Extensible authentication method and system based on ISAKMP (Internet Security Association and Key Management Protocol)

Extensible authentication method and system based on ISAKMP (Internet Security Association and Key Management Protocol)
复制标题

基于ISAKMP(互联网安全关联和密钥管理协议)的可扩展认证方法及系统

DOI:
--
复制
发表时间:
2011
期刊:
影响因子:
--
通讯作者:
韦银星
韦银星
中科院分区:
--
文献类型:
--
作者:
梁小萍;韦银星

文献摘要

被引文献

相似文献

本发明公开了一种基于互联网安全关联和密钥管理协议(ISAKMP)的可扩展认证方法。所述可扩展认证方法包括:一旦需要发送第一路由报文,发起方和响应方协商采用可扩展认证协议(EAP)进行认证;发起方和响应方根据EAP过程中产生的主会话密钥(MSK)或EAP认证通过后的共享密钥,计算携带AUTH载荷的消息认证码(HMAC)值,并将AUTH载荷发送给对方,以完成ISAKMP中的认证。本发明还公开了一种基于ISAKMP的可扩展认证系统。采用本发明的方法和系统,可以从ISAKMP中灵活选择认证方法,从而跟踪现代认证技术的发展。
The invention discloses an extensible authentication method based on an internet security association and key management protocol (ISAKMP). The extensible authentication method comprises the steps of: negotiating to carry out authentication by adopting an extensible authentication protocol (EAP) through an initiator and a responder once a first route message is required to be sent; calculating message authentication code (HMAC) value with a key in AUTH load through the initiator and the responder according to a master session key (MSK) produced in the EAP process or a shared key after passing the EAP authentication, and sending the AUTH load to the opposite side, so as to finish the authentication in the ISAKMP. The invention also discloses an extensible authentication system based on the ISAKMP. By adopting the method and system disclosed by the invention, the authentication method can be flexibly selected from the ISAKMP, so that the development of the modern authentication technology can be followed.