跳到主要导航 跳到搜索 跳到主要内容

IPSecOPEP: IPSec over PEPs architecture, for secure and optimized communications over satellite links

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

This paper presents a TCP/IP-based architecture (IPSecOPEP) to resolve the interoperability issue between PEPs (Performance Enhancing Proxies) and IPSec (Internet Protocol Security). Where this problem is due to the cryptographic protection of TCP header by IPSec ESP protocol, which prohibits TCP enhancing mechanisms to be performed by PEPs. The key idea of this solution is that IPSec devices can perform well as a bridge between end users and PEPs in such situations, because they can access to both TCP headers of original packets and IPSec headers of encrypted packets. By this way, IPSec devices can perform a simple mapping between original TCP headers and their corresponding IPSec headers to resolve the interoperability issue. In our proposed IPSecOPEP architecture, we add a new components to the standard TCP/IP stack for IPSec devices and PEPs proxies, to ensure cooperatively and transparently the interoperability between them, without affecting the security privacy and performance level in such situations. In fact, this solution doesn't need to exchange any secret information about IPSec-related security associations. Furthermore it doesn't imply the use of any additional headers to IPSec packets by the PEPs. However, IPSec devices should coordinate between end users and PEPs to ensure spoofing mechanism, to avoid slow start problem of a standard TCP. After that, PEPs can continue to apply other enhancing mechanisms over the satellite link. Hence, this solution presents a double advantages concerning both the security and the performance at once. Moreover, the components of this solution can be easily standardized, implemented, integrated and enabled, in IPSec and PEPs devices.

源语言英语
主期刊名ICSESS 2016 - Proceedings of 2016 IEEE 7th International Conference on Software Engineering and Service Science
编辑M. Surendra Prasad Babu, Li Wenzheng
出版商IEEE Computer Society
264-268
页数5
ISBN(电子版)9781467399036
DOI
出版状态已出版 - 2 7月 2016
活动7th IEEE International Conference on Software Engineering and Service Science, ICSESS 2016 - Beijing, 中国
期限: 26 8月 201628 8月 2016

出版系列

姓名Proceedings of the IEEE International Conference on Software Engineering and Service Sciences, ICSESS
0
ISSN(印刷版)2327-0586
ISSN(电子版)2327-0594

会议

会议7th IEEE International Conference on Software Engineering and Service Science, ICSESS 2016
国家/地区中国
Beijing
时期26/08/1628/08/16

指纹

探究 'IPSecOPEP: IPSec over PEPs architecture, for secure and optimized communications over satellite links' 的科研主题。它们共同构成独一无二的指纹。

引用此