• DocumentCode
    2462734
  • Title

    A distributed object-based IPSec multi-tunnels concurrent architecture

  • Author

    Wang, Song ; Lv, Hongbing

  • Author_Institution
    Coll. of Comput. Sci. & Technol., Zhejiang Univ., Hangzhou, China
  • fYear
    2011
  • fDate
    21-23 Oct. 2011
  • Firstpage
    471
  • Lastpage
    476
  • Abstract
    In the existing IPSec architecture, in which tunnel is built in kernel, the number of concurrent tunnels is restricted by IP address configured on the machine and user can not control the process of establishing tunnel. This brings inconvenience when we use personal computer to measure the performance parameters of VPN Gateway (e.g. the maximum number of concurrent tunnels and the maximum rate of the new tunnels built). In order to solve this problem, this paper presents a novel IPSec multi-tunnels concurrent architecture which uses distributed objects to build tunnels in user space. The architecture privodes one Console which are used to control all AgentNodes and multiple AgentNodes which are used to build tunnels. In AgentNode, the negotiation processing of tunnels, the IPSec processing of packets and the protocol processing of TCP/IP are all completed in user space by objects. Meanwhile, AgentNode uses virtual IP address instead of local IP address to negotiate tunnel and the number of concurrent tunnels will be unlimited (only limited by memory). Moreover, based on distributed architecture, the number of AgentNode can be arbitrarily extended. Therefore, the system has a great deal of flexibility on the number of concurrent tunnels and the rate of tunnel establishment, which helps to accurately measure the performance parameters of VPN Gateway.
  • Keywords
    IP networks; internetworking; transport protocols; virtual private networks; IPSec multitunnel concurrent architecture; TCP/IP; VPN gateway; concurrent tunnel; distributed object; multiple AgentNodes; virtual IP address; Computer architecture; IP networks; Kernel; Logic gates; Protocols; Security; Virtual private networks; AgentNode; Distributed; Distributed Object; IPSec; Kernel space; Multi-tunnels concurrent; Object; SA; User space;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computational Problem-Solving (ICCP), 2011 International Conference on
  • Conference_Location
    Chengdu
  • Print_ISBN
    978-1-4577-0602-8
  • Electronic_ISBN
    978-1-4577-0601-1
  • Type

    conf

  • DOI
    10.1109/ICCPS.2011.6089933
  • Filename
    6089933