On Layered VPN Architecture for Enabling User-Based Multiply Associated VPNs
نویسندگان
چکیده
In our previous work, we have proposed a new VPN architecture for enabling user-based multiply associated VPNs [1]. Almost all existing VPN technologies assume that users never simultaneously access more than a single VPN. Thus, for realizing a new VPN service allowing users to simultaneously join multiple VPNs, several fundamental mechanisms, such as dynamically changing user’s VPN association status according to the user’s request and authorizing user’s access to a group of VPNs, are required. In this paper, we propose a layered VPN architecture for realizing user-based multiply associated VPN. Our layered VPN architecture consists of three network levels such as PNL (Physical Network Level), LNL (Logical Network Level), and UNL (User Network Level). First, we discuss and classify functions required for each network level. We then present several approaches for implementing each network level using existing layer 2, 3, and 4 networking technologies, and quantitatively evaluate their advantages and disadvantages from several viewpoints including scalability and transmission speed.
منابع مشابه
A Prototype Implementation of VPN Enabling User-based Multiple Association
In our previous work, we have proposed a new VPN architecture for enabling user-based multiply associated VPNs. In this paper, we implement a prototype system of a VPN that enables users to be associated with multiple VPNs using existing network technologies for demonstrating the feasibility of our architecture and for clarifying the service image of a multiple association service. Our prototyp...
متن کاملVPN Architecture Enabling Users to be Associated with Multiple VPNs
Recent improvements in network technology enable network communications in various social organizations and enable various social organizations to be virtualized in networks. We named the mass of virtual organizations “cybersociety”. A “person” in cyber-society needs to establish secure communication associations with multiple virtual organizations. Therefore, we believe that VPN service can he...
متن کاملVPN Architecture Enabling Users to be Associated with Multple VPNs
Recent development of network technologies enables network communications in various social organizations and enables various social organizations to be virtualized in networks. We named the mass of virtual organizations ”cyber-society”. A ”person” in cyber-society needs to establish communication association s with multiple virtual organizations with adequate security. Therefore, we beli eve t...
متن کاملOn the Design and Implementation of Structured P2P VPNs
Centralized Virtual Private Networks (VPNs) when used in distributed systems have performance constraints as all traffic must traverse through a central server. In recent years, there has been a paradigm shift towards the use of P2P in VPNs to alleviate pressure placed upon the central server by allowing participants to communicate directly with each other, relegating the server to handling ses...
متن کاملRFC 4381 Security of BGP / MPLS IP VPNs February
This document analyses the security of the BGP/MPLS IP virtual private network (VPN) architecture that is described in RFC 4364, for the benefit of service providers and VPN users. The analysis shows that BGP/MPLS IP VPN networks can be as secure as traditional layer-2 VPN services using Asynchronous Transfer Mode (ATM) or Frame Relay. Behringer Informational [Page 1] RFC 4381 Security of BGP/M...
متن کامل