• DocumentCode
    3622426
  • Title

    IPSEC over satellite links: a new flow identification method

  • Author

    D.D. Isci;F. Alagoz;M.U. Caglayan

  • Author_Institution
    Dept. of Comput. Eng., Bogazici Univ., Istanbul, Turkey
  • fYear
    2006
  • fDate
    6/28/1905 12:00:00 AM
  • Firstpage
    140
  • Lastpage
    145
  • Abstract
    Acknowledgment based transport protocols such as TCP have low performance in satellite links, which are characterized by high latencies and high bit error rates. Low performance of TCP in satellite links is due to the fact that TCP packet losses are assumed to be the cause of congestion in the network, which turns out to be an invalid assumption for satellite links. TCP performance enhancing proxies (PEPs) are widely used to overcome the limitations of TCP over satellite links. However, when end-to-end security mechanisms, such as IPSEC, are used, TCP PEP mechanisms can not be used. IPSEC encrypts and/or authenticates the packet header fields that the PEP needs to read or modify. We propose a novel mechanism to integrate IPSEC with TCP PEPs. In our approach, a cryptographic hash of flow identification information is generated and stored in the IP header. The TCP sequence number is also stored in the IP header. Using the hash value and sequence numbers, the PEP is able to match packets and corresponding acknowledgements to regulate the flow. This approach is applicable to PEP mechanisms that need read access to the IP and TCP headers
  • Keywords
    "Satellites","Bit error rate","Delay","Cryptography","TCPIP","Security","Transport protocols","Performance loss","High performance computing","Computer networks"
  • Publisher
    ieee
  • Conference_Titel
    Computer Networks, 2006 International Symposium on
  • Print_ISBN
    1-4244-0491-6
  • Type

    conf

  • DOI
    10.1109/ISCN.2006.1662523
  • Filename
    1662523