Title :
Management of end-to-end security in collaborative IP network environments
Author :
Sivasubramanian, Balaji ; Sundareshan, Malur K.
Author_Institution :
Dept. of Electr. & Comput. Eng., Arizona Univ., Tucson, AZ, USA
Abstract :
Growth in popularity of the Internet has spawned a great interest in collaborative IP networks that support collaborative meetings between individuals or groups located at remote stations. The emphasis on security of information transfer during these meetings has made the management of end-to-end security in collaborative IP network environments, that may involve the creation of ad hoc communication networks that contain the Internet as an intermediate network, an important research issue. Addition of security features through standard methods gives rise to complex incompatibility problems resulting from the specific routing and address translation schemes that may be in place in these networks. The development of enhanced protocols that remove this incompatibility and ensure interoperability between security functions and address translation functions is discussed in this paper. Detailed steps in ensuring end-to-end security in various cases involving change of IP address, change of both IP address and the port, and the use of encapsulation security payload implemented in transport mode are described. The enhanced protocols presented here support generic implementation in the sense that the implementation of the security-related protocol is transparent to the use or not of the address translation scheme. For providing a proof of concept demonstration of the proposed solutions, the structure of a prototype collaborative network, which employs the Internet as an intermediate communication medium for supporting videoconferencing between remote stations, is outlined
Keywords :
Internet; computer network management; protocols; telecommunication security; teleconferencing; Internet; ad hoc communication networks; address translation; collaborative IP network environments; collaborative meetings; encapsulation security payload; end-to-end security; enhanced protocols; incompatibility problems; information transfer; intermediate network; interoperability; prototype collaborative network; remote stations; routing; transport mode; videoconferencing; Collaboration; Collaborative work; Communication networks; Encapsulation; Environmental management; IP networks; Information security; Payloads; Protocols; Prototypes;
Conference_Titel :
Integrated Network Management Proceedings, 2001 IEEE/IFIP International Symposium on
Conference_Location :
Seattle, WA
Print_ISBN :
0-7803-6719-7
DOI :
10.1109/INM.2001.918071