文档介绍:重庆大学硕士学位论文英文摘要IIABSTRACTVPN(Virtual work)is such a kind of technic that a work isbuilt in the work, thus the data can transmit in work through securedensification channel. IPSec(IP Security)is currently one of the main protocolsconstructing (SecurityAssociation)must be established and an agreementshould be reached on how to protect and exchange information and other public securitysettings before exchange data between two IPSec ( Key Exchange)protocol is the major part ofIPSec, responsiblefor the dynamic negotiation and managing SA. however, many disadvantages are stillexist in IKE, which will cause many problems in its security , efficiency plishment. Thus IKEv2 protocol and JFK(Just Fast Keying)protocol arebrought forward as the substitute for IKE to simplify protocol and resolve the problemsof the view of practical and simple and convenient, JFK protocol is chosen asthe research object of this thesis, which is safer , higher efficient and simpler than IKEprotocol. However JFK itself has some defects such as it hasn't realized PFS(PerfectForward Secrecy), and cannot plete non-state interaction etc. Based onthe detail analysis of JFK protocol, the thesis proposes some improvement program tomake JFKperfect while reserving its advantages. According to the analysis of JFK andconsulting current popular IKE protocol plishment program, this thesis bringsforth an improved JFK protocol plishment program, and introduces the mainfunction and realization method of each part, and validates the validity of improvementsand the feasibility plishment programthrough the experiment. The last part ofthis thesis is the introduction of some expansion functions of JFKprotocol, which arebrought forth to meet various operation requirements in different environment. Thebasic principles and how to realize in JFK of the expansion functions are simplyintroduced in the :IKE Protocol,JFK Protocol,Perfect Forward Secrecy,Denial Of Service重庆大学硕士学位论文1绪论1