[1] Beihang Univ, Sch Comp Sci & Engn, Key Lab Beijing Network Technol, Beijing, Peoples R China
来源:
2016 IEEE 24TH INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP)
|
2016年
关键词:
D O I:
暂无
中图分类号:
TM [电工技术];
TN [电子技术、通信技术];
学科分类号:
0808 ;
0809 ;
摘要:
The current IPsec gateway integrates many functions of IPsec operation, tunnel management and forwarding decision, which makes the IPsec gateway complicated in maintenance and deployment. The problem of maintaining such devices prevents IPsec VPN from applying widely. The emergence of SDN provides an innovative way to decouple the control plane and data plane. In this paper, a Software-Defined IPsec Gateway (SDIG) is proposed to achieve net2net IPsec VPN. Different from the traditional IPsec gateway, the SDIG device serves as a data plane equipment that just concentrates on exchanging IKE packets and encrypting/decrypting IP packets. A global view of SDIG devices can be constructed in the SDN controller by collecting the status of all devices. Therefore the controller can manage and configure SDIG devices centrally, and simplify deployment complexity. Outbound IP packets for the SDIG device can be viewed as a trigger to control the establishment of IPsec tunnels. The SDIG device and the controller exchange information through a customized southbound protocol. The prototype system of SDIG is implemented, and the preliminary experimental results show that the method is feasible and effective.
机构:
Universität Stuttgart und Promovierte, Fakultät der Konstruktions- und FertigungstechnikUniversität Stuttgart und Promovierte, Fakultät der Konstruktions- und Fertigungstechnik
Barwasser A.
Lentes J.
论文数: 0引用数: 0
h-index: 0
机构:Universität Stuttgart und Promovierte, Fakultät der Konstruktions- und Fertigungstechnik
Lentes J.
Riedel O.
论文数: 0引用数: 0
h-index: 0
机构:Universität Stuttgart und Promovierte, Fakultät der Konstruktions- und Fertigungstechnik
Riedel O.
Zimmermann N.
论文数: 0引用数: 0
h-index: 0
机构:Universität Stuttgart und Promovierte, Fakultät der Konstruktions- und Fertigungstechnik
机构:
Univ Tokyo, Grad Sch Interdisciplinary Informat Studies, Bunkyo Ku, Tokyo 1130033, JapanUniv Tokyo, Grad Sch Interdisciplinary Informat Studies, Bunkyo Ku, Tokyo 1130033, Japan
Farhady, Hamid
Lee, HyunYong
论文数: 0引用数: 0
h-index: 0
机构:
Univ Tokyo, Grad Sch Interdisciplinary Informat Studies, Bunkyo Ku, Tokyo 1130033, JapanUniv Tokyo, Grad Sch Interdisciplinary Informat Studies, Bunkyo Ku, Tokyo 1130033, Japan