NETWORK STACK OPTIMIZATION FOR IMPROVED IPSEC PERFORMANCE ON LINUX

被引:0
|
作者
Iatrou, Michael G. [1 ]
Voyiatzis, Artemios G. [1 ]
Serpanos, Dimitrios N. [1 ]
机构
[1] Univ Patras, Dept Elect & Comp Engn, GR-26504 Patras, Greece
关键词
IPsec; Performance; Petworking; Security; Linux;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Virtual Private Network (VPN) connectivity is a necessity in the public Internet, for accessing in a secure fashion private resources from anywhere. Internet Protocol Security (IPsec) is a standardized VPN technology for serving multiple connectivity scenarios. Implementation of cryptography is widely considered as a performance bottleneck and a target for optimization. We present a set of system configuration optimizations for the Linux 2.6 kernel network stack implementation, supported by extensive measurements. These optimizations achieve significant throughput gains. Our work demonstrates that comparable performance between plain IP and IPsec connections is possible without altering the implementation of the cryptographic algorithms.
引用
收藏
页码:83 / 91
页数:9
相关论文
共 50 条
  • [1] Measuring the Cost of the Linux Network Stack in Real-Time
    Miola, Davide
    Risso, Fulvio
    Parola, Federico
    2024 IEEE 10TH INTERNATIONAL CONFERENCE ON NETWORK SOFTWARIZATION, NETSOFT 2024, 2024, : 295 - 303
  • [2] Linux下IPsec的实现
    王张宜
    陈幼雷
    张焕国
    不详
    计算机工程与应用 , 2002, (11) : 157 - 159
  • [3] Linux access point and IPSec bridge
    Tseng, T.H.
    Ye, F.
    Tamkang Journal of Science and Engineering, 2003, 6 (02): : 121 - 126
  • [4] Linux中IPSec的配置
    张美常
    彭建明
    计算机与数字工程, 2003, (02) : 69 - 71
  • [5] Network Stack Specialization for Performance
    Marinos, Ilias
    Watson, Robert N. M.
    Handley, Mark
    ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2014, 44 (04) : 175 - 186
  • [6] Network Stack Specialization for Performance
    Marinos, Ilias
    Watson, Robert N. M.
    Handley, Mark
    SIGCOMM'14: PROCEEDINGS OF THE 2014 ACM CONFERENCE ON SPECIAL INTEREST GROUP ON DATA COMMUNICATION, 2014, : 175 - 186
  • [7] Capacitor Allocation Optimization for Improved Distribution Network Performance
    Jimoh, Abdulrasaq
    Ayanlade, Samson Oladayo
    Ariyo, Funso Kehinde
    Aremu, Abdullahi
    Jimoh, Bilikisu Adeola
    Jimoh, Mojisola Adunola
    2023 2ND INTERNATIONAL CONFERENCE ON MECHATRONICS AND ELECTRICAL ENGINEERING, MEEE, 2023, : 16 - 19
  • [8] Efficient Correctness Testing of Linux Network Stack under Packet Dynamics
    Vu, Minh
    Ha, Phuong
    Xu, Lisong
    ICC 2020 - 2020 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2020,
  • [9] Network performance in High Performance Linux clusters
    Huang, B
    Bauer, M
    Katchabaw, M
    PDPTA '05: Proceedings of the 2005 International Conference on Parallel and Distributed Processing Techniques and Applications, Vols 1-3, 2005, : 550 - 556
  • [10] Linux下IPsec协议的实现
    汤隽
    赵荣彩
    李超
    计算机应用, 2002, (06) : 69 - 71