摘要
IKEv2作为IKE的替代者极大地增强了IPSec VPN网关之间隧道建立过程的安全性。但IKEv2和IKE一样都不能在动态IP环境下进行密钥交换。介绍了IKEv2的协商过程,在此基础上讨论了文中提出的动态IP环境下IKEv2扩展方案的设计与改进。经过改进的扩展方案可以很好地适应动态IP环境下的协商过程,扩大了IKEv2的应用范围。
As a replacer of IKE, IKEv2 enhances the safety of the procedure of establishing the tunnel between IPSec VPN gateways greatly. But not only IKE but also IKEv2 can not proceed the key exchange with dynamic IP address. First introduces the negotiation procedure of IKEv2, then discusses the design and realization of IKEv2 extended scheme with dynamic IP address in detail on the base of standard IKEv2.
出处
《计算机技术与发展》
2008年第12期162-165,共4页
Computer Technology and Development
基金
江苏省自然科学基金项目(BK2004039)