• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

计算机工程与科学 ›› 2025, Vol. 47 ›› Issue (10): 1779-1786.

• 计算机网络与信息安全 • 上一篇    下一篇

基于路由接入的IPSec实体动态自组网解决方案研究

罗晋,梁嬿良,陈洋,赵祺   

  1. (中国电子科技集团公司第三十研究所,四川 成都 610041)
  • 收稿日期:2024-04-22 修回日期:2024-06-25 出版日期:2025-10-25 发布日期:2025-10-28
  • 基金资助:
    四川省科技计划(2022YFG0172)

A new dynamic ad-hoc network solution for IPSec entities based on routing access

LUO Jin,LIANG Yanliang,CHEN Yang,ZHAO Qi   

  1. (No.30 Institute of CETC,Chengdu 610041,China)
  • Received:2024-04-22 Revised:2024-06-25 Online:2025-10-25 Published:2025-10-28

摘要: 随着IPSec在网络层加密传输中应用日益广泛,其端到端特性在大规模组网应用中组网效率低、配置运维难的问题也逐渐显现。目前行业内提出的主流解决方案能够一定程度缓解上述问题,但均存在一定的局限性。通过对IPSec SPD和SAD的建立机制以及路由接入技术进行深入研究,挖掘二者相互融合的可能性,最后提出一种新的IPSec实体动态自组网解决方案,该方案能够有效提高IPSec实体在大规模组网应用中的自组网效率,降低配置运维保障的压力。

关键词: IPSec实体, 动态自组网, 解决方案, 路由接入

Abstract: With the increasing popularity of IPSec in encrypted transmission applications at the network layer, its end-to-end characteristics have gradually exposed problems such as low networking efficiency and difficulty in configuration, operation, and maintenance in large-scale networking applications. Currently, the mainstream solutions proposed in the industry can alleviate the above problems to a certain extent, but they all have certain limitations. This paper conducts in-depth research on the establishment mechanisms of IPSec SPDs and SADs, as well as routing access technologies, explores the possibility of integrating them, and finally proposes a new dynamic self-organizing network solution for IPSec entities. This solution can effectively improve the self-organizing efficiency of IPSec entities in large-scale networking applications and reduce the pressure of configuration, operation, maintenance, and support.

Key words: IPSec entity, dynamic ad-hoc network, solution, routing access