应用科学学报 ›› 2003, Vol. 21 ›› Issue (2): 193-198.

• 论文 • 上一篇    下一篇

基于IPSec的无线局域网安全通信机制分析及其算法研究

吴越1,2, 史小红1, 曹秀英1, 毕光国1   

  1. 1 东南大学无线电系移动通信国家重点实验室, 信息安全研究中心 江苏 南京 210096;
    2 华东船舶工业学院 电子与信息学院 江苏 镇江 212003
  • 收稿日期:2002-06-14 修回日期:2002-09-17 出版日期:2003-06-10 发布日期:2003-06-10
  • 作者简介:吴越(1968-),男,江苏兴化人,副教授,博士生;毕光国(1939-),男,上海人,教授,博导
  • 基金资助:
    国家高技术研究发展计划(2001AA143040);东南大学移动通信国家重点实验室开放基金(A0108)

A Security Analysis of the IPSec Based WLAN Solution and a Study of Its Algorithm

WU Yue1,2, SHI Xiao-hong1, CAO Xiu-ying1, BI Guang-guo1   

  1. 1 National Laboratory of Mobile Communications, Department of Radio Engineering, SoutheastUniversity, Nanjing 210096, China;
    2 College of Electronics and Information, East China Shipbuilding Institute, Zhenjiang 212003, China
  • Received:2002-06-14 Revised:2002-09-17 Online:2003-06-10 Published:2003-06-10

摘要: 分析了现有无线局域网标准IEEE802.11中的WEP协议密钥序列重复使用、消息认证和完整性、密钥管理与更新问题的安全机制的脆弱性,提出了基于IPSec的安全WLAN解决方案,详细讨论了其中的安全认证、完整性保护、重放攻击保护、机密性算法和密钥交换的结构和原理,给出其相应的编程实现,并对结果进行了深入的安全分析,最后对今后研究的方向作出了展望。

关键词: 无线局域网, 安全, 认证, WEP协议, IP安全, 加密

Abstract: This paper describes the vulnerability of the wired equivalent privacy(WEP) protocol in current IEEE802. 11 WLAN standard, such as key sequence reuse, key management and refreshment, message authentication and integrity, etc. It also presents a security solution for WLAN based on IP Security (IPSec) and discusses the fundamental principles of data origin authentication, integrity protection, anti-replay protection and key exchange, Finally it describes their software implementations, makes a security analysis of the solution and looks into the future research.

Key words: wireless local area network (WLAN), security, authentication, IP security(IPSec), WEP algorithm, encryption

中图分类号: