Title :
Public Key-Based Rendezvous Infrastructure for Secure and Flexible Private Networking
Author :
Kubota, Ayumu ; Miyake, Yutaka
Author_Institution :
KDDI R&D Labs. Inc., Fujimino, Japan
Abstract :
Secure private networking over the Internet is difficult especially when trying to form a new network with private servers and hosts that belong to different administrative domains. Although such form of private network is useful as a closed group communication environment, simply applying existing VPN technologies is not sufficient. Not to mention common problems such as NAT and firewall traversal, potential collision of private IP addresses among networks makes their interconnection extremely difficult. In addition, access control inside the private network is required in order to prevent inappropriate access to other users´ network resources. In this paper, we propose a public key-based rendezvous infrastructure and user-side VPN agents that can instantly interconnect multiple private networks while automatically mediating address collision and enforcing appropriate access control on cross domain communication by utilizing Zeroconf technologies. We built the rendezvous infrastructure using DHT technologies in order to achieve good scalability and implemented the VPN agent for Linux-based embedded devices so that users can run it on their residential gateway or wireless router.
Keywords :
Internet; authorisation; public key cryptography; security of data; telecommunication security; virtual private networks; DHT technologies; Internet; Linux-based embedded devices; NAT; VPN technologies; Zeroconf technologies; access control; address collision; closed group communication environment; cross domain communication; firewall traversal; flexible private networking; public key-based rendezvous infrastructure; residential gateway; scalability; secure private networking; user-side VPN agent; wireless router; Access control; Communications Society; Home automation; IP networks; Network address translation; Network servers; Virtual machining; Virtual private networks; Web and internet services; Web server;
Conference_Titel :
Communications, 2009. ICC '09. IEEE International Conference on
Conference_Location :
Dresden
Print_ISBN :
978-1-4244-3435-0
Electronic_ISBN :
1938-1883
DOI :
10.1109/ICC.2009.5199375