摘要
在基于策略的互联网络中,一致性的安全策略系统(SPS)的存在是非常必要的.IETF建议的SPS体系结构采取完全分布式的处理机制.分析了它在实际使用中存在缺少策略一致性检查、低效的策略协商过程等问题,在原有结构的基础上,增加集中的安全策略管理机制,较好的解决了SPS存在的安全和效率问题.
The existence of security policy system (SPS) is very necessary in the policy -based networking. The structure of IETF SPS adopt completely distributed processing mechanism. In the paper, we mainly analyzed the insufficiency of IETF SPS in actual working, such as lacking coincidence check - up, inefficient policy conferring etc. At the same time, the concentrated security policy management mechanism is increased based on the structure of IETF SPS, which can resolve the security and efficiency problems SPS has in a certain extent.
出处
《湖北民族学院学报(自然科学版)》
CAS
2006年第2期151-154,共4页
Journal of Hubei Minzu University(Natural Science Edition)
关键词
安全策略系统
安全策略管理
一致性检查
策略协商
security policy system
security policy management
coincidence check- up
policy conferring