首页> 外文期刊>Future generation computer systems >Transparent VPN failure recovery with virtualization
【24h】

Transparent VPN failure recovery with virtualization

机译:通过虚拟化进行透明的VPN故障恢复

获取原文
获取原文并翻译 | 示例

摘要

Cloud computing is widely used to provide today's Internet services. Since its service scope is being extended to a wide range of business applications, the security of network communications between clients and clouds are becoming important. Several cloud vendors support virtual private networks (VPNs) for connecting their clouds. Unfortunately, cloud services become unavailable when a VPN failure occurred in a VPN gateway or networks. We propose a transparent VPN failure recovery scheme that can hide VPN failures from users and operating systems (OSs). This scheme transparently recovers from VPN failures by establishing VPN connections in a virtualization layer. When a VPN failure occurs, a client virtual machine monitor (VMM) automatically reconnects to an available VPN gateway which is geographically distributed and connected via leased lines in clouds. IP address changes are hidden from client OSs and servers via a packet relay system implemented by a relay client in the client VMM and a relay server. We implemented a prototype system based on BitVisor, a small client VMM supporting IPsec VPN, and evaluated the prototype system in a wide-area distributed Internet environment in Japan. Experimental results show that our scheme can maintain TCP connections on VPN failures, and performance overhead with the virtualization layer is around 0.6 ms to latency and 8%-30% to throughput.
机译:云计算被广泛用于提供当今的Internet服务。由于其服务范围已扩展到广泛的业务应用程序,因此客户端与云之间的网络通信的安全性变得越来越重要。一些云供应商支持虚拟专用网络(VPN)来连接其云。不幸的是,当VPN网关或网络中发生VPN故障时,云服务将变得不可用。我们提出了一种透明的VPN故障恢复方案,该方案可以对用户和操作系统(OS)隐藏VPN故障。通过在虚拟化层中建立VPN连接,该方案可以从VPN故障中透明地恢复。当VPN发生故障时,客户端虚拟机监视器(VMM)会自动重新连接到可用的VPN网关,该网关在地理位置上分布并通过云中的租用线路连接。 IP地址更改通过客户端VMM中的中继客户端和中继服务器实现的数据包中继系统对客户端OS和服务器隐藏。我们基于BitVisor(一个支持IPsec VPN的小型客户端VMM)实现了原型系统,并在日本的广域分布式Internet环境中评估了该原型系统。实验结果表明,我们的方案可以在VPN失败时维持TCP连接,而虚拟化层的性能开销大约为延迟0.6毫秒,吞吐量为8%-30%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号