Internet key exchange ( ike ) is an important part of ipsec . it provides services of authentication , policy negotiation and key exchange Ike是ipsec协议集的重要组成部分,提供密钥协商、策略协商和身份认证的功能。
The emphases of ipsec are internet key exchange ( ike ) protocol and security policy system . whether ipsec is perfect and standard or not , it is according to the implementation of the two technologies 从ipsec协议族来看, ipsec的实现重点是internet密钥交换( ike )和安全策略系统,这两个技术的实现决定了ipsec实现是否完善和标准。
It pays a great attention to the internet security association and key management protocol ( isakmp ) and the internet key exchange ( ike ) based on isakmp , because the key management is always the most consequential part of any security systems 然后针对在安全系统中至关重要的密钥管理进行了重点分析,这其中包括了internet安全关联密钥管理协议,以及以它为框架在ipsec中实现的internet密钥交换协议,并且简单说明了在上述密钥管理协议中密钥信息的生成公式。
( 2 ) research on ipsec architecture the goal , function and construction of ipsec design ; the analysis on the two security protocols of ipsec ? ah and esp including security function , packet format , application mode and processing operations of each ; mainly of the security association ( sa ) and its two modes : transport and tunnel , the instrument on organizing and managing sas security association database ( sad ) , and that on managing security policies ? ? security policy database ( spd ) ; specific descriptions on internet key exchange ( ike ) ( 2 ) ipsec协议体系的研究给出了ipsec的设计目的、作用和组成;分析了ipsec的两种安全协议? ? ah和esp ,包括每种协议的安全功能、包格式、应用模式以及对数据包的处理过程;重点研究了安全联盟( sa )以及两种模式:传输模式和隧道模式,组织和管理sa的手段? ?安全联盟数据库( sad ) ,以及安全策略的管理手段? ?安全策略数据库( spd ) ;最后,对internet密钥交换( ike )进行了详细介绍。
The operating process of network cipher computer and kdmc are discoursed firstly , then the tcp / ip stack of linux is introduced , and an ipsec realization method with using a cipher card is put forward . triplex key system is adopted for internet key exchange ( ike ) . the database and other modules are also designed and implemented 论文论述了网络密码机和密钥管理中心的工作流程,接着介绍了linux下tcp / ip内核协议栈,提出了加密卡方案,采用了三重密钥管理体系实现了internet密钥自动交换,进行了中心数据库设计与实现,最后对其它模块进行了实现。
At first , this thesis describes the secure characteristics and mechanisms on the internet protocol security ( ip sec ) , also introduces the internet security association and key management protocol ( isakmp ) specified in rfc 2408 and the internet key exchange ( ike ) protocol specified in rfc 2409 for ip sec . secondly , it thoroughly analyzes the validities of the secure characteristics of the ike protocol based on the former formal analysis 本文首先论述了ipsec ( internetprotocolsecurity )安全特性和安全服务机制、支持ipsec的密钥管理协议isakmp ( internetsecurityassociationandkeymanagementprotocol )以及ike ( internetkeyexchange )协议,然后,从两个方面对ike协议进行了全面的研究。