Title :
A distributed object-based IPSec multi-tunnels concurrent architecture
Author :
Wang, Song ; Lv, Hongbing
Author_Institution :
Coll. of Comput. Sci. & Technol., Zhejiang Univ., Hangzhou, China
Abstract :
In the existing IPSec architecture, in which tunnel is built in kernel, the number of concurrent tunnels is restricted by IP address configured on the machine and user can not control the process of establishing tunnel. This brings inconvenience when we use personal computer to measure the performance parameters of VPN Gateway (e.g. the maximum number of concurrent tunnels and the maximum rate of the new tunnels built). In order to solve this problem, this paper presents a novel IPSec multi-tunnels concurrent architecture which uses distributed objects to build tunnels in user space. The architecture privodes one Console which are used to control all AgentNodes and multiple AgentNodes which are used to build tunnels. In AgentNode, the negotiation processing of tunnels, the IPSec processing of packets and the protocol processing of TCP/IP are all completed in user space by objects. Meanwhile, AgentNode uses virtual IP address instead of local IP address to negotiate tunnel and the number of concurrent tunnels will be unlimited (only limited by memory). Moreover, based on distributed architecture, the number of AgentNode can be arbitrarily extended. Therefore, the system has a great deal of flexibility on the number of concurrent tunnels and the rate of tunnel establishment, which helps to accurately measure the performance parameters of VPN Gateway.
Keywords :
IP networks; internetworking; transport protocols; virtual private networks; IPSec multitunnel concurrent architecture; TCP/IP; VPN gateway; concurrent tunnel; distributed object; multiple AgentNodes; virtual IP address; Computer architecture; IP networks; Kernel; Logic gates; Protocols; Security; Virtual private networks; AgentNode; Distributed; Distributed Object; IPSec; Kernel space; Multi-tunnels concurrent; Object; SA; User space;
Conference_Titel :
Computational Problem-Solving (ICCP), 2011 International Conference on
Conference_Location :
Chengdu
Print_ISBN :
978-1-4577-0602-8
Electronic_ISBN :
978-1-4577-0601-1
DOI :
10.1109/ICCPS.2011.6089933