首页> 外文期刊>Wireless communications & mobile computing >Remote access virtual private network architecture for high-speed wireless internet users
【24h】

Remote access virtual private network architecture for high-speed wireless internet users

机译:面向高速无线互联网用户的远程访问虚拟专用网络体系结构

获取原文
获取原文并翻译 | 示例
           

摘要

The new emerging broadband wireless network (BWN) technologies with high-speed wireless internet access promotes corporations to provide their roaming employees with high-speed wireless access to the computing resources on their corporate networks. Thus, a value added service to broadband wireless network is the remote access virtual private network (VPN), where the corporate legitimate users can connect to their offices wirelessly from different locations and get secure services as if they were connected to the corporate local area network (LAN). One of the most important challenges is to block out illegitimate user requests, which are wirelessly received, to protect corporate privacy. Registration (adding new users) and authentication (accepting current users) functions should be implemented with highly secured wireless connection. These functions are accomplished by encapsulating (i.e. tunneling) the user information in a secured form to the corporate authentication server through the internet traffic. The corporate authentication server then grants or denies the user access. In this paper, we propose a new operational design algorithm for remote access wireless VPN authentication and registration protocols that depends on modifying tunnel establishment as compared to existing dial-in VPN mechanisms. The modifications proposed in this paper are made to support successful deployment of the remote access VPN services over high-speed wireless network. The paper presents an overview of two tunneling approaches using Layer 3 and Layer 2 separately for implementing these functions. Then we propose how we establish the tunnel in both approaches, and compare it to similar operation steps previously reported for the dial-in VPN protocols. The proposed algorithms are distinguished from previously developed dial-in VPN protocols by using L2TP and IPSEC instead of mobile IP. It is also shown that the steps involved in the establishment of the tunnel are functionally different and more appropriate to our applications using communication environment of the BWN. Finally, a qualitative analysis of the added functions, and a comparison between L2TP-based and IPSec-based approaches are established.
机译:具有高速无线互联网访问权限的新兴新兴宽带无线网络(BWN)技术促进了公司向其漫游员工提供对其公司网络上的计算资源的高速无线访问权限。因此,宽带无线网络的增值服务是远程访问虚拟专用网(VPN),企业合法用户可以在其中从不同位置无线连接到他们的办公室,并获得安全的服务,就像他们已连接到企业局域网一样。 (局域网)。最重要的挑战之一是阻止无线接收到的非法用户请求,以保护公司的隐私。注册(添加新用户)和认证(接受当前用户)功能应通过高度安全的无线连接来实现。这些功能通过将用户信息以安全形式通过互联网流量封装(即通过隧道传输)到公司身份验证服务器来实现。然后,企业认证服务器会授予或拒绝用户访问权限。在本文中,我们提出了一种用于远程访问无线VPN身份验证和注册协议的新的运营设计算法,该算法与现有的拨入VPN机制相比,依赖于修改隧道的建立。本文提出的修改旨在支持在高速无线网络上成功部署远程访问VPN服务。本文概述了分别使用第3层和第2层来实现这些功能的两种隧道方法。然后,我们提出如何在两种方法中建立隧道,并将其与先前针对拨入VPN协议报告的类似操作步骤进行比较。通过使用L2TP和IPSEC代替移动IP,提出的算法与以前开发的拨入VPN协议有所不同。还表明,建立隧道涉及的步骤在功能上有所不同,并且更适合使用BWN通讯环境的应用程序。最后,对增加的功能进行了定性分析,并对基于L2TP和基于IPSec的方法进行了比较。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号