首页> 外文期刊>Bell Labs technical journal >Adaptive VPN: Tradeoff Between Security levels and Value-added Services in Virtual Private Networks
【24h】

Adaptive VPN: Tradeoff Between Security levels and Value-added Services in Virtual Private Networks

机译:自适应VPN:在虚拟专用网络中的安全级别和增值服务之间进行权衡

获取原文
获取原文并翻译 | 示例
       

摘要

An end-to-end virtual private network (VPN) session provides complete privacy and data integrity for enterprise users who access the enterprise network from outside the intranet. However, because packets are encrypted end-to-end from the client to the enterprise VPN gateway, it is not possible for network service providers (NSPs) to provide value-added services to these enterprise VPN users, because such services require visibility into packet headers and application data. A network-based VPN allows a user VPN session to be terminated at an IP service switch (IPSS) within the NSP's network. Another VPN session from the IPSS to the enterprise VPN gateway is used to carry traffic from the IPSS to the enterprise. Because packet headers and application data are visible in the clear at the IPSS, the NSP can provide value-added services. In this paper we discuss a new VPN mechanism―which we call adaptive VPN+that enables enterprises to selectively trade off end-to-end security for value-added services that can be outsourced to an NSP. Adaptive VPN makes it possible for traffic from a specific user to be carried on an end-to-end VPN session and/or a network-based VPN session, based on the network access identifier (NAI) of the user and the application that is being accessed. We also describe the implementation of adaptive VPN in Lucent's VPN security products.
机译:端到端虚拟专用网(VPN)会话为从Intranet外部访问企业网络的企业用户提供了完全的隐私和数据完整性。但是,由于数据包是从客户端到企业VPN网关的端到端加密,因此网络服务提供商(NSP)无法为这些企业VPN用户提供增值服务,因为此类服务需要对数据包具有可见性标头和应用程序数据。基于网络的VPN允许用户VPN会话在NSP网络内的IP服务交换机(IPSS)处终止。从IPSS到企业VPN网关的另一个VPN会话用于承载从IPSS到企业的流量。由于数据包头和应用程序数据在IPSS处清晰可见,因此NSP可以提供增值服务。在本文中,我们讨论了一种新的VPN机制-称为自适应VPN +,该机制使企业能够有选择地权衡端到端安全性,以换取可以外包给NSP的增值服务。自适应VPN使得基于用户和应用程序的网络访问标识符(NAI),可以在端到端VPN会话和/或基于网络的VPN会话上承载来自特定用户的流量。被访问。我们还将描述朗讯公司VPN安全产品中自适应VPN的实现。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号