Symmetric identification method in network combination of network equip ment and network combination method
Abstract
The invention relates to the network with internet apparatus, and fuse are authentication method and corresponding networking method. The invention claims a method for security password gain based on kerberos base, suitable claims a router the tendency and safety certification, a coordinating Kerberos entity symmetrical authentication method, wherein the invention, video and whole router is a Kerberos client entity, which makes user server and password and router, an alarm via KDC with an router via alternating and dynamic gain of random sharing password. At the same time, regular time kerberos is interactive with KDC and adjacency router of the router, the gain random key, very rod is realized dynamic updating symmetrical authentication key the safety function of the router, reduced in internet of the load of configuration and maintenance of facilitating symmetrical authentication.

Term
No projected expiry on record.
- Priority and filed
- Published
- Today
9 claims: 2 independent, 7 dependent
- 1The symmetrical authentication method in network 1.1 networkings device, comprising characterised:aThe full router and a Kerberos client entity, which makes user server and password and router, specifically comprising the following steps: (1) And the client kerberos module according to the kerberos protocol in the router end;(2) Are switch routers' kerberos module, for is connected with the adjacency router of the key distribution centre and corresponding router symbol and kerberos module, and kerberos protocol is interactive, so two ends to obtain the key distribution centre assignment for sharing random key system. 1.一种网络设备组网中的对称认证方法,其特征在于:将整个路由器作为一个Kerberos客户端实体,为路由器设置自身的用户名和密码,具体包括以下步骤:(1)在路由器端按照kerberos协议配置kerberos客户端模块;(2)启动所有路由器的kerberos模块,由kerberos模块通过与密钥分发中心和对应路由器标识的邻接路由器进行连接,并进行kerberos协议交互,使双方获得密钥分发中心分配的随机共享密钥。
- 8The 8.1 pair of network device networkings for symmetrical authentication the networking method, the is characterised:aThe full router and a Kerberos client entity, which makes user server and password and router, specifically comprising the following steps: (1) And the client kerberos module according to the kerberos protocol in the router end;(2) Are switch routers' kerberos module, for is connected with the adjacency router of the key distribution centre and corresponding router symbol and kerberos module, and kerberos protocol is interactive, so two ends to obtain the key distribution centre assignment for sharing random key system. 8.一种网络设备组网中使用对称认证的组网方法,其特征在于:将整个路由器作为一个Kerberos客户端实体,为路由器设置自身的用户名和密码,具体包括以下步骤:(1)在路由器端按照kerberos协议配置kerberos客户端模块;(2)启动所有路由器的kerberos模块,由kerberos模块通过与密钥分发中心和对应路由器标识的邻接路由器进行连接,并进行kerberos协议交互,使双方获得密钥分发中心分配的随机共享密钥。
Independent claims2
32 paragraphs, as filed
Symmetrical authentication method and networking method in network networking device
technical field
The safety certification method in the invention relates to a communication field, to of network device of transformer, how for supporting the dynamic and safety symmetrical authentication method and corresponding networking method.
background technology
Wherein the Internet of things, a network device (router or three switchboards, a rear succinct on emitter, and router end is emitter touching each one of protocols and) of the requirements safety constantly which; the main key is a router for accessing Internet for authorization, wherein the configuration error or a malicious configuration affect in network the original router, creates the routing miscalculation, the tunnel divulges secrets, network topology vibration equal a series of serious problems. The presentation of the router manufacturers' the magnetism protocol module (for example Line, OSPF, BGP, L2TP, Ipsec, Isis, Ldp equal) is a method for facilitating symmetrical authentication; the swap protocol message, authentication transmission message side and time of the state; and identification authentication of opposite party no bracket, which is arranged on not to receiver the router's protocol is interactive by, avoiding wrong introducing or a attacked a message.
Although the end-to-end are symmetrical MD5 authentication method, an router's and router in a network moved to the router of authorization, further arranged on the widespread application of the authentication method, display part inherent defects gradually: (1) At each factories the processing of configuration protocol end-to-end symmetrical authentication is very tedious, need of the protocol and arranged on the sleeves are key in the adjacency protocol hanging hole time, wherein the protocol of router are respectively provided with multiple to the conducting; each router of dozens with different keys is allocated to maintain. The need to use in a network security the password arranged of the router, the duty number of huge, moreover easily is a plug.
(2) Is a protocol module are input password of two sides router, the password is fixed; besides the manual modified, wherein an - side; creates the safety danger.
(3) Wherein the password is configured by a network management, manually for conveniently memory and managing, wherein the is generally that the serial connection of the password, a safety is very section, a to generate a random key automatically.
Shown and a digital 1 with the oxide end-to-end symmetrical authentication configuration schematic drawings, wherein two router (the position R1 and R2) is a supporting the end-to-end symmetrical authentication the protocol; the two ends of the balanced the corresponding of the password; the passwords and static allocations, comprising of the continuity, which are the password, wherein the maintain the password invariably very clamped easily is invention is a long time, a very dangerous. Therefore needed the network management personnel's regular updating protocol the passwords, a ensuring consistency between datum of the receiver router's authentication safety. Wherein the password universal one when the own diode device of each protocol, need to change the protocol password one of router, need to perform the protocol diode and commands end of the conducting unusually, easily to for configuring plug or a oversight. With very high burden to the maintenance network working.
The operating of usual router with multiple to the end, here supposition with n to the router, wherein the digital 1 configuration arranged on each router configured with common for ipsec, ldp, ospf, bgp, and m 12tp tunnels. On each router flowing balanced n× (4+m password), and, wherein the end-to-end symmetrical authentication needs a network management regular updating to prevent to divulge secrets; when the network topology is big (typically with dozens to more than one hundred router), wherein the password operating a load according with is very huge.
The patented claim CN1450766, claimed is a handling a dynamic host configuration protocol user management, comprising the following steps: (1 )Clients the number of the DHCP, request(2 )Is DHCP server response client request of a user control information, a a user access ability; (3 )And the user terminal and authentication, and a authenticate the inspection loop is electrically connected with the DHCP server,(4 )Is DHCP server authentication to perform updating user control information, and new network configuration a distribution a client; (5 )And the user access network the normally, the other DHCP information of DHCP server processing user. The method solve the user by the DHCP access to the weak problem that the user pipe, and multiple types of authentication respectively; the extending is convenient, lighting the maintenance network burden. A position needed a network management updating regular intervals to prevent to divulge secrets; when the network topology is big, wherein the password operating a load according with is very huge.
invention content
Target of the invention, to reduce wherein an internet of load of configuration and maintenance of facilitating symmetrical authentication, and enables router oneself is in a regular automatic for updating the new any cipher, wherein it is longer with the original fixing invariable password, provides of practical of the perfect solution for security and dynamic symmetrical authentication. The condition of the nowadays and network topology and configuring antenna is a day complex, a safety executing mechanism, a hard to maintain, capable of automatically and safety protection direction develop to the network device for gradually.
The invention based on the kerberos a function of initially, suitable router in coordination Kerberos entity the solution of tendency and safety symmetrical authentication, greatly reduces the technical field and maintain between the router with a, updating with giant load of each protocol end-to-end authentication passwords branches, simultaneously with realizes the dynamic updating authentication key safety function, large around the receiver router of safety, and enabled between the router the symmetrical authentication with good function of automatically safety.
The invention based on is taken the anti-theft base of Massachusetts claims an (MIT) development's kerberos secret key trustconnector protocol, service data switch density a standard (DES) overlapped the double-seal algorithm filled with density and authentication. Kerberos end of the authentication is designed to the support of network resource, comprising the same to the secret key system, Kerberos based on third-party concept of a trust, the third party to user service and execution safety certification. The Kerberos protocol, the third party of the trust capable of called key distribution body (KDC, Key Distribution Centre). Kerberos protocol is a years widely applied is shown for is very safety, a Microsoft, HP, IBM, CISCO, SUN and other manufacturers is supported. Moreover is easy substrate, and that is used for the host and client and application service/safety control the server terminal mode.
The invention claims a method for security password gain based on kerberos base, suitable claims a router the tendency and safety certification, a coordinating Kerberos entity symmetrical authentication method, wherein the invention, video and whole router is a Kerberos client entity, which makes user server and password and router, an alarm via KDC with an router via alternating and dynamic gain of random sharing password. At the same time, regular time kerberos is interactive with KDC and adjacency router of the router, the gain random key, very rod is realized dynamic updating symmetrical authentication key the safety function of the router.
Computing technology key unit of this invention is: (1) And the client kerberos module according to the kerberos protocol in the router terminal.
(2) Are switch routers' kerberos module, a time connected and a on the kerberos protocol is interaction between the adjacency router according KDC and corresponding router marks of the kerberos module, so two sides of the straight KDC assignment for sharing random key system. The protocol of shaft according to the router different, further configured different router in order to a random shared key system.
(3) And the lower support router dynamic continuous authentication the password, and the kerberos timer, the timer overtime time, wherein the automatic is connected and the kerberos protocol with the adjacency router according KDC and corresponding router marks and is interactive, so two ends to obtain the new shared random key system. An of the continuity and network security of key.
Brief description for drawings
Is further in detail invention to the invention claims a light of the auxiliary digital: Digital 1) is provided with a oxide end-to-end symmetrical authentication configuration schematic; drawingsDigital 2 kerberos is safenet; theDigital is 3 to apply the mis-plug preventing the model of kerberos cooperation mode,Digital 4 is in network networking device for configuring method and processing current of schematic positive symmetrical authentication.
Embodiments of the invention detailed description edges of the present invention best the auxiliary shape, wherein detailed description best embodiment of this invention.
Shown the digital 2) is Kerberos safenet model, Kerberos end of the authentication is designed to the support of network resource, comprising the same to the secret key system, Kerberos based on third-party capable of trust to a user service and execution safety certification. Shown and a digital 2, the third party of the trust a switch density a standard (DES) overlapped the double-seal algorithm filled with density and authentication is a key distribution centre 4, Kerberos service data. Kerberos with two short characteristics: (1) Kerberos so each to know for user server and password by Kerberos client entity 3, which is claim know of the user server and password on each application server S1, S2 S3, an alarm with each safety server alternating. (2) Although for symmetrical password mechanism, and password the circumference with an output in a network, comprising assured security system by a perfect message interaction mechanism.
Halogen-free low-smoke protocol message is interaction between S1 server, S2, S3 and KDC. The full network based on client/server side model 3, wherein the heating requests a client system for sending. <img Wi= the position " 89” he= " 17” file= of A20041000938400081.tif of img-format= of tif of/> represents in one or multiple protocol is message interaction.
Shown the digital 3 to apply the mis-plug preventing the model of kerberos cooperation mode, the invention, video and each router R1, R2, R3 is a Kerberos client, systems according to any kerberos two short characteristics of teeth and earlier, only need of for user server and password and router, 4 and alarm via the key distribution centre with an router via alternating and dynamic gain of random sharing password. At the same time, regular 4 and adjacency router time kerberos is interactive with a key distribution centre of the router, the gain random key, very rod is realized dynamic updating symmetrical authentication key the safety function of the router.
The invention is different from and each wire connection and a peer entity viewpoint; each router is a peer entity, obtaining secret key and router through kerberos, the router related protocol is kerberos to obtain, and same adjacency router interactive a random key, reduced the maintenance to updating with giant load of each protocol end-to-end passwords branches enormously, only needed trigger router for obtaining the integral condition random keys are connected Kerberos, simultaneously with realizes the dynamic updating authentication key safety function, large around the receiver router of safety. Wherein the network device authentication with good function of automatically safety.
Digital 4 is in network networking device for configuring method and processing current of schematic positive symmetrical authentication, and 4 in a light of the auxiliary digital the specific configuring method and working process of this invention: (1) And integral condition kerberos user (be on the router router mark) and (password ensuring consistency between datum with user server and password according to KDC database server and deposited consistent elements), and router's mark is in network.
(2) And the KDC server address on the router, and when kerberos module access KDC and router server address used.
(3) And the router is kerberos to consult the sharing cipher to different adjacency router to the. A with multiple and router to the end, a conducting Biao Quantum and router information according to the wire (adjacency router's a knowledge), a: ofkerberos id 1 peer 1.1.1.1 kerberos id 2 peer 10.1.1.3(4) according to the local set, and end-to-end symmetrical authentication password the routing module, module MPLS VPN or and module, one of claim the end-to-end are connected and authentication router's Biao Quantum, Biao Quantum for selecting according to router's is Biao Quantum; and local ospf flowing module and a router in some interface webpage recognizes and 10.1.1.3's adjacency router provided with a and end-to-end symmetrical safety certification: protocol ospf authentication-key kerberos id 2(5) switch are routers' kerberos module, a time connected and a on the kerberos protocol is interactive with KDC and corresponding router Biao Quantum adjacency router of the kerberos module, so two sides of the straight KDC assignment for sharing random key system.
(6) And the lower support router dynamic continuous authentication the password, and the kerberos timer, the timer overtime, wherein the automatic is connected and the kerberos protocol with the adjacency router according KDC and corresponding router marks and is interactive, so two ends to obtain the new shared random key system. An of the continuity and network security of key. The method comprises the supporting network management provide manual trigger local router for obtaining the new shared random key system.
Is overlapped status of the switch, comprising kerberos-based and solution for security and dynamic authentication, network and administrative personnel's the load of reducing, wherein the need to change the protocol the passwords, only need to gain a random sharing system key is a trigger kerberos module, wherein each set key module and kerberos mark with needed, wherein the straight change the automatic key. Pulse wherein the supporting the dynamic regular, authentication of strengthened the receiver router of safety, wherein the network device authentication with good function of automatically safety.
Although for best embodiment and attached shape of emitter target is claimed); the domain's a can provide: understandIt is not separated from a claim spirit and range of the invention and extends; each alternatives, wherein and are arranged. Therefore, the invention is not to limit the content to the best embodiment and attached digital publicize.
1 sheet
Sheet 1
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO2008043289A1 | Cited by | World Intellectual Property Organization (WIPO) | Search report |
| CN102025748A | Cited by | China | Search report |
| CN103177209A | Cited by | China | Search report |
| CN112636913A | Cited by | China | Search report |
| CN106612190A | Cited by | China | Search report |
| CN103093131A | Cited by | China | Search report |
| CN102711110A | Cited by | China | Search report |
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 200410009384 | China | A | |
| CN2004109384 | – | – | – |
Numbers
- Publication
- 1599312
- Publication, DOCDB
- 1599312
- Publication, EPODOC
- CN1599312
- Application
- 10009384
- Application, DOCDB
- 200410009384
- Application, EPODOC
- CN2004109384
Titles2
- English
- Symmetric identification method in network combination of network equip ment and network combination method
- Chinese
- 网络设备组网中的对称认证方法和组网方法
Classification
- IPC, 4
- H04L9 00
- H04L9 32
- H04L12 28
- H04L29 06