Parts easy to attack in the system are lan and communication link , which need to take link encrypting and point - to - point encrypting 系統(tǒng)易受攻擊的環(huán)節(jié)是局域網(wǎng)與通信鏈路,需采取鏈路加密和端到端加密措施。
Terrestrial trunked radio - security - synchronization mechanism for end - to - end encryption endorsement of the english version en 302109 v1 . 1 . 1 2003 - 10 as german standard 地面中繼無線電.安全.端到端加密的同步機制
Coinpe with talihonal analog tnulking system , tetra system is apter to boplemen digltal encrypon of speech and data , but system securiiy is unable to depertd sdriply on enctwon . from the point of view of the b1lbrmation system security arehithebe , the author classified and concltuled the tetra system seeurity and wuced sytw security bo the wts of thnd analysis , security requirements , security sehaces and security mangemen etc . 111e mechbosm of authentication , tem1ina enable and disabq air intn encrypion , end - bend encmption led in tewh is the key ler in this n to the security question of practical application , the re1evant wt w and m are provided too 但是系統(tǒng)安全不能單純依靠加密來保證,作者從信息系統(tǒng)安全體系的角度,對tetra系統(tǒng)安全進行了分類歸納,從風險分析、安全需求、安全服務(wù)、安全管理等方面對tetra系統(tǒng)安全體系進行了閘述,并對tetra系統(tǒng)中主要應(yīng)用的鑒權(quán)、終端激活禁用、空中接口加密、端到端加密等安個機制進行了重點研究,同時針對實際應(yīng)用中出現(xiàn)的安全性問題提出了解決方法。
W is a digiul trunkin mobile cominunhaon system based on mma forhnology it offers group call diw w m wion ( dmo ) , duplex phone tall , padri data sehece , short data service and so on . tetw supports air interface and end - bend encrypon . tem is not only a fit private system for dispateh cominedcation of the polieq fire servce " w ha wtport , city tiwhc eto , but also for ule project reqthements of the public tw communication system Tetra是一種基于時分復(fù)用( tdma )技術(shù)的數(shù)字集群移動通信系統(tǒng),它可以提供組呼調(diào)度、脫網(wǎng)直通( dmo ) 、企雙工電話、分組數(shù)據(jù)服務(wù)、數(shù)據(jù)短信息服務(wù)等業(yè)務(wù),支持空中接口加密和端到端加密功能,既適合公安、消防、機場、鐵路、城市交通管理等專業(yè)部門調(diào)度指揮專用,也可滿足社會共用集群網(wǎng)的設(shè)計要求。
Based on the analysis of relatively mature network security technology that can be introduced by sip , by the means of improving and applications , the article realizes tls hop - by - hop encryption , s / mime end - to - end encryption mechanism , improved http digest authentication , s / mime end - to - end signature mechanism and so on 在分析現(xiàn)今可以借鑒的用來對sip通信進行保護的相對比較成熟的網(wǎng)絡(luò)安全技術(shù)的基礎(chǔ)上,通過改進和應(yīng)用,實現(xiàn)了包括tls逐跳加密, s / mime端到端加密等的加密機制以及改進的http摘要認證, s / mime端到端簽名等的身份鑒定機制。
Secondly , some encryption algorithms are introduced , with the analysis and comparison for these encryption algorithms , the author designs an appropriate project to accomplish the end - to - end encryption . thirdly , this paper accomplish the design of an encryption scheme which combining the strongpoint of the rsa algorithm and the idea algorithm . the main process is as following : first , input the digital signal to the encryption device , and then the digital signal exclusive or with the keying sequence which is generated by key stream generator ( ksg ) and the ksg is based on the idea encrypting and deciphering algorithm , the secret key synchronization is also studied 本課題主要研究的內(nèi)容是數(shù)字集群通信系統(tǒng)加密機制的研究,首先介紹了數(shù)字集群通信系統(tǒng)的安全保密機制,講述了單向和雙向鑒權(quán)的過程、單呼和群呼的空中接口加密過程及其密鑰的選用和管理,特別介紹了端到端加密;然后介紹了幾種常用的加密算法,通過分析其優(yōu)劣,提出了端到端加密的解決方案;最后完成了基于rsa算法和idea算法的數(shù)字集群通信系統(tǒng)加密方案的設(shè)計,其具體過程為將經(jīng)過數(shù)字信號送入加密器里,和以idea加密算法為基礎(chǔ)設(shè)計的密碼流發(fā)生器( ksg )產(chǎn)生的密碼序列進行加解密運算,并且研究了此加密過程的密碼同步問題。