DocumentCode :
423229
Title :
Tunnel minimization and relay for managing virtual private networks
Author :
Chen, I-Wei ; Lin, Ying-Dar ; Lin, Yi-Neng
Author_Institution :
Dept. of Comput. & Inf. Sci., Nat. Chiao Tung Univ., Hsinchu, Taiwan
Volume :
4
fYear :
2004
fDate :
29 Nov.-3 Dec. 2004
Firstpage :
2128
Abstract :
A virtual private network (VPN) is a private data network, that carries traffic between remote sites. One of the most popular VPN applications is the "intranet/extranet VPN", which establishes network layer connections between remote intranet sites, using various tunneling protocols, to create an IP overlay network. IPSec, which is very prevalent in the industry, is one of these tunneling protocols that not only provide encapsulation/decapsulation but encryption/decryption and hashing, However, an IPSec tunnel often fails to be established due to the management complexity. The paper proposes a new concept of authority to alleviate the management overhead by reducing the number of tunnels. The problem of tunnel minimization is first formalized under three conditions - no constraint, a tunnel path length constraint and a tunnel relay degree constraint - and is then solved using graphical models and the zero-one integer programming algorithm. The effect of tunnel minimization is also investigated, and at most 90% of the tunnels are found to be reducible in a general enterprise VPN.
Keywords :
business communication; computational complexity; extranets; graph theory; integer programming; intranets; minimisation; protocols; security of data; telecommunication network management; telecommunication security; telecommunication traffic; virtual private networks; IP overlay network; IPSec; VPN management; decapsulation; decryption; encapsulation; encryption; enterprise VPN; graphical models; hashing; intranet/extranet VPN; management complexity; network layer connections; tunnel minimization; tunnel path length constraint; tunnel relay degree constraint; tunneling protocols; virtual private network management; zero-one integer programming algorithm; Cryptography; Encapsulation; Extranets; Graphical models; Minimization methods; Protocols; Relays; Telecommunication traffic; Tunneling; Virtual private networks;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Global Telecommunications Conference, 2004. GLOBECOM '04. IEEE
Print_ISBN :
0-7803-8794-5
Type :
conf
DOI :
10.1109/GLOCOM.2004.1378387
Filename :
1378387
Link To Document :
بازگشت