基于EAP-TLS的可信网络连接认证方案设计与实现
收稿日期: 2010-07-29
修回日期: 2010-10-26
网络出版日期: 2011-04-25
基金资助
国家自然科学基金资助项目(60951001);北京市自然科学基金资助项目(4102057);中办信息安全重点实验室项目(YZDJ0806)
Design and Implementation of an Authentication Scheme for Trusted Network Connection Based on EAPTLS
Received date: 2010-07-29
Revised date: 2010-10-26
Online published: 2011-04-25
池亚平1,杨磊1,2,李兆斌1,方勇1 . 基于EAP-TLS的可信网络连接认证方案设计与实现[J]. 计算机工程与科学, 2011 , 33(4) : 8 -12 . DOI: 10.3969/j.issn.1007130X.2011.
When a terminal access network, a trusted authentication of the terminal platform identity and the platform environment are implemented in the TNC architecture, which ensures the credibility of access terminal. However, the trusted authentication has the oneway limitation that can not guarantee the network server's credibility. EAPTLS is a extended authentication protocol based on 802.1x,which suports mutual authentication.On the basis of analyzing the architecture of TNC and the mutual authentication mechanism of EAPTLS,a mutual authentication scheme used in TNC based on EAPTLS is designed in this paper.The mutual authentication scheme is based on the certificates,the integrity and the trusted environment of platform,both for clients and servers.Finally,the paper implements a twoway trusted authentication scheme between the client and the server on the basis of the open source software FHH@TNC,and proves its validity.
[1]Trusted Computing Group.TCG Specification Trusted Network Connect TNC Architecture for Interoperability Revision 1.1 [EB/OL].[20060510].http://www.trustedcomputinggroup.org.
[2]LUO Anan, LIN Chuang,CHEN Zhen,et al. TNCcompatible NAC System Implemented on Network Processor[C]∥Proc of the 32nd IEEE Conf on Local Computer Networks,2007:10691075.
[3]Rehbock S, Hunt R. Trustworthy Clients: Architectural Approaches for Extending TNC to WebBased Environments[J]. Computer Communications,2009, 32(5):246249.
[4]罗安安,林闯,王元卓,等.可信网络连接的安全量化分析与协议改进[J].计算机学报,2009,32(5):887898.
[5]邓永晖,卿昱,左朝树,等.一种基于EAP的可信网络接入机制[J].通信技术,2009,12(42):109111.
[6]凤琦,王震宇,李向东,等.基于802.1X的可信网络连接技术[J].计算机工程,2009,35(5):165167.
[7]颜菲,任江春,戴葵,等.基于TNC的安全认证协议的设计与实现[J].计算机工程,2007,33(12):160162.
[8]张焕国,陈璐,张立强.可信网络连接研究[J].计算机学报,2010,33(1):112.
[9]王巧. 基于IEEE 802.1X/EAPTLS安全认证协议的研究和改进[D]. 成都:电子科技大学, 2009.
[10]Open Source Project for TNC[EB/OL].[20061018].http://tnc.inform.fhhannover.de.
/
| 〈 |
|
〉 |