Convergence of IPsec in presence of resets

被引:0
|
作者
Huang, CT [1 ]
Gouda, MG [1 ]
Elnozahy, EN [1 ]
机构
[1] Univ Texas, Dept Comp Sci, Austin, TX 78712 USA
来源
23RD INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS WORKSHOPS | 2003年
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
IPsec is the current security standard for the Internet Protocol IP According to IPsec, a selected computer pair (p, q) in the Internet can be designated a "security association". This designation guarantees that all sent IP messages whose original source is computer p and whose ultimate destination is computer q cannot be replayed in the future, (by an adversary between p and q) and still be received by q as fresh messages from p. This guarantee is provided by adding increasing sequence numbers to all IP messages sent from p to q. Thus, p needs to always remember the sequence number (of the last sent message, and q needs to always remember the sequence number of the last received message. Unfortunately, when computer p or q is reset these sequence numbers can be forgotten, and this leads to two bad possibilities: unbounded number of fresh messages from p can be discarded by q, and unbounded number of replayed messages can be accepted by q. In this paper, we propose two operations, "SAVE" and "FETCH" to prevent these possibilities. The SAVE operation can be used to store the last sent sequence number in persistent memory of p once every K-p sent messages, and can be used to store the last received sequence number in persistent memory of q once every K-q received messages. The FETCH operation can be used to fetch the last stored sequence number for a computer when that computer wakes tip after a reset. We show that the following three conditions hold when SAVE and FETCH are adopted in both p and q. First, when p is reset, at most 2K(p) sequence numbers will be lost but no fresh message sent from p to q will be discarded if no message reorder occurs. Second, when q is reset, the number of discarded fresh messages is bounded by 2K(q). In either case, no replayed message will be accepted by q.
引用
收藏
页码:22 / 27
页数:6
相关论文
共 50 条
  • [31] On the Convergence of Gossip Learning in the Presence of Node Inaccessibility
    Liu, Tian
    Cui, Yue
    Hu, Xueyang
    Xu, Yecheng
    Liu, Bo
    ICC 2024 - IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, 2024, : 4197 - 4202
  • [32] CONVERGENCE OF RANDOM SEARCH METHOD IN PRESENCE OF NOISE
    GURIN, LS
    RASTRIGI.LA
    AUTOMATION AND REMOTE CONTROL, 1965, 26 (09) : 1505 - &
  • [34] THE CONVERGENCE OF THE AGE METHOD IN THE PRESENCE OF UNSYMMETRIC OPERATORS
    EVANS, DJ
    LI, CJ
    ALWALI, AA
    INTERNATIONAL JOURNAL OF COMPUTER MATHEMATICS, 1991, 41 (1-2) : 115 - 122
  • [35] Implementing IPsec
    Keromytis, AD
    Ioannidis, J
    Smith, JM
    GLOBECOM 97 - IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, CONFERENCE RECORD, VOLS 1-3, 1997, : 1948 - 1952
  • [36] IPsec clustering
    Nuopponen, A
    Vaarala, S
    Virtanen, T
    SECURITY AND PROTECTION IN INFORMATION PROCESSING SYSTEMS, 2004, 147 : 367 - 379
  • [37] Performance analysis of OSPF and EIGRP convergence through IPsec tunnel using Multi-homing BGP connection
    Basit, Zeeshan
    Tabassum, Mujahid
    Sharma, Tripti
    Furqan, Muhammed
    Quadir Md, Abdul
    Materials Today: Proceedings, 2022, 62 : 4853 - 4861
  • [38] Performance analysis of OSPF and EIGRP convergence through IPsec tunnel using Multi-homing BGP connection
    Basit, Zeeshan
    Tabassum, Mujahid
    Sharma, Tripti
    Furqan, Muhammed
    Md, Abdul Quadir
    MATERIALS TODAY-PROCEEDINGS, 2022, 62 : 4853 - 4861
  • [40] Risperidone resets the circadian clock in mice
    Cherukalady, Rajeev
    Kumar, Dhanananajay
    Basu, Priyoneel
    Singaravel, Muniyandi
    BIOLOGICAL RHYTHM RESEARCH, 2017, 48 (04) : 583 - 591