Implementing IPsec

被引:0
|
作者
Keromytis, AD
Ioannidis, J
Smith, JM
机构
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The IP Security protocols are sufficiently mature to benefit from multiple independent implementations and worldwide deployment. Towards that goal, we implemented the protocols for the BSD/OS, Linux, OpenBSD and NetBSD(1) While some differences in the implementations exist due to the differences in underlying operating system structures, the design philosophy is common. A radix tree, namely the one used by the BSD code for routing purposes, is used to implement the policy engine; a transform table switch is used to make addition of security transformations an easy process; a lightweight kernel-user communication mechanism is used to pass key material and other configuration information from user space to kernel space, and to report asynchronous events such as requests for new keys from kernel space to a user-level keying daemon; and two distinct ways of intercepting outgoing packets and applying the IPsec transformations to them are employed. In this paper, the techniques used in our implementations are explained, differences in approaches are analysed, and hints are given to potential future implementers of new transforms.
引用
收藏
页码:1948 / 1952
页数:5
相关论文
共 50 条
  • [21] Validation IPSec devices
    Atanasovski, P
    COMMUNICATIONS NEWS, 2004, 41 (09): : 21 - 21
  • [22] Impact of IPsec on MANET
    Rahman, Fatin Hamadah M. A.
    Au, Thien Wan
    2016 INTERNATIONAL SYMPOSIUM ON COMPUTER, CONSUMER AND CONTROL (IS3C), 2016, : 408 - 411
  • [23] IPSec协议分析
    耿航
    电子科技, 2014, 27 (08) : 142 - 143+146
  • [24] SSL or IPSec? Or both?
    不详
    COMMUNICATIONS NEWS, 2003, 40 (10): : 16 - 18
  • [25] IPsec WIT: The NIST IPsec Web-based interoperability test system
    Glenn, R
    Frankel, S
    Montgomery, D
    IEEE 9TH INTERNATIONAL WORKSHOPS ON ENABLING TECHNOLOGIES: INFRASTRUCTURE FOR COLLABORATIVE ENTERPRISES, PROCEEDINGS, 2000, : 147 - 152
  • [26] Parameterization of IPsec Framework for Security in the Smart Grid Interoperability Latency and Throughput IPsec Overhead
    Neumann, Victor
    Gomes, Christian Lyra
    Unsihuay-Vila, Clodomiro
    Fonseca, Keiko V.
    Tones, Pedro Rodrigues, Jr.
    2015 IEEE PES INNOVATIVE SMART GRID TECHNOLOGIES LATIN AMERICA (ISGT LATAM), 2015, : 780 - 785
  • [27] IPSec结构及其应用
    毛剑
    杨波
    中兴通讯技术, 2001, (05) : 26 - 30
  • [28] 浅谈IPSEC VPN体系
    刘丽丽
    段丹丹
    林业科技情报, 2007, (02) : 85 - 86
  • [29] IPsec VPN的设计
    冯向辉
    电信网技术, 2003, (04) : 46 - 48
  • [30] 浅析IPSec安全机制
    敦亚南
    王振兴
    郭润
    微计算机信息, 2005, (20) : 18 - 20