要对网络体系做出重大调整,在新的协议设计之初将网络安全问题考虑在内越来越成为安全研究领域的共识.本文在国家“973”项目“一体化网络体系”的基础上,提出以具备自验证功能的地址结构实现端节点标识符,并在此基础上设计了一种新型接入机制,给出了相应的协议流程和协议格式,有效保障了“一体化网络体系”中信息源的真实性.最后使用SVO形式化逻辑对其安全性进行了详细的证明.
Making significant adjustment to the network architecture and including the security requirement at the beginning of the new architecture design is becoming a common view of the computer networking domain. Based on the "973" project "Universal network architecture", we use self-certifying address structure as the endpoint identifier and design a new access authorization mechanism. The corresponding protocol flow and protocol format were presented in this paper. Finally, the authors study the seourity of these new idea using SVO logic and find that this new architecture successfully guarantees authenticity of IP packer's sonrce address.