节点文献

移动IPv6数据穿越防火墙问题的研究和实现

Study and Implementation on Problems When the Mobile IPv6 Data Through the Firewall

【作者】 崔佳

【导师】 陈蜀宇;

【作者基本信息】 重庆大学 , 计算机系统结构, 2009, 硕士

【摘要】 移动通信技术和Internet技术正在飞速的发展,各种功能强大的便携式终端层出不穷并越来越普及,随时随地都可以上网的移动IP技术成为未来的发展方向。1996年IETF就出台了移动IPv4,但是移动IPv4有很多的局限性。由此,建立在IPv6技术基础上的移动IPv6应运而生。移动IPv6充分利用的IPv6技术的优势,可以提供几乎无限的IP地址资源和更有保障的服务质量。支持移动IPv6的网络节点可以不更改任何配置就可以漫游到外地网络,而原有的通信也不会中断。由于网络安全问题的日益突出,防火墙也越来越普遍。但是移动IPv6现在和防火墙却并不兼容,由于转交地址和IPSec的使用,当移动IPv6数据穿越防火墙时会面临很多问题。本文首先介绍了IPv6和移动IPv6的基本概念和工作原理,包括移动IPv6的报文的格式,地址格式等。随后着重介绍了移动节点,家乡代理,通信节点被防火墙保护的几种情况下移动IPv6数据穿越防火墙时出现的各种问题,并分析了问题的原因。然后本文设计了一种采用非对称密钥对移动数据进行认证的解决方案,为此本文对防火墙和移动IPv6协议栈进行修改,给防火墙增加了移动认证模块,移动IPv6协议增加了一个移动认证报头,和公钥请求消息、公钥回复消息两个移动报头的选项,并对解决方案的工作过程做了详细介绍。接着是解决方案的实现和测试。论文介绍了Linux的netfilter/iptable机制,并在此基础上实现了防火墙的移动认证模块。然后介绍了开源的移动IPv6协议栈MIPL,对MIPL的源代码进行了分析,并对MIPL做了修改以支持上述解决方案。最后建立了一个实验环境对方案的实现进行了测试,结果表明,方案是可行的,移动IPv6数据可以顺利穿越防火墙。

【Abstract】 All kinds of powerful Portable Terminals are becoming increasingly popular with the rapid development of Mobile communications technology and Internet technology, which makes Mobile IP technology become the development trend of the future. IETF already showed mobile IPv4 in 1996, but now it has been developed Internet protocol of new generation-IPv6 since IPv4 has a lot of limitations. Mobile Ipv6 can provide unlimited IP address resource and better quality of services based on making the utmost of IPv6 technology. Support to the network nodes of IPv6 makes it possible for the roaming of Foreign Network without any configuration’s alteration and interruption of original communicationNowadays, firewall is more and more common since network security problems are increasingly serious, however, Mobile IPv6 is incompatible with firewall. Due to using care of address and Ipsec,we’re facing a lot of problems when Mobile IPv6 datum traverse the firewall.The paper firstly introduces the principle of IPv6 and Mobile IPv6 including IPv6 Header format and addressing architecture etc., and then lays emphasis on various problems and the analysis of the reasons when Mobile IPv6 datum traverse the firewall under several circumstances that mobile node, home agent and Correspondent Node are protected by firewall; and next brings out a solution scheme--- using Asymmetric-key technology to authenticate the Mobile data, as a result, firewall and Mobile IPv6 protocol are modified in this paper--- Mobile authentication has been added for firewall, and Mobility Authentication Header, Public-key Request message and Public-key Response message are added for Mobile IPv6 protocol---also the whole process of solution is introduced in detail; after that, implementation and testing of solution are expatiated: first,the mechanism of netfilter/iptable of Linux is presented briefly, and mobile authentication module is implemented based on that mechanism; second, open source Mobile IPv6 stack MIPL is introduced, then the analysis and modification for source code of MIPL are done in order to support the solution above; finally, test environment for the implement schema is built, results indicate that the proposed technology is feasible and Mobile IPv6 data can pass through the firewall.

【关键词】 移动IPv6IPv6防火墙MIPL
【Key words】 Mobile IPv6IPv6FirewallMIPL
  • 【网络出版投稿人】 重庆大学
  • 【网络出版年期】2009年 12期
  • 【分类号】TP393.08;TN929.5
  • 【被引频次】3
  • 【下载频次】107
  • 攻读期成果
节点文献中: 

本文链接的文献网络图示:

本文的引文网络