DocumentCode :
1155145
Title :
On demand network-wide VPN deployment in GPRS
Author :
Xenakis, Christos ; Merakos, Lazaros
Author_Institution :
Univ. of Athens, Greece
Volume :
16
Issue :
6
fYear :
2002
Firstpage :
28
Lastpage :
37
Abstract :
Mobile Internet requires enhanced security services available to all mobile subscribers in a dynamic fashion. A network-wide virtual private network deployment scenario over the General Packet Radio Service is proposed and analyzed from a security viewpoint. The proposed security scheme improves the level of protection that is currently supported in GPRS and facilitates the realization of mobile Internet. It secures data transmission over the entire network route from a mobile user to a remote server by utilizing the default GPRS ciphering over the radio interface, and by deploying an IP VPN over the GPRS core, as well as on the public Internet. Thus, on-demand VPN services are made available for all GPRS network subscribers and roaming users. The VPN functionality, which is based on the IPsec framework, is outsourced to the network infrastructure to eliminate the potential computational overhead on the mobile device. The VPN initialization and key agreement procedures are based on an Internet Key Exchange protocol proxy scheme, which enables the mobile station to initiate VPN establishment, while shifting the complex key negotiation to the network infrastructure. The deployed VPN operates transparently to the mobile subscribers´ movement. The required enhancements for security service provision can be integrated in the existing network infrastructure; therefore, the propose security scheme can be employed as an add-on feature to the GPRS standard.
Keywords :
Internet; cellular radio; mobile computing; packet radio networks; protocols; telecommunication security; telecommunication standards; virtual private networks; GPRS standard; General Packet Radio Service; IP VPN; Internet key exchange protocol proxy scheme; add-on feature; ciphering; data transmission; functionality; lPsec framework; mobile Internet; network infrastructure; on demand network-wide VPN deployment; protection; radio interface; security services; virtual private network deployment; Data communication; Data security; Ground penetrating radar; IP networks; Network servers; Packet radio networks; Protection; Virtual private networks; Web and internet services; Web server;
fLanguage :
English
Journal_Title :
Network, IEEE
Publisher :
ieee
ISSN :
0890-8044
Type :
jour
DOI :
10.1109/MNET.2002.1081763
Filename :
1081763
Link To Document :
بازگشت