SDIG: Toward Software-Defined IPsec Gateway

被引:0
|
作者
Li, Wei [1 ]
Lin, Fengxu [1 ]
Sun, Guanchao [1 ]
机构
[1] Beihang Univ, Sch Comp Sci & Engn, Key Lab Beijing Network Technol, Beijing, Peoples R China
关键词
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
The current IPsec gateway integrates many functions of IPsec operation, tunnel management and forwarding decision, which makes the IPsec gateway complicated in maintenance and deployment. The problem of maintaining such devices prevents IPsec VPN from applying widely. The emergence of SDN provides an innovative way to decouple the control plane and data plane. In this paper, a Software-Defined IPsec Gateway (SDIG) is proposed to achieve net2net IPsec VPN. Different from the traditional IPsec gateway, the SDIG device serves as a data plane equipment that just concentrates on exchanging IKE packets and encrypting/decrypting IP packets. A global view of SDIG devices can be constructed in the SDN controller by collecting the status of all devices. Therefore the controller can manage and configure SDIG devices centrally, and simplify deployment complexity. Outbound IP packets for the SDIG device can be viewed as a trigger to control the establishment of IPsec tunnels. The SDIG device and the controller exchange information through a customized southbound protocol. The prototype system of SDIG is implemented, and the preliminary experimental results show that the method is feasible and effective.
引用
收藏
页数:8
相关论文
共 50 条
  • [21] Toward Control Path High Availability for Software-Defined Networks
    Park, Hyungbae
    Song, Sejun
    Choi, Baek-Young
    Choi, Taesang
    2015 11TH INTERNATIONAL CONFERENCE ON THE DESIGN OF RELIABLE COMMUNICATION NETWORKS (DRCN), 2015, : 165 - 172
  • [22] Toward Information-Centric Software-Defined Cellular Networks
    Vassilakis, Vassilios G.
    Moscholios, Ioannis D.
    Alzahrani, Bander A.
    Logothetis, Michael D.
    PROCEEDINGS OF THE 14TH INTERNATIONAL CONFERENCE ON TELECOMMUNICATIONS CONTEL 2017, 2017, : 99 - 105
  • [23] SDPA: Toward a Stateful Data Plane in Software-Defined Networking
    Sun, Chen
    Bi, Jun
    Chen, Haoxian
    Hu, Hongxin
    Zheng, Zhilong
    Zhu, Shuyong
    Wu, Chenghui
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2017, 25 (06) : 3294 - 3308
  • [24] Toward Software-Defined Backscatter Modulation via Signal Emulation
    Peng, Yuxiang
    He, Shiyue
    Zhang, Yu
    Xiao, Lixia
    Jiang, Tao
    IEEE TRANSACTIONS ON WIRELESS COMMUNICATIONS, 2024, 23 (10) : 14836 - 14847
  • [25] Software-defined radio
    不详
    TECHNOLOGY REVIEW, 2005, 108 (08) : 31 - 31
  • [26] Software-Defined Networking
    Kirkpatrick, Keith
    COMMUNICATIONS OF THE ACM, 2013, 56 (09) : 16 - 19
  • [27] Software-defined networking
    Greene, Kate
    Technology Review, 2009, 112 (02)
  • [28] SOFTWARE-DEFINED RADIO
    Vergari, Fabrizio
    IEEE VEHICULAR TECHNOLOGY MAGAZINE, 2013, 8 (02): : 71 - 82
  • [29] Software-Defined Cluster
    Nie, Hua
    Yang, Xiao-Jun
    Liu, Tao-Ying
    JOURNAL OF COMPUTER SCIENCE AND TECHNOLOGY, 2015, 30 (02) : 252 - 258
  • [30] Software-defined operations
    Meirosu, Catalin
    Pentikousis, Kostas
    Kind, Mario
    Gonzalez Prieto, Alberto
    INTERNATIONAL JOURNAL OF NETWORK MANAGEMENT, 2016, 26 (05) : 334 - 335