Title :
Packet routing over crypto-partitioned networks
Author :
Albuquerque, Marcelo M. ; Henderson, Thomas R. ; Bae, Kyle ; Kim, Jae H.
Author_Institution :
Boeing Phantom Works, Seattle, WA, USA
Abstract :
In this paper, we consider the performance of Internet packet routing on an overlay network formed by meshes of IPsec-encrypted tunnels. The motivation of the study is to verify the assumption that IPsec gateways can transparently tunnel secure red (encrypted) network traffic over a black (unencrypted) wireless network, making the black multi-hop backbone appear to the red routers as a single-hop broadcast-based network. Using simulation, we consider the impact of a composite red/black network architecture on the performance of the open shortest path first (OSPF) routing protocol. We initially present a high-level description of the simulation modules and the IPsec gateways and modifications for the Multicast extension of OSPF (MOSPF) for the QualNet simulator. The simulation scenarios, based on a typical crypto-partitioned network environment, are described along with the metrics used for measuring the network performance. We compare red OSPF overhead in composite red/black networks to that of red only wired networks, and find that the wireless network, instead of transparently providing full-mesh connectivity between security gateways, negatively affects the red network performance, and we identify some of the key causes for this degradation. We also suggest what are some potential areas for more detailed investigation in order to identify solutions that may mitigate these unwanted effects.
Keywords :
Internet; cryptography; internetworking; military communication; multicast protocols; packet radio networks; routing protocols; telecommunication traffic; IPsec gateways; IPsec-encrypted tunnels; Internet packet routing; MOSPF; Multicast extension of OSPF; OSPF routing protocol; QualNet simulator; black wireless network; composite red/black network architecture; crypto-partitioned networks; encrypted network traffic; network performance; open shortest path first routing protocol; overlay network; secure red network traffic; single-hop broadcast-based network; unencrypted wireless network; Broadcasting; Cryptography; IP networks; Routing protocols; Spine; Spread spectrum communication; Telecommunication traffic; Traffic control; Wireless mesh networks; Wireless networks;
Conference_Titel :
Military Communications Conference, 2004. MILCOM 2004. 2004 IEEE
Print_ISBN :
0-7803-8847-X
DOI :
10.1109/MILCOM.2004.1494869