首页> 外文期刊>IEEE/ACM Transactions on Networking >The KryptoKnight family of light-weight protocols for authentication and key distribution
【24h】

The KryptoKnight family of light-weight protocols for authentication and key distribution

机译:KryptoKnight系列轻量级协议,用于身份验证和密钥分发

获取原文
获取原文并翻译 | 示例

摘要

An essential function for achieving security in computer networks is reliable authentication of communicating parties and network components. Such authentication typically relies on exchanges of cryptographic messages between the involved parties, which in turn implies that these parties be able to acquire shared secret keys or certified public keys. Provision of authentication and key distribution functions in the primitive and resource-constrained environments of low-function networking mechanisms, portable, or wireless devices presents challenges in terms of resource usage, system management, ease of use, efficiency, and flexibility that are beyond the capabilities of previous designs such as Kerberos or X.509. This paper presents a family of light-weight authentication and key distribution protocols suitable for use in the low layers of network architectures. All the protocols are built around a common two-way authentication protocol. The paper argues that key distribution may require substantially different approaches in different network environments and shows that the proposed family of protocols offers a flexible palette of compatible solutions addressing many different networking scenarios. The mechanisms are minimal in cryptographic processing and message size, yet they are strong enough to meet the needs of secure key distribution for network entity authentication. The protocols presented have been implemented as part of comprehensive security subsystem prototype called KryptoKnight.
机译:在计算机网络中实现安全性的基本功能是对通信方和网络组件进行可靠的身份验证。这种认证通常依赖于相关方之间的加密消息交换,这又意味着这些方能够获取共享的秘密密钥或经认证的公共密钥。在低功能网络机制,便携式或无线设备的原始和资源受限的环境中提供身份验证和密钥分发功能给资源使用,系统管理,易用性,效率和灵活性带来了挑战,这些挑战超出了以前的设计(例如Kerberos或X.509)的功能。本文介绍了适用于网络体系结构低层的轻量级身份验证和密钥分发协议系列。所有协议都是基于通用的双向身份验证协议构建的。该论文认为,密钥分发在不同的网络环境中可能需要实质上不同的方法,并表明所提议的协议家族提供了可解决许多不同联网场景的兼容解决方案的灵活选择。该机制在密码处理和消息大小方面是最小的,但是它们足够强大,可以满足网络实体身份验证的安全密钥分发的需求。提出的协议已作为名为KryptoKnight的综合安全子系统原型的一部分实现。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号