节点文献

分布式虚拟专用网关键技术的研究——Internet密钥交换模块的设计与实现

【作者】 刘军

【导师】 袁宏春;

【作者基本信息】 电子科技大学 , 计算机应用, 2004, 硕士

【摘要】 IKE(Internet Key Exchange)协议是IPSec(IP Security) 协议簇的重要协议之一,负责动态协商和管理IPSec SA(Security Association , 安全关联)。论文主要研究了协议的详细内容、实现机制及协议本身存在的优缺点,并具体实现了IKE协议的主模式和快速模式。首先介绍了VPN(Virtual Private Network,虚拟专用网)技术,比较了传统虚拟专用网与分布式虚拟专用网(DVPN)的差异和各自的特点,同时介绍了目前流行的VPN关键技术。在分析IPSec协议的基础上,指明IKE协议在其中的地位和作用。其次,论文深入分析了IKE协议,包括IKE协议的组成,IKE协商的过程,IKE消息的格式及IKE协议的安全性,并在此基础上提出了一个可行的IKE实现方案,给出了一个全新的模块架构。然后,描述了该方案的各个模块的设计思想和功能划分,并对相关的主要数据结构和流程进行了介绍。同时深入分析了WINDOWS系统下应用程序与核心层通信的消息机制。最后,对IKE密钥交换模块进行了测试,分析了测试结果,并提出了可能的改进方案;论述了IKE功能的扩展和IKE今后的发展。论文的主要工作在于编程实现了IKE的主模式和快速模式,为IPSec提供了动态的SA,使VPN系统更加完善和安全。

【Abstract】 IKE protocol, which is responsible for the dynamic negotiation and management of IPSec SA, is an essential element of the IPSec protocol family. The thesis investigates the details of protocol content, the mechanisms of realizing the key exchange, as well as the pros and cons of the protocol itself. The thesis provides a practical mechanism to realize the Main Mode and the Quick Mode of IKE protocol.The thesis first introduces the technology of VPN. The concept and the design of the distributed VPN are described. The differences and their characteristics of the traditional VPN and the distributed VPN are then compared. Essential VPN technologies currently being deployed broadly are presented. On the base that IPSec protocol has been analysed, the status and action of IKE protocol in it is presented. The thesis then provides in-depth analysis of IKE protocol, including components of the protocol, the negotiating process of IKE, the format of IKE messages, and the security of the protocol. Based on the existing protocol, a new practical mechanism for realizing the IKE, as well as a new mode, is proposed. The design principles and the functionalities of each component are then illustrated. The main data structure and the procedures are also discussed. Meanwhile, the thesis provides a complete analysis of the message mechanism under Windows system, which describes how the application communicates with the kernel. The thesis finally examines the components for secret key exchange in the IKE, analyses the examination and brings forward a proposal. Then the expansion of functionalities and future development of IKE are discussed.The main achievement is that the thesis provides a group of program to realize the Main Mode and the Quick Mode of IKE protocol. Dynamic SAs have been provided for IPSec, and make the VPN system more perfect and safe.

  • 【分类号】TP393.08
  • 【下载频次】119
节点文献中: 

本文链接的文献网络图示:

本文的引文网络