针对网络层安全隐患,IETF提出了IPSec安全规范。本文论述了IPSec体系结构和它 的几种工作方式以及现方法,分析了它提供安全服务的原理与机制。 关键词:IPSec;网络安全;认证头;封装安全载荷;安全联盟 Brief Analysis on IPSec Security Mechanism DUN Ya-nan WANG Zhen-xing GUO Run (Institute of Information Engineering, Information Engineering University,Zhenzhou Henan,450002 ) Abstract :IETF developes IP security specifics to solve the problem of network layer’s security.The Architecture,work models and implementation methods of IPSec are introduced,and the mechamism and principle of its security services are also analyzed. Key words :IPSec; network security; authentication header; encapsulating security payload; security association