Title :
Performance analysis of AES-finalists along with SHS in IPSEC VPN over 1Gbps link
Author :
Tanveer, Awais ; Ali, Amir ; Paracha, Muhammad Arsalan ; Raja, Fawad Riasat
Author_Institution :
Centres of Excellence in Sci. & Appl. Technol. (CESAT), Islamabad, Pakistan
Abstract :
IPSEC is suit of protocols designed to provide secure communication over Network Layer (Layer-3) of TCP/IP model. Participating IPSEC gateways may have different algorithms installed in them but RFC-4835 mentions mandatory algorithms that a gateway must have so that participating gateways always have at least one algorithmic combination to agree upon. Off the shelve IPSEC implementations only implement these mandatory algorithms. In this paper, the enhancements involve the selection of hashing and encryption algorithms that yield better performance for the given system. All AES finalists and SHS algorithms have been embedded after some modifications in 64 bit RHEL 6.2 Linux kernel (2.6.32) and Openswan 2.6.38 (A user space agent which helps gateways to negotiate security associations between them) and performance analysis of these algorithms having throughput as the main parameter over 1 Gbps link in an IPSEC VPN has been done. For this purpose, all the combinations of block ciphers with different key lengths along with hashing algorithms are tested and analyzed under same operating conditions. Comparative results are shown with respect to every combination of AES finalists with every hashing algorithm of SHS and MD5. Furthermore, All the AES finalists have also been tested without hashing algorithms.
Keywords :
Linux; computer network security; cryptographic protocols; internetworking; operating system kernels; transport protocols; virtual private networks; AES finalist performance analysis; IPSEC VPN network layer; IPSEC gateway; Openswan 2.6.38; RHEL 6.2 Linux kernel; SHS algorithm; TCP-IP protocol model; advanced encryption standard; bit rate 1 Gbit/s; cipher blocking; encryption algorithm; hashing algorithm; off the shelve IPSEC implementation; secure communication; secure hash standard; user space agent; Authentication; Encryption; IP networks; Logic gates; Payloads;
Conference_Titel :
Applied Sciences and Technology (IBCAST), 2015 12th International Bhurban Conference on
Conference_Location :
Islamabad
DOI :
10.1109/IBCAST.2015.7058524