SDIG: Toward Software-Defined IPsec Gateway

被引:0
|
作者
Li, Wei [1 ]
Lin, Fengxu [1 ]
Sun, Guanchao [1 ]
机构
[1] Beihang Univ, Sch Comp Sci & Engn, Key Lab Beijing Network Technol, Beijing, Peoples R China
来源
2016 IEEE 24TH INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP) | 2016年
关键词
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
The current IPsec gateway integrates many functions of IPsec operation, tunnel management and forwarding decision, which makes the IPsec gateway complicated in maintenance and deployment. The problem of maintaining such devices prevents IPsec VPN from applying widely. The emergence of SDN provides an innovative way to decouple the control plane and data plane. In this paper, a Software-Defined IPsec Gateway (SDIG) is proposed to achieve net2net IPsec VPN. Different from the traditional IPsec gateway, the SDIG device serves as a data plane equipment that just concentrates on exchanging IKE packets and encrypting/decrypting IP packets. A global view of SDIG devices can be constructed in the SDN controller by collecting the status of all devices. Therefore the controller can manage and configure SDIG devices centrally, and simplify deployment complexity. Outbound IP packets for the SDIG device can be viewed as a trigger to control the establishment of IPsec tunnels. The SDIG device and the controller exchange information through a customized southbound protocol. The prototype system of SDIG is implemented, and the preliminary experimental results show that the method is feasible and effective.
引用
收藏
页数:8
相关论文
共 50 条
  • [41] Iris: Toward Intelligent Reliable Routing for Software-Defined Satellite Networks
    Wei, Wenting
    Fu, Liying
    Gu, Huaxi
    Lu, Xueyu
    Liu, Lei
    Mumtaz, Shahid
    Guizani, Mohsen
    IEEE TRANSACTIONS ON COMMUNICATIONS, 2025, 73 (01) : 454 - 468
  • [42] Programmable IP Service Gateway for Software-Defined Networking: Assisting Easy Composition of Service Overlays
    Jo, Jinyong
    Lee, Soyeon
    Kim, JongWon
    IEICE TRANSACTIONS ON COMMUNICATIONS, 2013, E96B (07) : 1918 - 1929
  • [43] Software-defined product features
    Barwasser A.
    Lentes J.
    Riedel O.
    Zimmermann N.
    ZWF Zeitschrift fuer Wirtschaftlichen Fabrikbetrieb, 2020, 115 (11): : 824 - 828
  • [44] A Survey on Software-Defined Networking
    Xia, Wenfeng
    Wen, Yonggang
    Foh, Chuan Heng
    Niyato, Dusit
    Xie, Haiyong
    IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2015, 17 (01): : 27 - 51
  • [45] Languages for Software-Defined Networks
    Foster, Nate
    Guha, Arjun
    Reitblatt, Mark
    Story, Alec
    Freedman, Michael J.
    Katta, Naga Praveen
    Monsanto, Christopher
    Reich, Joshua
    Rexford, Jennifer
    Schlesinger, Cole
    Walker, David
    Harrison, Major Robert
    IEEE COMMUNICATIONS MAGAZINE, 2013, 51 (02) : 128 - 134
  • [46] Software-Defined Data Center
    Ghazanfar Ali
    Jie Hu
    Bhumip Khasnabish
    ZTE Communications, 2013, 11 (04) : 2 - 7
  • [47] Software-Defined Vehicular Backhaul
    Baron, Benjamin
    Spathis, Promethee
    Rivano, Herve
    de Amorim, Marcelo Dias
    Viniotis, Yannis
    Clarke, Joseph
    2014 IFIP Wireless Days (WD), 2014,
  • [48] Modular software-defined radio
    Rhiemeier A.-R.
    EURASIP Journal on Wireless Communications and Networking, 2005 (3) : 333 - 342
  • [49] Software-Defined Networking: A survey
    Farhady, Hamid
    Lee, HyunYong
    Nakao, Akihiro
    COMPUTER NETWORKS, 2015, 81 : 79 - 95
  • [50] The Software-Defined Network Revolution
    Canini, Marco
    Jungers, Raphael
    ERCIM NEWS, 2014, (97): : 18 - 19