期刊文献+

ML-IKE:一种改进的卫星链路分层密钥分配协议 被引量:2

下载PDF
导出
摘要 传统的IKE协议不能适用于分层IPSec协议,为了解决卫星链路中基于PEP中间节点的TCP加速技术同端到端IP安全协议IPSec之间的矛盾,本文对传统IKE主模式和快速模式进行了扩展,提出了一种改进的分层密钥分配协议:ML-IKE。该密钥分发协议用于对两端节点和中间节点分别进行密钥交换,使得不同节点具有不同安全关联SA,而不同的SA分别对应分层IPSec中不同IP包字段,因此拥有不同安全关联SA的节点具有对IP包中不同数据段的权限。ML-IKE协议适用于分层IPSec,使得分层IPSec能够进行自动的密钥分发和更新。
出处 《信息网络安全》 2009年第3期40-43,共4页 Netinfo Security
  • 相关文献

参考文献1

二级参考文献17

  • 1KONG Jie-jun,GERLA M.Providing multi-layer security support for wireless communications across multiple trusted domains[R].[S.l.]:UCLA Computer Science Department,2003.
  • 2KENT S,ATKINSON R.Security architecture for the Internet protocol[EB/OL].(1998).http://www.ietf.org/rfc/rfc2401.txt.
  • 3ALLMAN M,DAWKINS S,GLOVER D,et al.RFC 2760,Ongoing TCP research related to satellites[S].2000.
  • 4AKYILDIZ I F,MORABITO G,PALAZZO S.Research issues for transport protocols in satellite IP networks[J].IEEE Personal Communications,2001,8(3):44-48.
  • 5BRAKMO L,PETERSON L.TCP vegas:end to end congestion avoidance on a global Internet[J].IEEE Journal on Selected Areas in Communications,1995,13(8):1465-1480.
  • 6FU C P.TCP veno:end-to-end congestion control over heterogeneous networks[D].Hong Kong:Chinese Univ Hong Kong,2001.
  • 7AKYILDIZ I F,MORABITO G,PALAZZO S.TCP peach:a new congestion control scheme for satellite IP networks[J].IEEE/ACM Transactions on Networking,2001,9(3):307-321.
  • 8BORDER J,KOJO M,GRINER J.RFC3135,Performance enhancing proxies intended to mitigate link-related degradations[S].2001.
  • 9HENDERSON T,KATZ R.Satellite transport protocol (STP):an SSCOP-based transport protocol for datagram satellite networks[C]//Proc of the 2nd Workshop on Satellite-Based Information Systems (WOSBIS'97).Budapest:[s.n.],1997.
  • 10BELLOVIN S.Transport-friendly ESP (or layer violation for fun and profit)[EB/OL].(1999).http://www.cs.columbia.edu/ ~smb/talks/tfesp-ndss/index.htm.

共引文献7

同被引文献16

  • 1KENT S,ATKINSON R.Security architecture for the Internet protocol[S].RFC2401,1998.
  • 2ZHANG Y, SINGH B. A multi-layer IPSec protocol[C].//Proc of the 9th USENIX Security Symposium. Denver,2000.
  • 3Harkins D,Carrel D. The Internet Key Exchange(IKE)[S]. RFC2409, 1998.
  • 4Kaufman C. Intemet Key Exchange(IKEv2) Pr0tocol[S]. RFC4306, 2005.
  • 5Lee, Kyesang.Intemet Key Exchange version 2 (IKEv2) protocol[R].http://seclab.cs.ucdavis.edu/-seminars/IKEv2.ppt,2006.
  • 6Andreas Steffen, IKEv2-based VPNs using StrongSwan[R]. LinuxKongress2009.http://www.strongswan.org.2009.
  • 7BORDER J,KOJO M,GRINER J.RFC3135,Performance enhancing proxies intended to mitigate link-related degradations[S].2001.
  • 8Zhan Huang and Xue-mai Gu.Design and Performance Analysis of CZML--IPSec for Satellite Networks.K.Li et al.(Eds):NPC 2007, LNCS 4672:277-286,2007.@IFIP International Federation for Information Processing,2007.
  • 9黄飞,许辉,吴诗其.基于PEP-IPSec实现卫星IP网的网络安全[J].计算机应用研究,2007,24(8):132-136. 被引量:8
  • 10Henderson,R.H,KatZ. Transport Protocols for Internet-Compatible Satellite Networks[J].IEEE Journal on Selected Areas in Communications,1999,(02):345-359.

引证文献2

二级引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部