It analyses in details the interplay of all the components , the essential concepts such as security association , security association database and security policy database , the process of the package handling , the two security protocol encapsulating security payload and authentication header it concerns not only the regulations of the protocols themselves but also the implementation schemes 对于ipsec各个组件之间的交互关系、涉及的重要概念(安全关联、安全关联数据库和安全策略数据库) 、数据包处理过程、两个安全协议(封装安全载荷和认证头)的协议本身规范和一般实现方法都进行了较为详细的讨论。
The ability of keeping the ip packet ' s integrity , secrecy , authentication , data origination , anti - relay is discussed . the relationship of ipsec component authentication header ( ah ) , encapsulating security payload ( esp ) and ike ( internet key exchange ) is also talked about . this discussion of ipsec makes the impression that ipsec make ip layer security enough 论述了ipsec在ip报文的完整性、机密性、数据来源认证和抗重播等方面的能力, ipsec的基本协议? ?认证报文头( ah )和安全封装载荷报头( esp )与ipsec安全体系的其它组成部分如安全策略、加密和认证算法、密钥管理等如何合作,共同完成对ip报文的安全保护。