首页> 外文会议>International Military Communications Conference >A PREFIX SPACE PARTITIONING APPROACH TO SCALABLE PEER GATEWAY DISCOVERY IN SECURE VIRTUAL PRIVATE NETWORKS
【24h】

A PREFIX SPACE PARTITIONING APPROACH TO SCALABLE PEER GATEWAY DISCOVERY IN SECURE VIRTUAL PRIVATE NETWORKS

机译:安全虚拟专用网络中可扩展对等网关发现的前缀空间分区方法

获取原文

摘要

Virtual Private Networks (VPNs) are the used by enterprises to secure sensitive traffic going over public network infrastructure like the Internet. In VPNs, geographically separated networks belonging to the same community of interest (COI) are connected through virtual links (security associations) between VPN gateways. VPN gateways authenticate traffic, encrypt packets, and decrypt packets so that only encrypted packets from VPN customers travel the public network infrastructure. Each of these encrypted packets has the entire original IP packet encrypted and has a new IP header added to route the packet from the source gateway to the destination gateway. Of course, this implies that the source gateway needs to map the destination network prefix to the plain and cipher text addresses of the destination gateway. This mapping is used to create a security association between VPN gateways when the first packet carrying the destination network prefix arrives at the source gateway. In the currently deployed VPNs, each VPN gateway is configured manually with a table containing mapping from each network prefix to the IP address (es) of the VPN gateway that fronts that prefix. Manual configuration process cannot scale to VPNs with large number of plain text (trusted) networks and cannot handle situations where entire (trusted) networks move frequently and attach to different VPN gateways. In particular, the Global Information Grid (GIG) vision of the future network for DoD communities indicates the need for VPNs with several tens of thousands to a million gateways and similar number of trusted networks. For such networks, we need discovery mechanism for a VPN gateway to automatically find out which peer VPN gateway currently fronts for a given network (prefix) so a security association can be established for transmitting encrypted packets to that prefix. We would like this discovery mechanism to require minimal information transfer from plain text (PT) to cipher text (CT) side. Several discovery approaches have been proposed and investigated. In this paper, we discuss key elements and organization of a new discovery mechanism, which uses a system of servers. The server organization is based on partitioning the space of prefixes and is designed to allow scalability and mobility support while keeping communication between these servers simple. We describe key ideas and key information exchange, and show how the solution scales to millions of prefixes. We also discuss how these ideas can be extended to add hierarchies and take advantage of sub communities of interest. Hierarchies may also be useful in dealing with multiple levels of cipher text networks separated by CT-PT-CT gateways.
机译:虚拟专用网络(VPN)由企业使用,以确保互联网上的公共网络基础架构的敏感流量。在VPN中,属于相同的景区(COI)的地理上分离网络通过VPN网关之间的虚拟链路(安全关联)连接。 VPN网关验证流量,加密数据包和解密数据包,以便仅来自VPN客户的加密数据包传输公共网络基础架构。这些加密数据包中的每一个都具有加密的整个原始IP数据包,并具有添加新的IP标题以将数据包从源网关路由到目标网关。当然,这意味着源网关需要将目的地网络前缀映射到目的网关的普通文本地址和密码文本地址。当携带目的地网络前缀的第一分组到达源网关时,该映射用于在VPN网关之间创建安全关联。在当前部署的VPN中,每个VPN网关手动配置,其中表包含从每个网络前缀的映射到前端的VPN网关的IP地址。手动配置过程无法使用大量纯文本(可信)网络(可信)网络缩放到VPN,无法处理整个(可信)网络频繁移动并附加到不同VPN网关的情况。特别是,国防部社区未来网络的全球信息网格(GIG)愿景表明,对VPN的需求具有几千到一百万个网关和类似数量的可信网络。对于这种网络,我们需要VPN网关的发现机制,以自动找出给定网络(前缀)的当前前端的对等体VPN网关,因此可以建立安全关联,以将加密分组发送到该前缀。我们希望此发现机制要求从普通文本(PT)到密码文本(CT)侧的最小信息传输。提出并调查了几种发现方法。在本文中,我们讨论了一种新发现机制的关键要素和组织,它使用服务器系统。服务器组织基于对前缀的空间进行分区,旨在允许可伸缩性和移动性支持,同时保持这些服务器之间的通信简单。我们描述了关键的想法和关键信息交换,并展示了解决方案如何缩放到数百万个前缀。我们还讨论如何扩展这些想法以添加层次结构并利用兴趣子群群。层次结构也可能有助于处理由CT-PT-CT网关分隔的多个级别的密文网络。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号