• DocumentCode
    3175357
  • Title

    Q-ESP: A QoS-Compliant Security Protocol to Enrich IPSec Framework

  • Author

    Mostafa, Mahmoud ; El Kalam, Anas Abou ; Fraboul, Christian

  • Author_Institution
    IRIT-CNRS, Univ. de Toulouse, Toulouse, France
  • fYear
    2009
  • fDate
    20-23 Dec. 2009
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    IPSec is a protocol that allows to make secure connections between branch offices and allows secure VPN accesses. However, the efforts to improve IPSec are still under way; one aspect of this improvement is to take quality of service (QoS) requirements into account. QoS is the ability of the network to provide a service at an assured service level while optimizing the global usage of network resources. The QoS level that a flow receives depends on a six-bit identifier in the IP header; the so-called differentiated services code point (DSCP). Basically, multi-field classifiers classify a packet by inspecting IP/TCP headers, to decide how the packet should be processed. The current IPSec standard does hardly offer any guidance to do this, because the existing IPSec ESP security protocol hides much of this information in its encrypted payloads, preventing network control devices such as routers and switches from utilizing this information in performing classification appropriately. To solve this problem, we propose a QoS-friendly encapsulated security payload (Q-ESP) as a new IPSec security protocol that provides both security and QoS supports. We also present our NetBSD kernel-based implementation as well as our evaluation results of Q-ESP.
  • Keywords
    DiffServ networks; IP networks; cryptographic protocols; quality of service; telecommunication security; transport protocols; virtual private networks; IP header; IPSec ESP security protocol; NetBSD kernel; Q-ESP; QoS level; QoS-compliant security protocol; QoS-friendly encapsulated security payload; TCP header; assured service level; differentiated services code point; encrypted payload; multifield classifiers; network resource; quality of service; secure VPN access; secure connection; Access protocols; Admission control; Cryptography; Data security; Electrostatic precipitators; Information security; Payloads; Quality of service; Telecommunication traffic; Transport protocols;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    New Technologies, Mobility and Security (NTMS), 2009 3rd International Conference on
  • Conference_Location
    Cairo
  • Print_ISBN
    978-1-4244-4765-7
  • Type

    conf

  • DOI
    10.1109/NTMS.2009.5384762
  • Filename
    5384762