DocumentCode :
3622426
Title :
IPSEC over satellite links: a new flow identification method
Author :
D.D. Isci;F. Alagoz;M.U. Caglayan
Author_Institution :
Dept. of Comput. Eng., Bogazici Univ., Istanbul, Turkey
fYear :
2006
fDate :
6/28/1905 12:00:00 AM
Firstpage :
140
Lastpage :
145
Abstract :
Acknowledgment based transport protocols such as TCP have low performance in satellite links, which are characterized by high latencies and high bit error rates. Low performance of TCP in satellite links is due to the fact that TCP packet losses are assumed to be the cause of congestion in the network, which turns out to be an invalid assumption for satellite links. TCP performance enhancing proxies (PEPs) are widely used to overcome the limitations of TCP over satellite links. However, when end-to-end security mechanisms, such as IPSEC, are used, TCP PEP mechanisms can not be used. IPSEC encrypts and/or authenticates the packet header fields that the PEP needs to read or modify. We propose a novel mechanism to integrate IPSEC with TCP PEPs. In our approach, a cryptographic hash of flow identification information is generated and stored in the IP header. The TCP sequence number is also stored in the IP header. Using the hash value and sequence numbers, the PEP is able to match packets and corresponding acknowledgements to regulate the flow. This approach is applicable to PEP mechanisms that need read access to the IP and TCP headers
Keywords :
"Satellites","Bit error rate","Delay","Cryptography","TCPIP","Security","Transport protocols","Performance loss","High performance computing","Computer networks"
Publisher :
ieee
Conference_Titel :
Computer Networks, 2006 International Symposium on
Print_ISBN :
1-4244-0491-6
Type :
conf
DOI :
10.1109/ISCN.2006.1662523
Filename :
1662523
Link To Document :
بازگشت