首页> 外文期刊>Computer networks >Secure performance enhancing proxy: To ensure end-to-end security and enhance TCP performance over IPv6 wireless networks
【24h】

Secure performance enhancing proxy: To ensure end-to-end security and enhance TCP performance over IPv6 wireless networks

机译:安全的性能增强代理:通过IPv6无线网络确保端到端安全并增强TCP性能

获取原文
获取原文并翻译 | 示例

摘要

It is a well known fact that TCP is incapacitated to distinguish congestion losses in the wired network from corruption losses occurring in the wireless link and this inability results in poor performance of TCP in a hybrid wired-cum-wireless scenario. Most of the solutions previously proposed to address this problem are designed oblivious of the security considerations and violate end-to-end TCP semantics. Achieving improved TCP performance together with ensuring end-to-end security necessitates the co-existence of security mechanisms like IPSEC and performance enhancing solutions. However, IP security and TCP performance have been traditionally dealt with in a mutually exclusive manner. We propose an innovative mechanism, Secure Performance Enhancing Proxy (SPEP), to address the seemingly arduous problem of enhancing TCP performance over wireless networks, preserving end-to-end TCP semantics as well as ensuring end-to-end security. The proposed SPEP scheme decouples error detection and error distinction mechanism from error recovery mechanism which not only facilitates in performance improvement but also offers multifarious advantages discussed in the paper. We have implemented the proposed scheme in FreeBSD 4.5 and conducted experiments in a controlled test bed setup. Our results show improved TCP performance in a secured environment with introduction of minimal overhead.
机译:众所周知的事实是,TCP无法将有线网络中的拥塞损失与无线链路中发生的损坏损失区分开来,并且这种无用导致在混合有线兼无线情况下TCP的性能较差。先前为解决此问题而提出的大多数解决方案在设计时都忽略了安全考虑,并违反了端到端TCP语义。为了提高TCP性能并确保端到端的安全性,必须将IPSEC等安全机制与性能增强解决方案并存。但是,传统上以相互排斥的方式处理IP安全性和TCP性能。我们提出了一种创新机制,即安全性能增强代理(SPEP),以解决看似艰巨的问题,即通过无线网络增强TCP性能,保留端到端TCP语义以及确保端到端安全性。提出的SPEP方案使错误检测和错误区分机制与错误恢复机制脱钩,这不仅有助于提高性能,而且还提供了本文讨论的众多优点。我们已经在FreeBSD 4.5中实现了建议的方案,并在受控的测试平台设置中进行了实验。我们的结果表明,在安全的环境中,TCP的性能得到了改善,并引入了最小的开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号