@inproceedings{6ad0a91937ae4ce0819859b1a709ec3e,
title = "IPSecOPEP: IPSec over PEPs architecture, for secure and optimized communications over satellite links",
abstract = "This paper presents a TCP/IP-based architecture (IPSecOPEP) to resolve the interoperability issue between PEPs (Performance Enhancing Proxies) and IPSec (Internet Protocol Security). Where this problem is due to the cryptographic protection of TCP header by IPSec ESP protocol, which prohibits TCP enhancing mechanisms to be performed by PEPs. The key idea of this solution is that IPSec devices can perform well as a bridge between end users and PEPs in such situations, because they can access to both TCP headers of original packets and IPSec headers of encrypted packets. By this way, IPSec devices can perform a simple mapping between original TCP headers and their corresponding IPSec headers to resolve the interoperability issue. In our proposed IPSecOPEP architecture, we add a new components to the standard TCP/IP stack for IPSec devices and PEPs proxies, to ensure cooperatively and transparently the interoperability between them, without affecting the security privacy and performance level in such situations. In fact, this solution doesn't need to exchange any secret information about IPSec-related security associations. Furthermore it doesn't imply the use of any additional headers to IPSec packets by the PEPs. However, IPSec devices should coordinate between end users and PEPs to ensure spoofing mechanism, to avoid slow start problem of a standard TCP. After that, PEPs can continue to apply other enhancing mechanisms over the satellite link. Hence, this solution presents a double advantages concerning both the security and the performance at once. Moreover, the components of this solution can be easily standardized, implemented, integrated and enabled, in IPSec and PEPs devices.",
keywords = "Interoperability, IPSec, IPSecOPEP, Optimization, PEPs, Satellite links, Security, TCP/IP",
author = "Lekhemissi Djeddai and Liu, \{Rong Ke\}",
note = "Publisher Copyright: {\textcopyright} 2016 IEEE.; 7th IEEE International Conference on Software Engineering and Service Science, ICSESS 2016 ; Conference date: 26-08-2016 Through 28-08-2016",
year = "2016",
month = jul,
day = "2",
doi = "10.1109/ICSESS.2016.7883063",
language = "英语",
series = "Proceedings of the IEEE International Conference on Software Engineering and Service Sciences, ICSESS",
publisher = "IEEE Computer Society",
pages = "264--268",
editor = "Babu, \{M. Surendra Prasad\} and Li Wenzheng",
booktitle = "ICSESS 2016 - Proceedings of 2016 IEEE 7th International Conference on Software Engineering and Service Science",
address = "美国",
}