首页> 外文会议>IEEE International Conference on Communications >TCP-GEN Framework to Achieve High Performance for HAIPE-Encrypted TCP Traffic in a Satellite Communication Environment
【24h】

TCP-GEN Framework to Achieve High Performance for HAIPE-Encrypted TCP Traffic in a Satellite Communication Environment

机译:TCP-GEN框架可在卫星通信环境中为HAIPE加密的TCP流量实现高性能

获取原文

摘要

A satellite communication environment has a high latency and a high data error rate, and thus the performance of TCP is greatly impaired. To overcome this, Performance Enhancing Proxies (PEPs) are commonly deployed around the satellite links. However, the operation of PEPs is disabled when TCP traffic is encrypted by High Assurance Internet Protocol Encryptions (HAIPE). As a result the performance of the HAIPE-encrypted TCP traffic across satellite links becomes very low. Numerous approaches have been proposed to resolve this problem, but a practical solution is yet to be developed. In this research, we developed a method that can achieve the high performance offered by PEPs for HAIPE-encrypted TCP traffic across satellite links. This method encodes and relays the original TCP flow information across HAIPE without any modification to the existing HAIPE while preserving the same level of security. It then reconstructs new TCP streams and encapsulates HAIPE-encrypted original TCP packets in them. These new TCP streams can be natively handled by PEPs and thus the full TCP performance can be achieved. This method is also applicable to both IPv4 and IPv6. However, this scheme faces a challenge of handling TCP-over-TCP that suffers from a phenomenon called TCP meltdown. We propose a method that can prevent TCP meltdown and briefly describe it.
机译:卫星通信环境具有较高的等待时间和较高的数据错误率,因此大大损害了TCP的性能。为了克服这个问题,通常在卫星链路周围部署性能增强代理(PEP)。但是,当通过高保证Internet协议加密(HAIPE)对TCP通信进行加密时,PEP的操作将被禁用。结果,跨卫星链路的HAIPE加密的TCP流量的性能变得非常低。已经提出了许多解决该问题的方法,但是尚未开发出实用的解决方案。在这项研究中,我们开发了一种方法,该方法可以实现PEP提供的针对跨卫星链路的HAIPE加密TCP流量的高性能。此方法在HAIPE上对原始TCP流信息进行编码和中继,而无需对现有HAIPE进行任何修改,同时保留相同级别的安全性。然后,它重建新的TCP流,并在其中封装HAIPE加密的原始TCP数据包。这些新的TCP流可以由PEP本地处理,因此可以实现完整的TCP性能。此方法也适用于IPv4和IPv6。但是,此方案面临处理TCP-over-TCP的挑战,这种现象受称为TCP崩溃的现象的困扰。我们提出一种可以防止TCP崩溃的方法,并对其进行简要描述。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号