E2E: An Optimized IPsec Architecture for Secure And Fast Offload

被引:3
|
作者
Migault, Daniel
Palomares, Daniel
Herbert, Emmanuel
You, Wei
Ganne, Gabriel
Arfaoui, Ghada
Laurent, Maryline
机构
来源
2012 SEVENTH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES) | 2012年
关键词
IPsec; IKEv2; MOBIKE; MOBIKE-X; Mobility; Multihoming; TRANSPORT;
D O I
10.1109/ARES.2012.80
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
When mobile End Users are offloaded from a Radio Access Network (RAN) to a WLAN, current I-WLAN [1] offloaded architectures consider traffic converging to a common Security Gateway. In this paper, we propose an alternative End-to-End security (E2E) architecture based on the MOBIKE-X [2] protocol, which extends the MOBIKE [3] Mobility and Multihoming features to Multiple Interfaces and to the Transport mode of IPsec. The benefits of this E2E architecture are mostly load reduction and a better End User experience. First, E2E offloads the ISP CORE and backhaul networks, then E2E uses IPsec Transport mode instead of Tunnel mode, which removes networking and security overhead. This reduces CPU load by 20%, enhances Mobility and Multihoming operations by about 15%, and makes the system 2.9 times more reactive for detecting modifications of interfaces.
引用
收藏
页码:365 / 374
页数:10
相关论文
共 50 条
  • [1] Measurement System Architecture for Measuring Network Parameters of e2e Services
    Kulik, Vyacheslav
    Kirichek, Ruslan
    Borodin, Alexey
    Koucheryavy, Andrey
    DISTRIBUTED COMPUTER AND COMMUNICATION NETWORKS (DCCN 2017), 2017, 700 : 291 - 306
  • [2] DeepIntent: ImplicitIntent based Android IDS with E2E Deep Learning architecture
    Sewak, Mohit
    Sahay, Sanjay K.
    Rathore, Hemant
    2020 IEEE 31ST ANNUAL INTERNATIONAL SYMPOSIUM ON PERSONAL, INDOOR AND MOBILE RADIO COMMUNICATIONS (IEEE PIMRC), 2020,
  • [3] On Persistent Implications of E2E Testing
    Frajtak, Karel
    Cerny, Tomas
    ENTERPRISE INFORMATION SYSTEMS, ICEIS 2021, 2022, 455 : 326 - 338
  • [4] E2E数据采集网络
    张振华
    宫海波
    李国星
    中国科技信息, 2017, (06) : 67 - 70
  • [5] E2E Service Class Mapping in Heterogeneous IOUT: SDN-Based Architecture
    Ali, Jehad
    Roh, Byeong-Hee
    Alzamil, Zamil S.
    IEEE Internet of Things Magazine, 2022, 5 (04): : 48 - 52
  • [6] Analysis of E2E Delay and Wiring Harness in In-Vehicle Network with Zonal Architecture
    Park, Chulsun
    Cui, Chengyu
    Park, Sungkwon
    SENSORS, 2024, 24 (10)
  • [7] Managing Mobile Relays for Secure E2E Connectivity of Low-Power IoT Devices
    Porambage, Pawani
    Manzoor, Ahsan
    Liyanage, Madhsanka
    Gurtov, Andrei
    Ylianttila, Mika
    2019 16TH IEEE ANNUAL CONSUMER COMMUNICATIONS & NETWORKING CONFERENCE (CCNC), 2019,
  • [8] POSTER: An E2E Trusted Cloud Infrastructure
    Wang, Juan
    Zhao, Bo
    Zhang, Huanguo
    Yan, Fei
    Zhang, Liqiang
    Yu, Fajiang
    Hu, Hongxin
    CCS'14: PROCEEDINGS OF THE 21ST ACM CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2014, : 1517 - 1519
  • [9] A NOVEL PRICING-BASED RESOURCE ALLOCATION ARCHITECTURE AND IMPLEMENT FOR E2E HETEROGENEOUS NETWORKS
    Xie, Bing
    Zhou, Wenan
    Chen, Wei
    Song, Junde
    PROCEEDINGS OF 2009 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS TECHNOLOGY AND APPLICATIONS, 2009, : 851 - 855
  • [10] Vulnerability studies of E2E voting systems
    Rura, Lauretha
    Issac, Biju
    Haldar, Manas
    Lecture Notes in Electrical Engineering, 2015, 313 : 223 - 231