The realization includes establishing and managing security association database in linux kernel , developing pf _ key socket interface and pf _ key message , and designing the state machines of ike main mode and ike quick mode 包括如何在内核中创建和管理安全关联数据库,如何实现pf _ key套接字接口和pf _ key消息,如何设计ike协议的主模式和快速模式的状态机等等。