/ACM Transactions on Networ- king. 2007 : 359-372.
  • 6Tavemier W, Papadimitfiou D, Colle D, et al. Optimizing the IP router update process with traffic-driven updates. Proc of the 7th IEEE Conference on Design of Reliable Communication Networks. 2009: 115-122.
  • 7Sang A, Li S. A predictability analysis of network traffic, Computer networks, 2002 ; 39 (5) : 329-345.
  • 8Zhou B, He D, Sun Z. Network traffic modeling and prediction with ARIMA/GARCH.//Proc of the third international working confer- ence of performance modeling and evaluation of heterogeneous net- works. [S. 1. ] : IEEE Press, 2005; 112-118.
  • 9Di C, Hai-Hang F, Qing-jia L, et al. Multiseale intemet traffic pre- diction using wavelet neural network combined model. Proc of the 1st International Conference on Communications and Networking in Chi- na. [ S. 1. ] : IEEE Press, 2006 : 1-5.
  • 10Cao Zheng, Lei Li. The improvement of the forecasting model of short-term traffic flow based on wavelet and ARMA. Proc. the 8th IEEE conference of Supply Chain Management and Information Sys- tems, 2010 International Conference on . [ S. 1. ] : IEEE Press, 2010; 1-4.

引证文献2

二级引证文献2

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部