作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2006, Vol. 32 ›› Issue (5): 102-103,182.

• 网络与通信 • 上一篇    下一篇

虚拟专用网组策略管理模型研究

贾培,曹 斌,刘积仁   

  1. 东北大学信息科学与工程学院,沈阳 110004
  • 出版日期:2006-03-05 发布日期:2006-03-05

Research on Group Security Policy Based Management Architecture for Virtual Private Network

JIA Pei, CAO Bin, LIU Jiren   

  1. School of Information Science and Technology, Northeastern University, Shenyang 110004
  • Online:2006-03-05 Published:2006-03-05

摘要: 针对大规模虚拟专用网络中安全隧道管理的复杂性,提出了一种基于组策略的管理模型。通信实体按其安全需求聚合为不同的安全组,组策略以抽象方式定义组内成员间通信的安全保护机制,设备之间的隧道连接关系则通过对组策略的扩展自动生成。模型实现了对全网VPN 设备的统一管理,有效减轻了VPN 的管理负担,具有良好的扩展能力。

关键词: 虚拟专用网;安全隧道;组策略;安全组

Abstract: Group policy based management architecture is proposed to solve complexity problem of security tunnel management in large-scale VPN network. In this architecture, communication entities are aggregated into different security groups, and group policy is used to regulate security protection mechanism for communications among group members. For each VPN device, tunnel relationships are computed automatically via extension of corresponding group policy. This architecture is both efficient and scalable, and is supposed to have promising perspective

Key words: VPN; Security tunnel; Group policy; Security group