论文部分内容阅读
主机标识协议HIP使得主机身份有了独立的标识HI,它作为唯一代表主机身份的标识验证主机的身份。HIP中虽然给出了拥有HI的主机的身份验证和建立安全关联的方法,但并没有涉及主机和HI的映射关系。文中通过PKI注册生成主机和HI的对应关系的证书来保证主机身份和HI映射的权威性,同时扩展HIP的基本交换,将它用于验证证书的真实性,从而和HIP共同形成一套完整的网络安全体系。
The host identity protocol HIP enables the host identity to have an independent identity, HI, that authenticates the identity of the host as the only identity that represents the host identity. Although the HIP gives the authentication of the host that owns HI and how to establish the security association, it does not refer to the mapping between the host and the HI. In this paper, PKI registers to generate the host and HI correspondence to ensure the host identity and HI mapping authority, while expanding the basic HIP exchange, it will be used to verify the authenticity of the certificate, which together with the HIP to form a complete set Network Security System.