Title :
GDS-B: A protocol to support HAIPE® peer discovery server communication
Author :
Louis, I Berger ; Ziemba, G. Paul ; Hawkins, William H ; Decina, Basil A
Author_Institution :
LabN Consulting, LLC, Washington, DC, USA
fDate :
Oct. 31 2010-Nov. 3 2010
Abstract :
HAIPE® devices provide encrypted tunneling and transporting services for Internet Protocol (IP) datagrams through an unsecured network on behalf of secure Plain Text (PT) enclaves. Traditionally, secure tunnels were established by manually configuring the local HAIPE with information for peer enclaves. When a large number of enclaves are involved, automation of this configuration process improves administrative efficiency and reduces errors. Such automation is known as HAIPE Peer Discovery, or HPD. With the support of the HAIPE Interoperability Specification (HAIPE IS) Generic Discovery Client (GDC) Extension, HAIPEs can communicate with a generic discovery server (GDS) that implements a server-based HPD service. The HAIPE IS GDC Extension specifies only how a HAIPE communicates with a GDS. It does not specify a mechanism for exchanging HAIPE peer information between GDSes. In this paper we describe a protocol mechanism for exchanging discovery information among GDSes. This protocol, which we refer to as the GDS-B protocol, reuses Border Gateway Protocol (BGP) Virtual Private Network (VPN) and Tunnel mechanisms to encode and disseminate HAIPE and enclave routing information among servers. Servers implementing the GDS-B protocol, known as GDS-B Servers, obtain and provide this information to client HAIPEs via the HAIPE IS GDC Extension. We describe the design and implementation of a GDS-B Server using open-source routing software and present the status of this implementation when used in large-scale scenarios.
Keywords :
peer-to-peer computing; telecommunication network routing; transport protocols; GDS-B; Internet Protocol datagrams; border gateway protocol; encrypted tunneling; generic discovery server; open-source routing software; peer discovery server communication; transporting services; virtual private network; IP networks; Protocols; Redundancy; Routing; Servers; Topology; Virtual private networks; Discovery; Generic Discovery; HAIPE; Network and transport protocols; Peer Discovery; Routing; Securing network protocols;
Conference_Titel :
MILITARY COMMUNICATIONS CONFERENCE, 2010 - MILCOM 2010
Conference_Location :
San Jose, CA
Print_ISBN :
978-1-4244-8178-1
DOI :
10.1109/MILCOM.2010.5680090