首页> 外文会议>Communication, Network, and Information Security >BEHAVIORAL AND PERFORMANCE CHARACTERISTICS OF IPsec/IKE IN LARGE-SCALE VPNS
【24h】

BEHAVIORAL AND PERFORMANCE CHARACTERISTICS OF IPsec/IKE IN LARGE-SCALE VPNS

机译:大型VPN中IPsec / IKE的行为和性能特征

获取原文

摘要

Cryptographic network security services are essential for providing secure data communication over an insecure public network such as the Internet. Recently there has been tremendous growth in the requirements for, and use of, secure virtual private networks (VPNs) to interconnect enterprises with business partners, traveling staff, and remote office locations. IPsec tunnels have become one of the most widely adopted means to build secure VPNs between sites and individual computers. To date, most IPsec VPNs are statically configured and are of moderate scale. To facilitate future, very large VPNs with potentially varied security policies and changing memberships, the industry must move to the use of dynamic key management protocols and policy management systems to ease the administrative burden associated with VPN instantiation and operation. In this paper we examine the dynamic behavior and relative performance characteristics of large scale VPN environments based upon IPsec and IKE version 1 (version 2 of IKE is currently under development by IETF). We use detailed, packet level, simulation models to characterize the performance impact of varying: key management scenarios, security association (SA) policy and management parameters, cryptographic algorithms, and implementation options in IPsec/IKE suites. Our results highlight the significant performance impact of subtle IPsec/IKE implementation and policy decisions on the overall performance and behavior of TCP based applications in large scale VPNs.
机译:加密网络安全服务对于通过不安全的公共网络(例如Internet)提供安全的数据通信至关重要。近年来,对安全虚拟专用网络(VPN)的需求和使用有了巨大的增长,以使企业与业务合作伙伴,外出工作人员和远程办公室相互连接。 IPsec隧道已成为在站点和单个计算机之间建立安全VPN的最广泛采用的手段之一。迄今为止,大多数IPsec VPN都是静态配置的,规模适中。为了促进未来的,具有可能变化的安全策略和不断变化的成员资格的超大型VPN,行业必须转向使用动态密钥管理协议和策略管理系统,以减轻与VPN实例化和操作相关的管理负担。在本文中,我们检查了基于IPsec和IKE版本1(IETF目前正在开发IKE的版本2)的大规模VPN环境的动态行为和相对性能特征。我们使用详细的数据包级别的仿真模型来表征变化对性能的影响:密钥管理方案,安全关联(SA)策略和管理参数,加密算法以及IPsec / IKE套件中的实现选项。我们的结果强调了微妙的IPsec / IKE实施和策略决策对大规模VPN中基于TCP的应用程序的整体性能和行为的重大性能影响。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号