研究移动互联网络安全以及适合移动环境的密钥管理机制是当前安全领域研究的热点问题.本文在综合研究现有移动安全方案的基础上,以嵌入主机标识的方法,对目前Internet中最为流行和广泛使用的网络密钥管理协议——因特网密钥交换协议第2版(IKEv2)进行了扩展,使其符合新型移动环境的安全隧道建立和管理要求.结果分析发现,利用本文提出的方法确保移动IP安全,比其他传统方法具有更高的切换效率.
Research that focuses on securing mobile internet and developing mobile environment suitable key management protocols, has attracted more and more attention. This paper analyzes and compares the advantages and limitations of existing mobile security protocols, and then proposes a novel way to extend IKEv2 for mobility support. This mobility extension introduces the concept of host identifier to IKEv2 and degrades the difficulty of SA management in mobile networks. The protocol proposed on this paper could be used to secure mobile networks in a more efficient way.