摘要
在Internet所使用的TCP/IP协议中,网络层IP地址同时代表了主机标识符和定位符,使得IP地址无法支持主机移动性与多宿主性,更加无法保障用户之间的可信任性。为了解决这一系列问题,文章深入研究了主机标识协议(HIP)的体系结构。该体系通过主机标志层来标志连接终端,加强了安全性和可移动性,满足了人们对保密通信和移动通信上的要求。文章基于ARM嵌入式系统,提出以透明网桥为载体架设防火墙过滤HIP包,达到对一个网段进行网络安全防范的目的。
From de prospective of TCP/IP protocol in Internet,the IP address,which lies upon the network layer,represents the host identifier and locater simultaneously.Such design of the IP address correspondingly sets barriers to the mobility of a single host as well as the implementation of the multi-homed host;furthermore,it fails to provide the guarantee of credence between users.With the advent of Host Identity Protocol(HIP) architecture,which strengthens the security and authentication in the network,in the problems described above could be well solved.HIP connects hosts by means of the identifier of the host identity layer,which enhances security of hosts along with the mobility;meanwhile,it satisfies the demands for secure communication and mobile communication.This paper,based on ARM embedded System,utilizes transparent bridge to filtrate HIP packets,which finally achieves the purpose of security defense in a network segment.
出处
《信息网络安全》
2012年第1期53-57,共5页
Netinfo Security