论文部分内容阅读
IP网络的安全是目前受关注度最高的安全问题之一。虽然IPsec可在网络层上有效地解决IP网络的安全问题,但是在动态IP环境下,IPsec链路就很难建立起来。同时,处在网络层上的IPsec并不能感知到上层的应用,因此它无法对特定的应用进行保护。提出基于安全SIP环境的IPsec通信,可在安全的SIP环境中,通信双方利用SIP消息来交换IP地址信息和应用信息,并将这些信息引入到IPsec中,在解决动态IP环境下IPsec链路建立的同时,也能通过不同的IPsec策略,对不同的应用进行保护。
IP network security is one of the most concerned security issues. Although IPsec can effectively solve the IP network security issues at the network layer, IPsec links are hard to set up under dynamic IP environment. At the same time, IPsec at the network layer can not sense the upper application, so it can not protect a particular application. IPsec communication based on secure SIP environment is proposed. In a secure SIP environment, both parties of communication use SIP messages to exchange IP address information and application information, and introduce these information into IPsec. In addressing the establishment of IPsec link in dynamic IP environment At the same time, different IPsec policies can be used to protect different applications.