通过对GDOI(Group Domain of Interpretation)协议的详细分析,针对GDOI应用于IPSec时只适用于单源多播的局限性,提出改进建议。描述改进后GDOI的工作原理,并在用户主机端进行部分模拟验证,实验表明,改进后的GDOI能够更好地适用于多源多...通过对GDOI(Group Domain of Interpretation)协议的详细分析,针对GDOI应用于IPSec时只适用于单源多播的局限性,提出改进建议。描述改进后GDOI的工作原理,并在用户主机端进行部分模拟验证,实验表明,改进后的GDOI能够更好地适用于多源多播,并具有一定的可行性。展开更多
Network security protocols such as IPsec have been used for many years to ensure robust end-to-end communication and are important in the context of SDN. Despite the widespread installation of IPsec to date, per-packe...Network security protocols such as IPsec have been used for many years to ensure robust end-to-end communication and are important in the context of SDN. Despite the widespread installation of IPsec to date, per-packet protection offered by the protocol is not very compatible with OpenFlow and tlow-like behavior. OpenFlow architecture cannot aggregate IPsee-ESP flows in transport mode or tunnel mode because layer-3 information is encrypted and therefore unreadable. In this paper, we propose using the Security Parameter Index (SPI) of IPsec within the OpenFlow architecture to identify and direct IPsec flows. This enables IPsec to conform to the packet-based behavior of OpenFlow architecture. In addition, by distinguishing between IPsec flows, the architecture is particularly suited to secure group communication.展开更多
文摘通过对GDOI(Group Domain of Interpretation)协议的详细分析,针对GDOI应用于IPSec时只适用于单源多播的局限性,提出改进建议。描述改进后GDOI的工作原理,并在用户主机端进行部分模拟验证,实验表明,改进后的GDOI能够更好地适用于多源多播,并具有一定的可行性。
文摘Network security protocols such as IPsec have been used for many years to ensure robust end-to-end communication and are important in the context of SDN. Despite the widespread installation of IPsec to date, per-packet protection offered by the protocol is not very compatible with OpenFlow and tlow-like behavior. OpenFlow architecture cannot aggregate IPsee-ESP flows in transport mode or tunnel mode because layer-3 information is encrypted and therefore unreadable. In this paper, we propose using the Security Parameter Index (SPI) of IPsec within the OpenFlow architecture to identify and direct IPsec flows. This enables IPsec to conform to the packet-based behavior of OpenFlow architecture. In addition, by distinguishing between IPsec flows, the architecture is particularly suited to secure group communication.