...
首页> 外文期刊>International journal of communication networks and distributed systems >Protection of LAN-wide, P2P interactions: a holistic approach
【24h】

Protection of LAN-wide, P2P interactions: a holistic approach

机译:保护局域网范围内的P2P交互:一种整体方法

获取原文
获取原文并翻译 | 示例
           

摘要

This article advocates the need of a holistic approach to protect LAN interactions and presents a solution for implementing it based on secure LAN (SLAN), a novel security architecture. SLAN uses the 802.1X access control mechanisms and is supported by a key distribution centre (KDC) built upon an 802.1X authentication server. The KDC is used, together with a new host identification policy and modified DHCP servers, to provide proper resource allocation and message authentication in DHCP transactions. The KDC is used to authenticate ARP transactions and to distribute session keys to pairs of LAN hosts, allowing them to set up arbitrary, LAN-wide peer-to-peer security associations using such session keys. We show how PPPoE and IPSec security associations may be instantiated and present a prototype implementation for IPSec.
机译:本文提出了一种保护LAN交互的整体方法的需求,并提出了一种基于安全LAN(SLAN)(一种新颖的安全体系结构)的实现方案。 SLAN使用802.1X访问控制机制,并由建立在802.1X身份验证服务器上的密钥分发中心(KDC)支持。 KDC与新的主机标识策略和经过修改的DHCP服务器一起用于在DHCP事务中提供正确的资源分配和消息身份验证。 KDC用于验证ARP事务并将会话密钥分发给成对的LAN主机,从而使它们可以使用此类会话密钥建立任意的,局域网范围内的对等安全关联。我们将说明如何实例化PPPoE和IPSec安全关联,并介绍IPSec的原型实现。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号