SDIG: Toward Software-Defined IPsec Gateway

被引:0
|
作者
Li, Wei [1 ]
Lin, Fengxu [1 ]
Sun, Guanchao [1 ]
机构
[1] Beihang Univ, Sch Comp Sci & Engn, Key Lab Beijing Network Technol, Beijing, Peoples R China
关键词
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
The current IPsec gateway integrates many functions of IPsec operation, tunnel management and forwarding decision, which makes the IPsec gateway complicated in maintenance and deployment. The problem of maintaining such devices prevents IPsec VPN from applying widely. The emergence of SDN provides an innovative way to decouple the control plane and data plane. In this paper, a Software-Defined IPsec Gateway (SDIG) is proposed to achieve net2net IPsec VPN. Different from the traditional IPsec gateway, the SDIG device serves as a data plane equipment that just concentrates on exchanging IKE packets and encrypting/decrypting IP packets. A global view of SDIG devices can be constructed in the SDN controller by collecting the status of all devices. Therefore the controller can manage and configure SDIG devices centrally, and simplify deployment complexity. Outbound IP packets for the SDIG device can be viewed as a trigger to control the establishment of IPsec tunnels. The SDIG device and the controller exchange information through a customized southbound protocol. The prototype system of SDIG is implemented, and the preliminary experimental results show that the method is feasible and effective.
引用
收藏
页数:8
相关论文
共 50 条
  • [1] Design of software-defined gateway for industrial interconnection
    Jiang, Zongmin
    Chang, Yan
    Liu, Xuefen
    JOURNAL OF INDUSTRIAL INFORMATION INTEGRATION, 2020, 18
  • [2] Toward Software-Defined SLAs
    Lango, Jason
    COMMUNICATIONS OF THE ACM, 2014, 57 (01) : 54 - 60
  • [3] Cryptographic Algorithm Invocation Based on Software-Defined Everything in IPsec
    Yang, Ximin
    Wang, Deqiang
    Feng, Wei
    Wu, Jingjing
    Tang, Wan
    WIRELESS COMMUNICATIONS & MOBILE COMPUTING, 2018,
  • [4] Toward Software-Defined Middlebox Networking
    Gember, Aaron
    Prabhu, Prathmesh
    Ghadiyali, Zainab
    Akella, Aditya
    PROCEEDINGS OF THE 11TH ACM WORKSHOP ON HOT TOPICS IN NETWORKS (HOTNETS-XI), 2012, : 7 - 12
  • [5] Toward Software-Defined Battlefield Networking
    Nobre, Jeferson
    Rosario, Denis
    Both, Cristiano
    Cerqueira, Eduardo
    Gerla, Mario
    IEEE COMMUNICATIONS MAGAZINE, 2016, 54 (10) : 152 - 157
  • [6] WIRELESS HOME GATEWAY: SOFTWARE-DEFINED RADIO ARCHITECTURE AND APPLICATIONS
    Zhang, Chaorui
    Xie, Peng
    Li, Deyuan
    Zhang, Jiekai
    Yu, Rong
    PROCEEDINGS OF 2011 INTERNATIONAL CONFERENCE ON COMMUNICATION TECHNOLOGY AND APPLICATION, ICCTA2011, 2011, : 346 - 350
  • [7] OpenSIP: Toward Software-Defined SIP Networking
    Montazerolghaem, Ahmadreza
    Moghaddam, Mohammad Hossein Yaghmaee
    Leon-Garcia, Alberto
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2018, 15 (01): : 184 - 199
  • [8] JTRS and the evolution toward software-defined radio
    Melby, J
    2002 MILCOM PROCEEDINGS, VOLS 1 AND 2: GLOBAL INFORMATION GRID - ENABLING TRANSFORMATION THROUGH 21ST CENTURY COMMUNICATIONS, 2002, : 1286 - 1290
  • [9] Toward manageable middleboxes in software-defined networking
    Zadkhosh, Ehsan
    Bahramgiri, Hossein
    Sabaei, Masoud
    ETRI JOURNAL, 2020, 42 (02) : 186 - 195
  • [10] Toward a Scalable Software-Defined Vehicular Network
    Correia, Sergio
    Boukerche, Azzedine
    GLOBECOM 2017 - 2017 IEEE GLOBAL COMMUNICATIONS CONFERENCE, 2017,