• DocumentCode
    2895771
  • Title

    Performance-Aware Security of Unicast Communication in Hybrid Satellite Networks

  • Author

    Roy-Chowdhury, Ayan ; Baras, John S.

  • Author_Institution
    Electr. & Comput. Eng., Univ. of Maryland, College Park, MD, USA
  • fYear
    2009
  • fDate
    14-18 June 2009
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    In this work, we address the performance problems that arise when unicast security protocols IPSEC and SSL are applied for securing the end-to-end communication in hybrid satellite networks. Satellite networks use TCP and HTTP performance-enhancing proxy servers to overcome the adverse effect of the large delay-bandwidth product of the satellite channel. However, the proxy servers cannot function when IPSEC and SSL are used for secure unicast communication in hybrid satellite networks. We therefore propose the use of the layered IPSEC (LES) protocol as an alternative to IPSEC for network-layer security. We describe a modification to the Internet key exchange protocol if dynamic key establishment is needed for layered IPSEC. For application-level security of Web browsing with acceptable end-to-end delay, we propose the dual-mode SSL protocol (DSSL) to be used instead of SSL. We describe how LES and DSSL protocols achieve the desired end-to-end communication security while allowing the TCP and HTTP proxy servers to function correctly. Through simulation studies, we quantify the improvement in performance that is achieved using our proposed protocols, compared to traditional IPSEC and SSL.
  • Keywords
    Internet; computer network performance evaluation; file servers; satellite communication; telecommunication security; transport protocols; HTTP; Internet key exchange protocol; TCP; Web browsing; dual-mode secure socket layer protocol; dynamic key establishment; end-to-end communication security; hybrid satellite networks; layered Internet security protocol; network-layer security; performance-aware security; performance-enhancing proxy servers; satellite channel; unicast communication; unicast security protocols; Artificial satellites; Cryptography; Delay; HTML; Internet; Network servers; Protocols; TCPIP; Unicast; Web server;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communications, 2009. ICC '09. IEEE International Conference on
  • Conference_Location
    Dresden
  • ISSN
    1938-1883
  • Print_ISBN
    978-1-4244-3435-0
  • Electronic_ISBN
    1938-1883
  • Type

    conf

  • DOI
    10.1109/ICC.2009.5199335
  • Filename
    5199335