• DocumentCode
    2896609
  • Title

    Public Key-Based Rendezvous Infrastructure for Secure and Flexible Private Networking

  • Author

    Kubota, Ayumu ; Miyake, Yutaka

  • Author_Institution
    KDDI R&D Labs. Inc., Fujimino, Japan
  • fYear
    2009
  • fDate
    14-18 June 2009
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    Secure private networking over the Internet is difficult especially when trying to form a new network with private servers and hosts that belong to different administrative domains. Although such form of private network is useful as a closed group communication environment, simply applying existing VPN technologies is not sufficient. Not to mention common problems such as NAT and firewall traversal, potential collision of private IP addresses among networks makes their interconnection extremely difficult. In addition, access control inside the private network is required in order to prevent inappropriate access to other users´ network resources. In this paper, we propose a public key-based rendezvous infrastructure and user-side VPN agents that can instantly interconnect multiple private networks while automatically mediating address collision and enforcing appropriate access control on cross domain communication by utilizing Zeroconf technologies. We built the rendezvous infrastructure using DHT technologies in order to achieve good scalability and implemented the VPN agent for Linux-based embedded devices so that users can run it on their residential gateway or wireless router.
  • Keywords
    Internet; authorisation; public key cryptography; security of data; telecommunication security; virtual private networks; DHT technologies; Internet; Linux-based embedded devices; NAT; VPN technologies; Zeroconf technologies; access control; address collision; closed group communication environment; cross domain communication; firewall traversal; flexible private networking; public key-based rendezvous infrastructure; residential gateway; scalability; secure private networking; user-side VPN agent; wireless router; Access control; Communications Society; Home automation; IP networks; Network address translation; Network servers; Virtual machining; Virtual private networks; Web and internet services; Web server;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communications, 2009. ICC '09. IEEE International Conference on
  • Conference_Location
    Dresden
  • ISSN
    1938-1883
  • Print_ISBN
    978-1-4244-3435-0
  • Electronic_ISBN
    1938-1883
  • Type

    conf

  • DOI
    10.1109/ICC.2009.5199375
  • Filename
    5199375