...
首页> 外文期刊>Computer Communications >A network-assisted mobile VPN for securing users data in UMTS
【24h】

A network-assisted mobile VPN for securing users data in UMTS

机译:网络辅助的移动VPN,用于保护UMTS中的用户数据

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

This paper proposes a network-assisted mobile Virtual Private Network (mVPN) security scheme that provides secure remote access to corporate resources over the Universal Mobile Telecommunication System (UMTS). The proposed scheme, which is based on IPsec, distributes the required security functionality for deploying a VPN between the involved user's device and the mobile network limiting the configuration, computation and communication overheads associated with the user and its device. The network-assisted mVPN addresses the security weaknesses of the UMTS technology in protecting users' data and satisfies the security requirements of the mobile users. It can be integrated into the UMTS network infrastructure requiring only some limited enhancements to the existing mobile network architecture, and without disrupting the network operation. For the initialization of a network-assisted mVPN and the related key agreement an extension of Internet Key Exchange version 2 (IKEv2) is proposed. The proposed network-assisted mVPN can operate seamlessly and provide security services continuously while the mobile user moves and roams as it binds the UMTS mobility management with the VPN deployment. The deployment cost of the proposed scheme is evaluated analytically and via simulations and is compared to that of the end-to-end (e2e) VPN scheme that protects the data exchanged between the mobile user and the remote server, and a scheme that does not include any additional security mechanism. The proposed scheme increases the cumulative VPN deployment cost compared to the e2e scheme, but on the other hand it limits considerably the VPN deployment cost of the involved MS, which is important due to it resource limitation. Moreover, it does not considerably affect the capacity of the UMTS network. Finally, the deployed network-assisted mVPN hardly has an impact on the total delay of the transmitted user's packets.
机译:本文提出了一种网络辅助的移动虚拟专用网(mVPN)安全方案,该方案可通过通用移动电信系统(UMTS)提供对公司资源的安全远程访问。所提出的基于IPsec的方案在涉及的用户设备和移动网络之间分配了用于部署VPN的所需安全功能,从而限制了与用户及其设备相关的配置,计算和通信开销。网络辅助的mVPN解决了UMTS技术在保护用户数据方面的安全漏洞,并满足了移动用户的安全要求。它可以集成到UMTS网络基础结构中,仅需要对现有移动网络体系结构进行一些有限的增强,而不会影响网络运行。为了初始化网络辅助的mVPN和相关的密钥协议,提出了Internet密钥交换版本2(IKEv2)的扩展。当移动用户将UMTS移动性管理与VPN部署绑定在一起时,拟议的网络辅助mVPN可以无缝运行并连续提供安全服务,同时移动用户可以移动和漫游。拟议方案的部署成本经过分析和模拟评估,并与保护移动用户和远程服务器之间交换数据的端到端(e2e)VPN方案的成本进行了比较,而没有包括任何其他安全机制。与端到端方案相比,提出的方案增加了累积的VPN部署成本,但另一方面,它极大地限制了所涉及MS的VPN部署成本,由于其资源限制,这一点很重要。而且,它不会显着影响UMTS网络的容量。最后,已部署的网络辅助mVPN几乎不会影响传输的用户数据包的总延迟。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号