Title :
A shared secure server for multiple closed networks
Author :
Terao, Kazuyuki ; Ono, Satoshi
Author_Institution :
NTT Software Labs., Tokyo, Japan
Abstract :
A method is proposed that enables a shared single server to provide secure, customised services to multiple closed networks by using a new network address translation (NAT) function called root-side NAT. This method promises to overcome two problems involved in using agent technology in providing advanced communications services to mobile computers. Due to the shortage of global IP addresses, we are forced to dynamically assign a global address to a host at connection set-up time, or to statically assign a local address to a host. The former has a problem that a connection cannot be initiated from a server to a mobile host. The latter has a problem of duplicate addresses among closed networks, when a single server on the Internet provides secure, customized services to multiple closed networks. Our proposed method is basically based on the static assignment of local addresses. Each of multiple closed networks is connected to a server´s network through a PPP (point-to-point protocol) connection. The address duplication problem is solved by translation of IP addresses using not only the IP addresses of a packet (both the source address and the destination address) but also a PPP connection identifier through which the closed network is connected to a server. This enables the server on the Internet to provide a common service such as a ticket service to multiple closed networks
Keywords :
Internet; LAN interconnection; mobile computing; network servers; telecommunication security; transport protocols; Internet protocol; PPP connection identifier; agent technology; common service provision; communications services; connection setup time; destination address; duplicate addresses; dynamic address assignment; global IP addresses; local address; mobile computers; mobile host; multiple closed networks; point-to-point protocol; root-side network address translation; secure customised services; shared secure server; source address; static address assignment; ticket service; Application software; Computer networks; IP networks; Mobile communication; Mobile computing; Network address translation; Network servers; Protocols; Web and internet services; Web server;
Conference_Titel :
Internet Workshop, 1999. IWS 99
Conference_Location :
Osaka
Print_ISBN :
0-7803-5925-9
DOI :
10.1109/IWS.1999.810913