信息网络安全 ›› 2016, Vol. 16 ›› Issue (11): 19-27.doi: 10.3969/j.issn.1671-1122.2016.11.004

• • 上一篇    下一篇

基于国密算法的安全接入设备设计与实现

李兆斌, 刘丹丹(), 黄鑫, 曹浩   

  1. 北京电子科技学院通信工程系,北京 100070
  • 收稿日期:2016-09-20 出版日期:2016-11-20 发布日期:2020-05-13
  • 作者简介:

    作者简介:李兆斌(1977—),男,北京,副研究员,博士,主要研究方向为信息安全、以太网链路安全加密;刘丹丹(1991—),女,河南,硕士研究生,主要研究方向为VPN技术、移动通信技术、密码技术;黄鑫(1993—),女,山东,硕士研究生,主要研究方向为测试技术、数据加解密;曹浩(1991—),男,湖北,硕士研究生,主要研究方向为SIP电话、Android系统前端开发。

  • 基金资助:
    北京市自然科学基金[416307]

Design and Implementation of Secure Access Device Based on Guomi Algorithm

Zhaobin LI, Dandan LIU(), Xin HUANG, Hao CAO   

  1. Communication Engineering Department, Beijing Electronic Science and Technology Institute, Beijing 100070, China
  • Received:2016-09-20 Online:2016-11-20 Published:2020-05-13

摘要:

为了解决电子政务系统移动终端安全接入问题,文章设计并实现了一个面向移动终端的安全接入设备。该设备基于IPSec VPN技术,主要实现通信隧道的建立、通信双方身份认证、保障数据的机密性和完整性等功能。文章基于Strongswan软件框架的再开发技术完成系统各个模块的功能。密码算法作为设备安全设计的核心,现在通用的密码算法已经不能满足信息安全需求,使用国密算法标准成为设备的必然选择。Strongswan只提供了国际通用算法,因此有必要使用硬件密码卡来实现设备对国密算法的支持。通过修改Strongswan的算法库和策略库将国密算法注册到Strongswan中,同时对其功能模块进行设计改进,最终实现一个基于国密算法的安全接入设备。文章最后搭建测试环境验证了系统的可行性。

关键词: IPSec VPN, 电子政务系统, 国密算法, 硬件密码卡

Abstract:

In order to solve the security access problem of mobile terminal in E-government system, this paper designs a security access device for mobile terminal. The device is based on IPSec VPN technology, mainly to achieve the establishment of communication tunnel, the two sides’ identity authentication, protect the confidentiality and integrity of data and so on. The implementation of the system is based on the redevelopment of Strongswan software framework to complete the function of each module. At the same time, as the core of the security design, the cryptographic algorithm has been unable to meet the information security requirements. And Guomi algorithm becomes a necessary requirement of the equipment. Strongswan only provides the international common algorithm, so it is necessary to use the hardware encryption card to realize the equipment to the secret algorithm support. The algorithm of Strongswan and the strategy library are modified to register the state secret algorithm into Strongswan. At the same time, the design of the module is improved to realize a secure access device based on the national secret algorithm. At last, this paper establishment of environment to verify the system function and availability.

Key words: IPSec VPN, e-government system, Guomi algorithm, hardware encryption card

中图分类号: