Title :
EESP: A Security protocol that supports QoS management
Author :
Mostafa, Mahmoud ; El Kalam, Anas Abou ; Fraboul, Christian
Author_Institution :
CNRS, Univ. de Toulouse, Toulouse
Abstract :
In order to effectively manage network resources and to serve different traffic needs, several works have been done in the QoS area. Basically, ldquomulti-field (MF) packet classifiersrdquo classify a packet by looking for multiple fields of the IP/TCP headers, recognize which flow the packet belongs to, and according to this information, provide service differentiation in IP networks. However, for security purposes, existing security protocols (such as the IPSec Encapsulating Security Payload (ESP) algorithm) hides much of this information in their encrypted payloads, preventing network control devices such as routers and switches from utilizing this information in performing classification appropriately. The ESPQ (ESP considered QoS) protocol deals with this problem but unfortunately, it has some security weaknesses. In this paper we present the ESPQ vulnerabilities and we propose EESP (Enhanced encapsulated security payload) as a security protocol that provides both security and QoS.
Keywords :
DiffServ networks; IP networks; Internet; cryptography; pattern classification; quality of service; resource allocation; telecommunication network management; telecommunication security; telecommunication traffic; transport protocols; EESP security protocol; IP network; IP/TCP header; Internet; QoS management; multi field packet classifier; network control device prevention; network resource management; network traffic; payload encryption; service differentiation; Cryptography; Electrostatic precipitators; IP networks; Information security; Payloads; Protocols; Resource management; Switches; TCPIP; Telecommunication traffic; AH; ESP; IPSec; QoS; Security protocols; active admission control; multi-field packet classifier;
Conference_Titel :
Risks and Security of Internet and Systems, 2008. CRiSIS '08. Third International Conference on
Conference_Location :
Tozeur
Print_ISBN :
978-1-4244-3309-4
DOI :
10.1109/CRISIS.2008.4757476