SDIG: Toward Software-Defined IPsec Gateway

被引:0
|
作者
Li, Wei [1 ]
Lin, Fengxu [1 ]
Sun, Guanchao [1 ]
机构
[1] Beihang Univ, Sch Comp Sci & Engn, Key Lab Beijing Network Technol, Beijing, Peoples R China
关键词
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
The current IPsec gateway integrates many functions of IPsec operation, tunnel management and forwarding decision, which makes the IPsec gateway complicated in maintenance and deployment. The problem of maintaining such devices prevents IPsec VPN from applying widely. The emergence of SDN provides an innovative way to decouple the control plane and data plane. In this paper, a Software-Defined IPsec Gateway (SDIG) is proposed to achieve net2net IPsec VPN. Different from the traditional IPsec gateway, the SDIG device serves as a data plane equipment that just concentrates on exchanging IKE packets and encrypting/decrypting IP packets. A global view of SDIG devices can be constructed in the SDN controller by collecting the status of all devices. Therefore the controller can manage and configure SDIG devices centrally, and simplify deployment complexity. Outbound IP packets for the SDIG device can be viewed as a trigger to control the establishment of IPsec tunnels. The SDIG device and the controller exchange information through a customized southbound protocol. The prototype system of SDIG is implemented, and the preliminary experimental results show that the method is feasible and effective.
引用
收藏
页数:8
相关论文
共 50 条
  • [31] Software-Defined Batteries
    Badam, Anirudh
    Chandra, Ranveer
    Dutra, Jon
    Ferrese, Anthony
    Hodges, Steve
    Hu, Pan
    Meinershagen, Julia
    Moscibroda, Thomas
    Priyantha, Bodhi
    Skiani, Evangelia
    COMMUNICATIONS OF THE ACM, 2016, 59 (12) : 111 - 119
  • [32] Software-Defined Networking
    Zhili Sun
    Jiandong Li
    Kun Yang
    ZTECommunications, 2014, 12 (02) : 1 - 2
  • [33] Software-Defined Cluster
    Hua Nie
    Xiao-Jun Yang
    Tao-Ying Liu
    Journal of Computer Science and Technology, 2015, 30 : 252 - 258
  • [34] The Implementation of Border Gateway Protocol Using Software-Defined Networks: A Systematic Literature Review
    Zhao, Xi
    Band, Shahab S.
    Elnaffar, Said
    Sookhak, Mehdi
    Mosavi, Amir
    Salwana, Ely
    IEEE ACCESS, 2021, 9 : 112596 - 112606
  • [35] Future Scenarios for Software-Defined Metro and Access Networks and Software-Defined Photonics
    Muciaccia, Tommaso
    Passaro, Vittorio M. N.
    PHOTONICS, 2017, 4 (01)
  • [36] Programmable Networks-From Software-Defined Radio to Software-Defined Networking
    Macedo, Daniel F.
    Guedes, Dorgival
    Vieira, Luiz F. M.
    Vieira, Marcos A. M.
    Nogueira, Michele
    IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2015, 17 (02): : 1102 - 1125
  • [37] Toward Network-based DDoS Detection in Software-defined Networks
    Jevtic, Stefan
    Lotfalizadeh, Hamidreza
    Kim, Dongsoo S.
    PROCEEDINGS OF THE 12TH INTERNATIONAL CONFERENCE ON UBIQUITOUS INFORMATION MANAGEMENT AND COMMUNICATION (IMCOM 2018), 2018,
  • [38] Toward a Cyber Resilient and Secure Microgrid Using Software-Defined Networking
    Jin, Dong
    Li, Zhiyi
    Hannon, Christopher
    Chen, Chen
    Wang, Jianhui
    Shahidehpour, Mohammad
    Lee, Cheol Won
    IEEE TRANSACTIONS ON SMART GRID, 2017, 8 (05) : 2494 - 2504
  • [39] On SDPN: Integrating the Software-Defined Perimeter (SDP) and the Software-Defined Network (SDN) Paradigms
    Lefebvre, Michael
    Engels, Daniel W.
    Nair, Suku
    2022 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2022, : 353 - 358
  • [40] Toward Plug-and-Play Software-Defined Elastic Optical Networks
    Cugini, Filippo
    Paolucci, Francesco
    Fresi, Francesco
    Meloni, Gianluca
    Sambo, Nicola
    Poti, Luca
    D'Errico, Antonio
    Castoldi, Piero
    JOURNAL OF LIGHTWAVE TECHNOLOGY, 2016, 34 (06) : 1494 - 1500