工业网络中非标准VPN的安全技术研究
Study on non-standard VPN security technology in the industrial network
-
摘要: 针对在工业控制领域中,传统的监控与数据采集独立运转且很少配置安全管理的问题,利用N2N为工业网络之间的通信构建一条安全通道,使用数字证书对加入的节点进行身份验证,借助IKEv2协议实现节点之间的协商通信,并通过动态选择加密算法及通信密钥,有效提高了N2N在工业网络通信中的安全性.Abstract: Aiming at the problem that the traditional SCADA (supervision control and data acquisition) is operated independently with less configuration safety management in current industrial control field,a secure channel was constructed the communication between industrial network using N2N (a layer two peer-to-peer VPN), in which the joining node will be authenticated with digital certificates, and node communication between joint be realized with IKEv2 protocol. As a result, the security of N2N in industrial network communication will be improved efficiently and greatly through dynamic selective encryption algorithm and communication key.
-
-
[1]
Deri L,Andrews R.N2N:A layer two peer-to-peer VPN[J].LNCS,2008,5127:53-64.
-
[2]
张小波,程良伦. PKI在虚拟专用网络中的应用[J].计算机工程,2011,37(15):113.
-
[3]
寇晓蕤,王清闲.网络安全协议——原理、结构与应用[M].北京:高等教育出版社,2009.
-
[4]
邱司川,潘进,刘丽明. IKEv2协议的分析与改进[J].计算机工程,2009,35(15):126.
-
[5]
韩旭东,汤隽,郭玉东.新一代IPSec密钥交换规范IKEv2的研究[J].计算机工程与设计,2007,28(11):2549.
-
[6]
韩明奎,潘进,李波. 一种改进的IKEv2协议及其形式化验证[J].计算机应用研究,2010,27(2):707.
-
[1]
计量
- PDF下载量: 45
- 文章访问数: 776
- 引证文献数: 0