Research and application of encrypted data transmission based on IPSec

Shengbo Qu, Yulong Cheng, Xuesong Bai · 2023

In order to solve the security problem of data transmission between networks, Internet practitioners have been trying various solutions, trying to make data can be transmitted in multiple complex network environments, while security is also satisfied. The most classic solution is to use an encryption algorithm to encrypt and transmit data. The encryption algorithm includes international algorithms such as RSA[1]and AES[2]. There are also SM1[3], SM2[4]and SM4[4]in China to fill the vacancy of the encryption algorithm, but the above solutions are all aimed at encrypting the data itself. This article tries to solve the problem of data security transmission from another angle. Even if the data itself is not encrypted, it can still ensure that both the sender and receiver of the data can transmit the data safely. The idea of this article is to try to establish a proprietary encrypted channel at the sending and receiving ends of the data. Based on this encrypted channel, the security of data transmission can be guaranteed even though the data passes through multiple devices in the Internet environment. The data sender and receiver can base on the Site-to-Site[5]VPN[6]channel established by IPSec[7], cooperate with the domestic encryption algorithm, which not only ensures the security of the data, but also avoids the risk of using foreign algorithms, and realizes the encryption of the data packet during the transmission process. This method has the characteristics of safety and wide applicability, and can be used as a new idea for safe data transmission.

Read the paper · More papers on PaperTik