首页> 外文会议>IEEE Military Communications Conference >PROACTIVE MULTICAST-BASED IPSEC DISCOVERY PROTOCOL AND MULTICAST EXTENSION
【24h】

PROACTIVE MULTICAST-BASED IPSEC DISCOVERY PROTOCOL AND MULTICAST EXTENSION

机译:基于主基于组播的IPSec Discovery协议和多播扩展

获取原文

摘要

In a large-scale network, manual configuring IPsec tunnels and security policies is labor intensive and difficult to manage. In some cases, a full-mesh IPsec tunnels are required so that all Plain Text (PT) networks behind the IPsec devices can be reachable. Without an IPsec Discovery Protocol (IDP), static routes have to be configured at all PT routers that are connected to the IPsec devices so that a PT packet can be encrypted and sent to a remote PT network. Another disadvantage of not having an IDP is that an IPsec device has no way of knowing if an IPsec peer is down so that security policy (SP) can be updated. As a result, data are sent to IPsec 'dead' peer will be dropped in the Cipher Text (CT) network until the Security Association (SA) timer expires which can take a long period of time. Several IPsec Discovery Protocols with different mechanisms for IPsec discovery have been designed and implemented. The two most common mechanisms are the Multicast-based and the Client-Server. Another mechanism is used in Implicit Peer Enclave Prefix Discovery (IM-PEPD) protocol. While these protocols are reactive, the protocol described in the paper is proactive and well suited for dynamic networks in which IPsec devices are often unreachable and their mobility requires IPsec tunnels and SP to be updated dynamically. This paper presents an IDP called the Proactive Multicast-based IPsec Discovery Protocol (PMIDP) that has been designed, developed, and demonstrated in the multinational Interoperable Networks for Secure Communications (INSC) network - an IPv6 network based on the CT Core Routing Architecture. For PMIDP, at the end of the discovery process, all IPsec devices in the network have full-meshed IPsec tunnels, and SPs are setup and ready for PT traffics. The paper also describes the benefits of the Proactive Discovery Mechanism including support for security gateway, network mobility, PT-to-PT dynamic routing, dead peer detection, and PT/CT address separation. Finally, the paper presents a multicast mechanism of the PMIDP that enables an IPsec to dynamically multicast route PT multicast IP packets in CT network without compromising security protection of PT prefixes and multicast addresses in the CT network.
机译:在大型网络中,手册配置IPSec隧道和安全策略是劳动密集型且难以管理的。在某些情况下,需要全网状IPSec隧道,以便可以访问IPSec设备后面的所有普通文本(PT)网络。如果没有IPSec发现协议(IDP),则必须在连接到IPsec设备的所有PT路由器处配置静态路由,以便可以加密PT包并将其发送到远程PT网络。不具有IDP的另一个缺点是IPSec设备无法知道IPSec对等体是否关闭,以便可以更新安全策略(SP)。因此,数据被发送到IPsec'死'对等体将丢弃在密码文本(CT)网络中,直到安全关联(SA)计时器到期,这可能需要很长一段时间。已经设计并实现了具有不同IPSec Discovery机制的几种IPsec发现协议。两个最常见的机制是基于组播和客户端服务器。另一种机制用于隐式对等体入围前缀发现(IM-PEPID)协议。虽然这些协议是反应性的,但本文描述的协议是主动的,非常适合于动态网络,其中IPSec设备通常无法访问,并且它们的移动性需要动态更新IPsec隧道和SP。本文提出一种IDP称那已经设计,开发,并在保密通信(INSC)网络的跨国可互操作的网络展示了基于组播的主动IPsec发现协议(PMIDP) - 基于CT核心路由架构IPv6网络。对于PMIDP,在发现过程结束时,网络中的所有IPSec设备都有全网格化的IPSec隧道,SPS是设置并准备好PT流量的。本文还介绍了主动发现机制的好处,包括支持安全网关,网络移动性,PT-TO-PT动态路由,死点检测和PT / CT地址分离。最后,本文提出了PMIDP的多播机制,使IPSec能够在CT网络中动态组播多播IP分组,而不会影响CT网络中的PT前缀和多播地址的安全保护。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号