Flexi-Tunes: An efficient architecture for adaptive and flexible VPN tunnels

نویسندگان

  • Shashank Khanvilkar
  • Ashfaq Khokhar
چکیده

Virtual Private Networks (VPNs) provide the security and isolation properties of private networks, but at lower costs made possible by using a shared infrastructure such as the Internet. VPNs use point-to-point tunnels to create a secure overlay network, with every tunnel being pre-configured to encrypt, compress, and/or authenticate traffic. Once the tunnels are created such properties are maintained throughout its lifetime and traffic streams from different application flowing through the tunnel are subjected to same treatment. This poses a heavy computational burden on the edge routers and may be unnecessary for many applications, which only require a subset of these functions (or variations thereof) to be applied to their streams. Current VPNs are unable to offer such differential and application specific treatment, which makes them inflexible. Moreover, performing unnecessary computations on every packet degrades network performance. In this paper, we propose and evaluate a flexible VPN architecture (called FlexiTunes) where within a single VPN tunnel, different VPN functions can be applied to different applications, thus offering differential and customized treatment. Flexi-Tunes empowers applications on end-hosts to either specify the kind of treatment they expect for their traffic streams or take active part in applying the tunneling functions themselves. This is realized by enhancing the VPN edge router architecture and introducing a new IP Option. Simulations of this enhanced model show that 90% of the bandwidth is used compared to only 20% bandwidth utilization in conventional VPNs. Similarly, end-to-end delay is improved by almost 60% over the conventional case.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Towards a Scalable and Flexible Architecture for Virtual Private Networks

Virtual Private Networks (VPNs) are commonly used to provide secure connectivity over public networks. VPNs use tunnels to provide encryption, compression, and authentication functions, which are identically applied to every packet passing through them. However, this behavior may be overly rigid in many situations where the applications require different functions to be applied to different par...

متن کامل

Scalability implications for Open-Source Linux Based Virtual Private networks

Virtual Private Networks (VPNs) provide leased-line like connectivity to private networks using a public infrastructure like the Internet. A number of commercial VPN products can now be purchased, but the freely available OpenSource Linux based VPN solutions (OSLVs) seem to be gaining immense popularity. This is mainly due to their open-source licensing, which gives complete access to the sourc...

متن کامل

Adaptive Information Analysis in Higher Education Institutes

Information integration plays an important role in academic environments since it provides a comprehensive view of education data and enables mangers to analyze and evaluate the effectiveness of education processes. However, the problem in the traditional information integration is the lack of personalization due to weak information resource or unavailability of analysis functionality. In this ...

متن کامل

Adaptive Information Analysis in Higher Education Institutes

Information integration plays an important role in academic environments since it provides a comprehensive view of education data and enables mangers to analyze and evaluate the effectiveness of education processes. However, the problem in the traditional information integration is the lack of personalization due to weak information resource or unavailability of analysis functionality. In this ...

متن کامل

A Scalable VPN Gateway for Multi-Tenant Cloud Services

Major cloud providers offer networks of virtual machines with private IP addresses as a service on the cloud. To isolate the address space of different customers, customers are required to tunnel their traffic to a Virtual Private Network (VPN) gateway, which is typically a middlebox inside the cloud that internally tunnels each packet to the correct destination. To improve performance, an incr...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2004