摘要
IPSec协议中的IKE(Internet密钥交换协议)实现了在不可信网络通道上的密钥交换的安全机制。尽管IKE已成为IPSec协议的一部分,它仍然有一些缺陷和不足,文章简单分析了传统IKE协议的缺陷,JFK密钥交换协议(包括JFKi协议、JFKr协议和内核安全),及其对传统IKE协议的改进。
IKE realizes the security mechanism of key exchange on the untrusted network channel.Although IK has become a part of IPSec protocol, it still has certain shortcomings and flaws.This paper briefly analyzes ticks off the shortage of traditional IKE protocol, discusses JFK protocol, including JFKi, JFKr and kernel security, and the modification on traditional IKE protocol. This paper can be used as a reference in the design of Internet key management.
出处
《信息安全与通信保密》
2008年第7期86-88,共3页
Information Security and Communications Privacy