节点文献
无线应用场景下IPSec的研究与实现
Research and Implementation of IPsec under Wireless Network Scenarios
【作者】 张朝伟;
【导师】 李伟生;
【作者基本信息】 北京交通大学 , 计算机软件与理论, 2007, 硕士
【摘要】 随着无线移动通信技术的发展,Wi-Fi手机成为了市场上的一大热点和亮点。Wi-Fi手机是在以无线局域网(WLAN)和因特网(Internet)为基础的未授权移动接入(UMA)网络环境下支持IP电话(VoIP)功能的手机。Wi-Fi手机最核心的问题就是安全性,尽管无线安全技术基本上可以保证WLAN部分的安全,但是对工作在UMA环境下的Wi-Fi手机而言,只有IPSec技术才能同时保证整个UMA通信网络的安全性。IPSec一直就是为Internet安全提供保障的最佳技术。论文将IPSec的保护范围从Internet延伸到WLAN部分,确保Wi-Fi手机的安全性。论文的研究目标是通过实现IPSec安全隧道保证Wi-Fi手机在UMA网络上的通信安全。IPSec是一个协议族,相关的技术主要有安全协议(AH/ESP)、密钥交换和管理协议以及加密和认证技术等。安全协议负责对传输信息进行封装,保证传输的安全性;密钥管理技术保证协商双方正确的建立安全关联;认证机制是为合法用户提供安全保障。论文主要做了以下几个方面的工作:1.学习和研究IPSec相关协议包括认证头协议(AH)、封装安全载荷协议(ESP)以及密钥交换协议(IKEv2),掌握了IPSec的体系结构和工作机制。2.分析和研究Linux2.6内核的安全框架和通信机制,构建了基于Linux2.6内核上的IPSec系统模型。3. IKEv2是密钥交换协议的最新版本,在深入研究该协议的基础上,设计并实现了密钥管理系统。4. EAP是一种非对称的可扩展的认证机制,在密钥管理系统中通过实现EAP-SIM认证方法,用于安全网关对手机用户的认证。实现了对手机用户的访问控制。论文在Linux2.6内核的手机系统上,通过实现以IKEv2为基础的密钥管理系统和EAP-SIM认证方法,在手机和安全网关之间建立IPSec隧道,为Wi-Fi手机在UMA网络上的通信提供了安全框架。论文的研究成果已在Wi-Fi手机产品中得到了应用,并取得了良好的效果。
【Abstract】 As the development of wireless mobility communication technology, Wi-Fi Phone becomes the hot and high light point in the mobile phone market. Wi-Fi Phone, which supports calling over IP function in Unlicensed Mobility Access (UMA) network environment, which is based Wireless Local Area Network (WLAN) and Internet, is a phone. The most important things of Wi-Fi Phone is security, though the WLAN part’s security can be guaranteed by the wireless security technology, to the Wi-Fi Phone working in UMA environment, only the IPSec can ensure the security of the whole UMA communication network. IPSec is always the optimal technology used for Internet. The paper extends the protection from Internet to WLAN part; that can make sure the security of Wi-Fi Phone.The target of the paper is to guarantee the security of Wi-Fi Phone, during communicating in UMA network, by implementing IPSec security tunnel. In order to do that, we need study the related knowledges of IPSec. IPSec is a serial of protocols including IPSec security protocols (AH/ESP)、Internet Security Key Exchange and Management Protocols、Encrpytion and Authentication techniques etc. Security protocols are used to encapsulate the informations to ensure the security; security management techniques are used to setup Security Association between the two negotiations; Authentication mechanism is to provide security protection for legal users.The paper mainly does the following servial parts works:First, Study and research IPSec related protocols including Authentication Header protocol (AH)、Encapsulating Security Payload protocol (ESP) and Internet Security Key Exchange protocol version 2 (IKEv2), to master the architecture and working mechanism of IPSec.Second, Analysis and research the security frame and communication mechanism of Linux2.6 kernel, and then design the IPSec system model. Third, IKEv2 is the latest version of Internet Security Key Exchange protocol, after deeply research the protocol,we design and implementation a security key management system.Fourth, EAP is an unsymmetric extensible authentication mechanism; we implement the EAP-SIM authentication method, which is used to authenticate phone users by security gateway, in security key management system. Implement the access
【Key words】 WLAN; IP Security; IKEv2; EAP-SIM Authentication; Linux2.6;
- 【网络出版投稿人】 北京交通大学 【网络出版年期】2007年 06期
- 【分类号】TP393.08
- 【被引频次】3
- 【下载频次】168