DocumentCode
653783
Title
Secure hierarchical Virtual Private LAN Services for provider provisioned networks
Author
Liyanage, Mohan ; Ylianttila, Mika ; Gurtov, Andrei
Author_Institution
Centre for Wireless Commun., Univ. of Oulu, Oulu, Finland
fYear
2013
fDate
14-16 Oct. 2013
Firstpage
233
Lastpage
241
Abstract
Virtual Private LAN Service (VPLS) is a widely used Layer 2 (L2) Virtual Private Network (VPN) service. Initially, VPLS architectures were proposed as flat architectures. They were used only for small and medium scale networks due to the lack of scalability. Hierarchical VPLS architectures are proposed to overcome these scalability issues. On the other hand, the security is an indispensable factor of a VPLS since it delivers the private user frames via an untrusted public network. However, the existing hierarchical architectures unable to provide a sufficient level of security for a VPLS network. In this paper, we propose a novel hierarchical VPLS architecture based on Host Identity Protocol (HIP). It provides a secure VPLS network by delivering vital security features such as authentication, confidentiality, integrity, availability, secure control protocol and robustness to the known attacks. The simulations verify that our proposal provides the control, forwarding and security plane scalability by reducing the number of tunnels in the network as well as the number of keys stored at a node and the network. Finally, the simulation results confirm that the control protocol of the proposed architecture is protected from IP based attacks.
Keywords
computer network security; local area networks; protocols; virtual private networks; IP based attacks; Internet protocol; VPN service; authentication; availability; confidentiality; control plane scalability; forwarding plane scalability; hierarchical VPLS architecture; host identity protocol; integrity; local area networks; provider provisioned networks; secure VPLS network; secure control protocol; secure hierarchical virtual private LAN services; security features; security plane scalability; virtual private network service; Authentication; Cryptography; Hip; Protocols; Scalability; Virtual private networks; Host Identity Protocol; Security; Virtual Private LAN Service; Virtual Private Networks;
fLanguage
English
Publisher
ieee
Conference_Titel
Communications and Network Security (CNS), 2013 IEEE Conference on
Conference_Location
National Harbor, MD
Type
conf
DOI
10.1109/CNS.2013.6682712
Filename
6682712
Link To Document