Netinfo Security ›› 2016, Vol. 16 ›› Issue (11): 19-27.doi: 10.3969/j.issn.1671-1122.2016.11.004

• Orginal Article • Previous Articles     Next Articles

Design and Implementation of Secure Access Device Based on Guomi Algorithm

Zhaobin LI, Dandan LIU(), Xin HUANG, Hao CAO   

  1. Communication Engineering Department, Beijing Electronic Science and Technology Institute, Beijing 100070, China
  • Received:2016-09-20 Online:2016-11-20 Published:2020-05-13

Abstract:

In order to solve the security access problem of mobile terminal in E-government system, this paper designs a security access device for mobile terminal. The device is based on IPSec VPN technology, mainly to achieve the establishment of communication tunnel, the two sides’ identity authentication, protect the confidentiality and integrity of data and so on. The implementation of the system is based on the redevelopment of Strongswan software framework to complete the function of each module. At the same time, as the core of the security design, the cryptographic algorithm has been unable to meet the information security requirements. And Guomi algorithm becomes a necessary requirement of the equipment. Strongswan only provides the international common algorithm, so it is necessary to use the hardware encryption card to realize the equipment to the secret algorithm support. The algorithm of Strongswan and the strategy library are modified to register the state secret algorithm into Strongswan. At the same time, the design of the module is improved to realize a secure access device based on the national secret algorithm. At last, this paper establishment of environment to verify the system function and availability.

Key words: IPSec VPN, e-government system, Guomi algorithm, hardware encryption card

CLC Number: