摘要
IPSec协议的一种实现模式是采用IPSec网关间隔各个网络段,通过网关的策略配置,满足安全通信需求。然而,策略交叉会导致破坏安全需求的信息回流,拆分策略是避免信息回流的有效方法,但拆分过细,会引发额外的密码计算。提出一种带冗余策略的IPSec网关的分布式配置方法,在自动分布式生成无冲突的IPSec策略集基础上,引入冗余策略以减少IPSec网关的密码计算负荷。模拟实验验证了这种方法的可行性。
An application scenario for IPSec is to partition a network by IPSec gateways.The security requirements are implemented by IPSec policies between gateways.The overlapping tunnels may lead network traffic looping and introduce policy conflicts.h needs policy cuts to avoid those conflicts.However the too fine policies may lead many cryptology computations.In this paper,a distributed gateway configuring method with redundant policy,named DistlPSecR is proposed,to reduce the time-cost computation.We have conducted simulated experiments to validate the proposed method.
出处
《计算机工程与应用》
CSCD
北大核心
2009年第3期106-108,共3页
Computer Engineering and Applications
基金
广东省科技计划(No.2005B10101024)