A Multi-Layer IPSEC Protocol

A Multi-Layer IPSEC Protocol
复制标题

多层IPSEC协议

DOI:
--
复制
发表时间:
2000
期刊:
--
影响因子:
--
通讯作者:
Bikramjit Singh
Bikramjit Singh
中科院分区:
--
文献类型:
--
作者:
Yongguang Zhang;Bikramjit Singh

文献摘要

被引文献

相似文献

KA 98 c是一套标准协议,为互联网通信提供安全服务。它以“端到端”的方式保护整个IP数据报;公共Internet中的任何中间网络节点都无法访问或修改受IPSec保护的数据包中IP层以上的任何信息。然而,互联网技术的最新进展引入了一组丰富的新服务和应用,如流量工程、TCP性能增强或透明加密和缓存,所有这些都需要中间网络节点访问IP数据报的某个部分,通常是上层协议信息,以执行流分类、基于约束的路由或其他定制处理。这与反腐败机制直接冲突。在这项研究中,我们提出了一个多层的安全保护方案,它使用更细粒度的访问控制,允许可信的中间路由器读取和写入IP数据报的选定部分(通常是头部)在一个安全和受控的方式。
IPsec [KA98c] is a suite of standard protocols that provides security services for Internet communications. It protects the entire IP datagram in an "end-to-end" fashion; no intermediate network node in the public Internet can access or modify any information above the IP layer in an IPsec-protected packet. However, recent advances in internet technology introduce a rich new set of services and applications, like traffic engineering, TCP performance enhancements, or transparent proxying and caching, all of which require intermediate network nodes to access a certain part of an IP datagram, usually the upper layer protocol information, to perform flow classification, constraint-based routing, or other customized processing. This is in direct conflict with the IPsec mechanisms. In this research, we propose a multi-layer security protection scheme for IPsec, which uses a finer-grain access control to allow trusted intermediate routers to read and write selected portions of IP datagrams (usually the headers) in a secure and controlled manner.