作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2009, Vol. 35 ›› Issue (9): 166-168. doi: 10.3969/j.issn.1000-3428.2009.09.058

• 安全技术 • 上一篇    下一篇

基于IPSec的网络安全系统的分析与设计

金尚柱,彭 军,杨治明,游明英   

  1. (重庆科技学院电子信息工程学院,重庆 400042)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2009-05-05 发布日期:2009-05-05

Analysis and Design of Network Security System Based on IPSec

JIN Shang-zhu, PENG Jun, YANG Zhi-ming, YOU Ming-ying   

  1. (College of Electronic Information Engineering, Chongqing University of Science and Technology, Chongqing 400042)
  • Received:1900-01-01 Revised:1900-01-01 Online:2009-05-05 Published:2009-05-05

摘要: 针对软件加密解密时发送和接收数据包速率较低的问题,利用IPSec协议和密码卡相结合,提出一种高速、高性能和适应于各种安全需求的网络安全系统,包括标准IPSec的本地化改造,ESP协议和IKE协议自由使用密码卡上的专用算法等关键技术。测试和分析结果表明,该系统与软件加密系统相比具有比较明显的优势。

关键词: 网络安全, 保密数据传输, Internet密钥交换协议, 虚拟专用网络

Abstract: Aiming at encryption and decryption used by software sending and receiving data packets at lower rate, an implementary scheme with the properties of high speed, high performance and flexibility to all kinds of secure system is proposed by exploiting IPSec protocol, including ESP and IKE which can freely use special algorithm within the crypto card. The implementary IPSec models and data transmission system are tested and analyzed. Results indicate that the system proposed is distinct advantage than software encryption system .

Key words: network security, secret data transmission, Internet Key Exchange(IKE) protocol, Virtual Private Network(VPN)

中图分类号: