A CPK-Based Security Scheme at Network Layer
Zhiyuan Xie, Junhui He, Shaohua Tang · 2009
A novel security scheme at network layer is proposed. It provides mutual authentication between the communication partners by adopting the effective combined public key (CPK) algorithm, which is an identity-based cryptosystem. And each outgoing packet can be digitally signed with CPK-based signature, which uses elliptic curve digital signature algorithm (ECDSA) and may offer equal security with a far smaller key size than RSA' s, to provide packet-level non-repudiation when necessary. In addition, the data transmitted over the network can be encrypted for better security via a symmetric or asymmetric cipher. Compared to similar network security solutions, the proposed scheme is easier to configure and more flexible. The experimental results show that the scheme owns better efficiency.