...
首页> 外文期刊>Annual review of communications >Security and Privacy with IPv6
【24h】

Security and Privacy with IPv6

机译:IPv6的安全性和隐私

获取原文
获取原文并翻译 | 示例

摘要

All end-to-end security models today inherently imply security above the transport layer. PGP S/MIME and SSL secure higher layer objects and hand them down to the lower layers. In addition, link-layer security mechanisms ensure privacy on the physical communications link, hop-by-hop. IPSec in IPv6 implies security at the network layer. It complements the security mechanisms at the other layers and does not eliminate the need for them. Users are becoming increasingly mobile and are demanding increasing flexibility, making perimeter security (firewalls, etc) less effective for organizations. In a world where applications are increasingly developed as Web services and port tunneling techniques are well advanced, firewalls, once seen as critical to system security are increasingly perceived as having limitations [Singer, 2003] Business applications will benefit by taking advantage of the IPv6 security infrastructure. There is an implicit need here for confidentiality as well as authentication. While security mechanisms today provide for confidentiality of objects, data in transit (transport payload) as well as link layer encryption, there is nonspecific security mechanism at the network layer. The most important benefits for such a specific community are twofold. All sources of data can be authenticated and data confidentiality can be provided with the use of IPSec. Given that such a community most likely already has a specific PKI developed for its own use, deployment of IPSec with this PKI becomes simply a matter of integration of the two.
机译:当今所有的端到端安全模型都固有地暗示了传输层之上的安全性。 PGP S / MIME和SSL保护较高层的对象,并将它们交给较低层。另外,链路层安全机制逐跳地确保物理通信链路上的隐私。 IPv6中的IPSec意味着网络层的安全性。它补充了其他层的安全机制,并没有消除对它们的需要。用户变得越来越移动,并要求增加灵活性,从而使组织的外围安全(防火墙等)的效率降低。在当今世界,随着Web服务和端口隧道技术的不断发展,应用程序也越来越发达,曾经被视为对系统安全至关重要的防火墙越来越被认为具有局限性[Singer,2003年]商业应用程序将受益于IPv6安全性。基础设施。这里隐含了对机密性和身份验证的需求。尽管当今的安全机制为对象,传输中的数据(传输有效载荷)以及链路层加密提供机密性,但在网络层却存在非特定的安全机制。对于这样一个特定的社区,最重要的好处是双重的。可以对所有数据源进行身份验证,并且可以使用IPSec提供数据机密性。鉴于这样的社区很可能已经开发出了自己的专用PKI,因此使用此PKI进行IPSec部署仅是两者集成的问题。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号