The realization includes establishing and managing security association database in Linux kernel, developing PF_KEY socket interface and PF_KEY message, and designing the state machines of IKE main mode and IKE quick mode. 包括如何在内核中创建和管理安全关联数据库,如何实现PFKEY套接字接口和PFKEY消息,如何设计IKE协议的主模式和快速模式的状态机等等。
The second part is implementation of security extension Embedded Linux kernel and of General Security Interface. 二是安全增强的嵌入式Linux内核实现以及通用安全接口的实现。