Research of Main Mode with Signature Authentication in IKE Protocol
Ruchuan Wang · Journal of Nanjing University of Posts and Telecommunications · 2007
It is inevitable that there are some security limitations in IKE protocol,because of its flexibility and complexity.After the mechanism of IKE is introduced,the two kinds of man-in-middle attack are analyzed.In order to defend the second one,some improvements are presented in the main mode with signature authentication.Moreover the conception of key-signature payload is provided.Finally,the paper makes a quantitative capability analysis on the whole.By combining with the open code of freeS/WAN,it modifies and adds some appropriate functions to integrate the idea of improvement into IKE.