期刊文献+

基于IPSec的虚拟专用网络密钥交换实现及其安全分析 被引量:2

Key exchange implementation and security analysis for IPSec based virtual private network
下载PDF
导出
摘要 本文研究了基于IPSec结构的虚拟专用网密钥交换的基本概念和原理 ,详细地阐述了通过一系列参数的协商在非安全的公共IP网络中建立安全通信的密钥交换机制 ,给出了基于Linux系统的客户机 /服务器VPN密钥交换的软件实现 ,对其安全特性作出了分析 ,指出其具有抗服务拒绝攻击、抗中间人攻击、抗连接插入攻击和防止窃听等安全性能 。 IPSec (IP security) is the de facto standard of implementing virtual private network on network layer, while key exchange and management mechanism is crucial for IPSec protocols. A through study on fundamental concepts and principles of key exchange for IPSec based VPN (virtual private network) is conducted and the details of the security key exchange mechanism on non-secure public IP based network through a set of parameters negotiation is illustrated. A software implementation of Client/Server model VPN key exchange upon Linux operating system is presented and its security performance such as anti-denial-of-service, anti-connection lijacking, anti-the man-in-the-middle attack and anti-eavesdropping etc. are analyzed. Finally the paper gives a prospective view of IKE (Internet key exchange) research.
出处 《东南大学学报(自然科学版)》 EI CAS CSCD 北大核心 2002年第4期551-557,共7页 Journal of Southeast University:Natural Science Edition
基金 国家"九五"科技攻关重点资助项目 (2 0 0 0 A3 2 12 )
关键词 IPSEC 虚拟专用网 IP安全协议 密钥交换 网络安全 Computer software Internet Network protocols Servers
  • 相关文献

参考文献7

  • 1[1]Steven Brown. Implementing virtual private networks[M]. New York: McGraw-Hill Companies Inc, 1999. 150.
  • 2[2]Kent S, Atkinson R. RFC2401M, Security architecture for the Internet protocol[S]. Nov 1998.
  • 3[3]Kent S, Atkinson R. RFC2402, IP authentication header[S]. Nov 1998.
  • 4[4]Kent S, Atkinson R.RFC2406, IP encapsulation security payload(ESP). Nov 1998.
  • 5[5]Maughan D, Schertler M, Schneider M, et al. RFC2408, Internet security association key management protocol(I SAKMP) [S]. Nov 1998.
  • 6[6]Harkins D, Carrel D. RFC2409, Internet key exchange[S]. Nov 1998.
  • 7[7]Orman H. RFC2412, The Oakley key determination protocol. Nov 1998.

同被引文献8

  • 1LAN MAN Standards of the IEEE Computer Society. Wireless LAN Medium Access Control (MAC)and Physical Layer(PHY) Specification. IEEE Standard 802.11 [S]. 1999 Edition.
  • 2Walker Jesse R. Unsafe at Any Key Size: An Analysis of the WEP Encapsulation. docz IEEE 802.11 -00/362[S]. Oct 27,2000.
  • 3Krawczyk H, et al. HMAC: Keyed-Hashing for Message Authentication RFC2104 [S]. Feb. 1997.
  • 4Maughan D, et al. Internet Security Association Key Management Protocol (ISAKMP) RFC2408 [S].Nov. 1998.
  • 5Harkins D. Internet Key Exchange RFC2409 [S].Nov. 1998.
  • 6Security Solution in Ericsson Wireless LAN System[Z]. White Paper, Ericsson Radio Systems 1999.
  • 7周贤伟.移动IP与安全[M].北京:国防工业出版社.2005
  • 8张贤德,李晓东,余祥宣.关于IPSec密钥交换的研究及实现[J].内蒙古农业大学学报(自然科学版),2002,23(3):103-107. 被引量:1

引证文献2

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部