为了实现对变化的Age域值的签名和验证,利用可净化签名技术提出一种新的开放式最短路径优先(OSPF)路由协议安全保护机制.改进了可净化签名方案,结合其弱透明性的安全属性,并将其用于保护OSPF协议路由信息的安全.分析结果表明,所提的OSPF协议安全机制能有效抵制最大年龄(MaxAge)攻击和早熟MaxAge攻击.
In order to sign the vary age value and check its verification. A new secure protection mechanism for open shortest path first (OSPF) routing protocol is proposed through utilizing the sanitizable signature scheme. Enhanced sanitizable signature schemes, combines with the security property of weak transparence on the sanitizable signature algorithm,to protect the routing massage on the OSPF protocol. Security analysis shows, the proposed OSPF protocol can avoid the MaxAge attack and premature MaxAge attack.