Network security protocols such as IPsec have been used for many years to ensure robust end-to-end communication and are important in the context of SDN. Despite the widespread installation of IPsec to date, per-packe...Network security protocols such as IPsec have been used for many years to ensure robust end-to-end communication and are important in the context of SDN. Despite the widespread installation of IPsec to date, per-packet protection offered by the protocol is not very compatible with OpenFlow and tlow-like behavior. OpenFlow architecture cannot aggregate IPsee-ESP flows in transport mode or tunnel mode because layer-3 information is encrypted and therefore unreadable. In this paper, we propose using the Security Parameter Index (SPI) of IPsec within the OpenFlow architecture to identify and direct IPsec flows. This enables IPsec to conform to the packet-based behavior of OpenFlow architecture. In addition, by distinguishing between IPsec flows, the architecture is particularly suited to secure group communication.展开更多
文摘Network security protocols such as IPsec have been used for many years to ensure robust end-to-end communication and are important in the context of SDN. Despite the widespread installation of IPsec to date, per-packet protection offered by the protocol is not very compatible with OpenFlow and tlow-like behavior. OpenFlow architecture cannot aggregate IPsee-ESP flows in transport mode or tunnel mode because layer-3 information is encrypted and therefore unreadable. In this paper, we propose using the Security Parameter Index (SPI) of IPsec within the OpenFlow architecture to identify and direct IPsec flows. This enables IPsec to conform to the packet-based behavior of OpenFlow architecture. In addition, by distinguishing between IPsec flows, the architecture is particularly suited to secure group communication.
文摘受到战争等特殊环境下部分节点导航拒止、节点移动性与环境干扰所带来的影响,快速进行测控网络拓扑重构是保证连续测控关键。为了解决上述问题,针对多体制无人集群测控网络的场景,提出一种基于多智能体深度确定性策略梯度(multi-agent deep deterministic policy gradient,MADDPG)的分布式多智能体测控网络群切换算法。该算法运用局部可观测马尔可夫决策模型,并考虑最小连通度、能耗与测控精度设计奖励函数,构建可靠的测控定位系统。仿真结果表明,该算法在不同的干扰环境下能有效抵抗外界干扰,保证测控定位的正常运行,与传统切换算法相比切换成功率提升12%以上。