DocumentCode
1907816
Title
TNC-compatible NAC System implemented on Network Processor
Author
Luo, An´an ; Lin, Chuang ; Chen, Zhen ; Peng, Xuehai ; Ungsunan, Peter D.
Author_Institution
Res. Inst. of Inf. Technol. Tsinghua Univ. Beijing, Beijing
fYear
2007
fDate
15-18 Oct. 2007
Firstpage
1069
Lastpage
1075
Abstract
In this paper, based on the trusted network connect architecture, we designed a novel TNC-compatible network access control system which ensures that network administrators enforce security policies on endpoint connection and communication with corporate network depending on the endpoint integrity and security status. The platform framework is built on the Intel IXP2400 network processor and a set of network access control mechanisms is implemented. The paper introduces the system design and implementation based on hardware characteristic of the IXP2400 architecture, presents emulation performance results of the system, and then proposes systemic performance optimizations, especially cryptographic performances, according to IXP2400 shared memory hierarchy and access latency, which averagely boost the throughput more than 25%. The novelty of system design is the utilization of IXP2400 multi-core and multi-thread network processor´s software and hardware platform to implement the NAC system framework through secure and reliable communication to ensure endpoint integrity and platform-authentication, which is compatible with trusted network connect.
Keywords
authorisation; multi-threading; program processors; software architecture; Intel IXP2400 network processor; endpoint integrity; multithread network processor; network access control system; network administrators; platform-authentication; security policies; trusted network connect architecture; Access control; Communication system security; Communication system software; Computer architecture; Cryptography; Delay; Emulation; Hardware; Optimization; Throughput; AES algorithm; TNC; network access control; network processor;
fLanguage
English
Publisher
ieee
Conference_Titel
Local Computer Networks, 2007. LCN 2007. 32nd IEEE Conference on
Conference_Location
Dublin
ISSN
0742-1303
Print_ISBN
0-7695-3000-1
Electronic_ISBN
0742-1303
Type
conf
DOI
10.1109/LCN.2007.60
Filename
4367951
Link To Document