Three ways of Network encryption and their comparison
There are three ways to encrypt network data:
Link encryption: Also known as online encryption, it is to encrypt a communication link between two network nodes, which is the main method used in current network security systems.
Node to node encryption: on the basis of link encryption, encryption and decryption protection devices are installed in intermediate nodes, so that nodes also encrypt nodes.
End-to-end encryption: Also known as off-line encryption or packet encryption, data is encrypted at the source node, and always exists in ciphertext form during transmission to the destination.
Comparison of three encryption methods:
Link encryption encrypts only data in communication links, but not data in network nodes; node to node encryption does not allow messages to exist in plaintext form in network nodes, and it has common weaknesses with link encryption: it requires cooperation from public network providers, modification of switching nodes in public networks, and addition of security elements or protection devices; End-to-end encryption, only after the message reaches the destination is decrypted, the disadvantage is that it can not hide the source node and destination node of the message, can not prevent ***.