E2E: An Optimized IPsec Architecture for Secure And Fast Offload

被引:3
|
作者
Migault, Daniel
Palomares, Daniel
Herbert, Emmanuel
You, Wei
Ganne, Gabriel
Arfaoui, Ghada
Laurent, Maryline
机构
关键词
IPsec; IKEv2; MOBIKE; MOBIKE-X; Mobility; Multihoming; TRANSPORT;
D O I
10.1109/ARES.2012.80
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
When mobile End Users are offloaded from a Radio Access Network (RAN) to a WLAN, current I-WLAN [1] offloaded architectures consider traffic converging to a common Security Gateway. In this paper, we propose an alternative End-to-End security (E2E) architecture based on the MOBIKE-X [2] protocol, which extends the MOBIKE [3] Mobility and Multihoming features to Multiple Interfaces and to the Transport mode of IPsec. The benefits of this E2E architecture are mostly load reduction and a better End User experience. First, E2E offloads the ISP CORE and backhaul networks, then E2E uses IPsec Transport mode instead of Tunnel mode, which removes networking and security overhead. This reduces CPU load by 20%, enhances Mobility and Multihoming operations by about 15%, and makes the system 2.9 times more reactive for detecting modifications of interfaces.
引用
收藏
页码:365 / 374
页数:10
相关论文
共 50 条
  • [1] Measurement System Architecture for Measuring Network Parameters of e2e Services
    Kulik, Vyacheslav
    Kirichek, Ruslan
    Borodin, Alexey
    Koucheryavy, Andrey
    [J]. DISTRIBUTED COMPUTER AND COMMUNICATION NETWORKS (DCCN 2017), 2017, 700 : 291 - 306
  • [2] DeepIntent: ImplicitIntent based Android IDS with E2E Deep Learning architecture
    Sewak, Mohit
    Sahay, Sanjay K.
    Rathore, Hemant
    [J]. 2020 IEEE 31ST ANNUAL INTERNATIONAL SYMPOSIUM ON PERSONAL, INDOOR AND MOBILE RADIO COMMUNICATIONS (IEEE PIMRC), 2020,
  • [3] On Persistent Implications of E2E Testing
    Frajtak, Karel
    Cerny, Tomas
    [J]. ENTERPRISE INFORMATION SYSTEMS, ICEIS 2021, 2022, 455 : 326 - 338
  • [4] E2E数据采集网络
    张振华
    宫海波
    李国星
    [J]. 中国科技信息, 2017, (06) : 67 - 70
  • [5] Analysis of E2E Delay and Wiring Harness in In-Vehicle Network with Zonal Architecture
    Park, Chulsun
    Cui, Chengyu
    Park, Sungkwon
    [J]. SENSORS, 2024, 24 (10)
  • [6] Managing Mobile Relays for Secure E2E Connectivity of Low-Power IoT Devices
    Porambage, Pawani
    Manzoor, Ahsan
    Liyanage, Madhsanka
    Gurtov, Andrei
    Ylianttila, Mika
    [J]. 2019 16TH IEEE ANNUAL CONSUMER COMMUNICATIONS & NETWORKING CONFERENCE (CCNC), 2019,
  • [7] POSTER: An E2E Trusted Cloud Infrastructure
    Wang, Juan
    Zhao, Bo
    Zhang, Huanguo
    Yan, Fei
    Zhang, Liqiang
    Yu, Fajiang
    Hu, Hongxin
    [J]. CCS'14: PROCEEDINGS OF THE 21ST ACM CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2014, : 1517 - 1519
  • [8] A NOVEL PRICING-BASED RESOURCE ALLOCATION ARCHITECTURE AND IMPLEMENT FOR E2E HETEROGENEOUS NETWORKS
    Xie, Bing
    Zhou, Wenan
    Chen, Wei
    Song, Junde
    [J]. PROCEEDINGS OF 2009 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS TECHNOLOGY AND APPLICATIONS, 2009, : 851 - 855
  • [9] Lightweight Secure Message Delivery for E2E S2S Communication in the IoT-Cloud System
    Al Sibahee, Mustafa A.
    Lu, Songfeng
    Abduljabbar, Zaid Ameen
    Liu, Xin
    Abdalla, Hemn Barzan
    Hussain, Mohammed Abdulridha
    Hussien, Zaid Alaa
    Jassim Ghrabat, Mudhafar Jalil
    [J]. IEEE ACCESS, 2020, 8 : 218331 - 218347
  • [10] An IP-ERN architecture to enable hybrid E2E/ERN protocol and application to satellite networking
    Pacheco, Dino Martin Lopez
    Tuan Tran Thai
    Lochin, Emmanuel
    Arnal, Fabrice
    [J]. COMPUTER NETWORKS, 2012, 56 (11) : 2700 - 2713