计算机与现代化 ›› 2013, Vol. 1 ›› Issue (2): 90-93.doi: 10.3969/j.issn.1006-2475.2013.02.022

• 信息安全 • 上一篇    下一篇

一种基于防火墙实现数据包加密与解密的自主式主机接入控制方法

张雪峰   

  1. 广州番禺职业技术学院,广东广州511483
  • 收稿日期:2012-09-21 修回日期:1900-01-01 出版日期:2013-02-27 发布日期:2013-02-27

An Autonomous Access Control Method of Implementing Data Packet Encryption and Decryption Technology Based on Firewall

ZHANG Xue-feng   

  1. Guangzhou Panyu Polytechnic, Guangzhou 511483, China
  • Received:2012-09-21 Revised:1900-01-01 Online:2013-02-27 Published:2013-02-27

摘要: 提出一种通过防火墙实现数据包加密与解密的自主式主机接入控制方法,它利用NDIS过滤驱动技术实现个人版防火墙功能,易于在高低端网络环境中实现主机的接入控制。这种接入控制方法具有通用性好、安全性高、可控性强和扩展性好的特点,其目的是当主机接入时阻止非法(未授权)主机接入安全内网,减少丢包现象,提高系统转发速度。实验表明了该方法的有效性。

关键词: 加密技术, 接入控制, 包过滤, 自主式切换, 网络驱动程序接口规范, 数据包识别

Abstract: The paper presents an independent host access control method to realize packet encryption and decryption based on firewall. It realizes personal firewall function using NDIS filter driver technology, and it is easy to realize the access control in high performance or simple network environment. The access control method has good universality, high safety, strong controllability and good scalability characteristics, and its purpose is to prevent illegal (unauthorized) host access security network, reduce the packet loss, and improve the system of transfer rate when the host access network. The experimental results show that this method contributes to improve the stability of system and reduce the illegal access during the encryption and decryption process.

Key words: encryption technology, access control, packet filtering, automatic switchover, network driver interface specification, data packet recognition