DocumentCode
3622426
Title
IPSEC over satellite links: a new flow identification method
Author
D.D. Isci;F. Alagoz;M.U. Caglayan
Author_Institution
Dept. of Comput. Eng., Bogazici Univ., Istanbul, Turkey
fYear
2006
fDate
6/28/1905 12:00:00 AM
Firstpage
140
Lastpage
145
Abstract
Acknowledgment based transport protocols such as TCP have low performance in satellite links, which are characterized by high latencies and high bit error rates. Low performance of TCP in satellite links is due to the fact that TCP packet losses are assumed to be the cause of congestion in the network, which turns out to be an invalid assumption for satellite links. TCP performance enhancing proxies (PEPs) are widely used to overcome the limitations of TCP over satellite links. However, when end-to-end security mechanisms, such as IPSEC, are used, TCP PEP mechanisms can not be used. IPSEC encrypts and/or authenticates the packet header fields that the PEP needs to read or modify. We propose a novel mechanism to integrate IPSEC with TCP PEPs. In our approach, a cryptographic hash of flow identification information is generated and stored in the IP header. The TCP sequence number is also stored in the IP header. Using the hash value and sequence numbers, the PEP is able to match packets and corresponding acknowledgements to regulate the flow. This approach is applicable to PEP mechanisms that need read access to the IP and TCP headers
Keywords
"Satellites","Bit error rate","Delay","Cryptography","TCPIP","Security","Transport protocols","Performance loss","High performance computing","Computer networks"
Publisher
ieee
Conference_Titel
Computer Networks, 2006 International Symposium on
Print_ISBN
1-4244-0491-6
Type
conf
DOI
10.1109/ISCN.2006.1662523
Filename
1662523
Link To Document