期刊文献+

IKE与NAT协同工作研究与设计 被引量:3

Research and design for co-operation between IKE and NAT
下载PDF
导出
摘要 为解决因特网密钥交换协议(IKE)与网络地址转换(NAT)协同工作问题,通过解析NAT对IKE数据包的改动操作,分析了两者不兼容的表现及原因,采用浮动UDP端口号的方法,对NAT探测载荷内容进行2次HASH运算,并依据上述方法给出了使二者协同工作的详细设计。根据设计中对原有方案的改进,给出了设计的安全性分析。 Research on co-operation between internet key exchange (IKE) and network address translation (NAT) is done. Through analysing the operation on IKE packages by NAT and analyzing incompatible manifestations and reasons, the methods of floating UDP ports are adopted, and NAT detecting payloads are verified two times by HASH calculation. According to changes made by the design, security analysis is proposed on it.
出处 《计算机工程与设计》 CSCD 北大核心 2005年第6期1551-1553,1556,共4页 Computer Engineering and Design
关键词 因特网密钥交换协议 NAT穿透 UDP端口 IKE NAT traversal UDP port
  • 相关文献

参考文献6

  • 1Harkins D, Carrel D. The intemet key exchange (IKE)[S/OL]RFC24091998.11 [EB/OL] http://www. faqs.org/rfcs/rfc2409.html.
  • 2William Stallings. Cryptography and network security: Principles and practice [M]. Second Edition. 北京:清华大学出版社,2002.421-440.
  • 3Srisuresh P, Egevang K. Traditional IP network address translator (traditional NAT) [S]. RFC3022, 2001.1 [EB/OL] http://www. faqs.org/rfcs/rfc3022.html.
  • 4Doraswamy N Harkins D.IPSec:新一代因特网安全标准[M].北京:机械工业出版社,2000.63-81.
  • 5Huttunen A, Swander B. UDP encapsulation of IPSec packets[EB/OL] .http://www. ietf.org/proceedings/03nov/I-D/draft-ietf-ipsec-udp-encaps-06.txt.
  • 6Kivinen T, Swander B, Huttunen A. Negotiation of NAT-traversal in the IKE [EB/OL].http://www. ietf. org/proceedings/03nov/Ⅰ-D/draft-ietf-ipsec-nat-t-ike07.txt.

同被引文献27

引证文献3

二级引证文献7

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部