首页> 外文会议>IEEE International Conference on Software Engineering and Service Science >IPSecOPEP: IPSec over PEPs architecture, for secure and optimized communications over satellite links
【24h】

IPSecOPEP: IPSec over PEPs architecture, for secure and optimized communications over satellite links

机译:IPSecOPEP:基于PEP的IPSec体系结构,用于通过卫星链路进行安全和优化的通信

获取原文
获取外文期刊封面目录资料

摘要

This paper presents a TCP/IP-based architecture (IPSecOPEP) to resolve the interoperability issue between PEPs (Performance Enhancing Proxies) and IPSec (Internet Protocol Security). Where this problem is due to the cryptographic protection of TCP header by IPSec ESP protocol, which prohibits TCP enhancing mechanisms to be performed by PEPs. The key idea of this solution is that IPSec devices can perform well as a bridge between end users and PEPs in such situations, because they can access to both TCP headers of original packets and IPSec headers of encrypted packets. By this way, IPSec devices can perform a simple mapping between original TCP headers and their corresponding IPSec headers to resolve the interoperability issue. In our proposed IPSecOPEP architecture, we add a new components to the standard TCP/IP stack for IPSec devices and PEPs proxies, to ensure cooperatively and transparently the interoperability between them, without affecting the security privacy and performance level in such situations. In fact, this solution doesn't need to exchange any secret information about IPSec-related security associations. Furthermore it doesn't imply the use of any additional headers to IPSec packets by the PEPs. However, IPSec devices should coordinate between end users and PEPs to ensure spoofing mechanism, to avoid slow start problem of a standard TCP. After that, PEPs can continue to apply other enhancing mechanisms over the satellite link. Hence, this solution presents a double advantages concerning both the security and the performance at once. Moreover, the components of this solution can be easily standardized, implemented, integrated and enabled, in IPSec and PEPs devices.
机译:本文提出了一种基于TCP / IP的体系结构(IPSecOPEP),以解决PEP(性能增强代理)和IPSec(Internet协议安全性)之间的互操作性问题。出现此问题的原因是IPSec ESP协议对TCP报头进行了密码保护,这禁止了PEP执行TCP增强机制。该解决方案的关键思想是,在这种情况下,IPSec设备可以很好地充当最终用户和PEP之间的桥梁,因为它们可以访问原始数据包的TCP标头和加密数据包的IPSec标头。通过这种方式,IPSec设备可以在原始TCP标头及其对应的IPSec标头之间执行简单的映射,以解决互操作性问题。在我们提议的IPSecOPEP体系结构中,我们在IPSec设备和PEP代理的标准TCP / IP堆栈中添加了新组件,以确保透明地协作且透明地确保它们之间的互操作性,而不会影响这种情况下的安全性和性能水平。实际上,此解决方案不需要交换与IPSec相关的安全关联的任何秘密信息。此外,这并不意味着PEP会在IPSec数据包中使用任何其他标头。但是,IPSec设备应在最终用户和PEP之间进行协调,以确保欺骗机制,以避免标准TCP的启动缓慢问题。之后,PEP可以继续在卫星链路上应用其他增强机制。因此,该解决方案在安全性和性能方面都具有双重优势。此外,可以在IPSec和PEP设备中轻松地标准化,实现,集成和启用此解决方案的组件。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号