A ULE Security Approach for Satellite Networks on PLATINE Test Bed
نویسنده
چکیده
The satellite network does not have the IP layer where the IPsec [2][3] is designed for. Therefore, a new algorithm is needed to secure the satellite link at link layer or physical layer. This paper will give a short analysis on the advantages and disadvantages of the MPEG-2 TS encryption and present an approach trying to use the extension header of Unidirectional Lightweight Encapsulation (ULE) [6] Protocol Data Unit (PDU) to provide the efficient security solution for satellite networks. This approach is just above the MPEG-2 TS layer and makes the link security as a part of the encapsulation layer. Thanks to a test bed platform named PLATINE developed by France partners and contributed by other partners within the SATSIX project on which the DVB-S and DVB-RCS have been implemented. The Unidirectional Lightweight Encapsulation (ULE) [6] mechanism working together with MPEG 2 Transport Stream (TS) as a part of the encapsulation in PLATINE is for the transport of IPv6 (& IPv4) Datagrams and other network protocol packets directly over the ISO MPEG-2 Transport Stream as TS Private Data. The proposed security approach is implemented within PLATINE to provide integrated security with ULE protocol at the link layer. The approach is based on the security requirements Internet draft [1] Introduction Current broadband satellite services are regarded as a niche market due to the high cost of launching a satellite system, and the relatively limited available bandwidth compared to terrestrial counterparts. To improve take-up of broadband satellite, it is essential to provide costeffective solutions, to efficiently accommodate new multimedia applications, and to integrate satellites into next generation networks. These issues are being addressed in the EU-funded IST FP6 project Satellite-based communications systems within IPv6 (SATSIX). This project will implement innovative concepts and for broadband satellite systems and services. The MPEG-2 Transport Stream (TS) has been widely accepted not only for providing digital TV services, but also as a subnetwork technology for building IP networks. RFC 4326 [6] describes the Unidirectional Lightweight Encapsulation (ULE) mechanism for the transport of IPv6 (& IPv4) Datagrams and other network protocol packets directly over the ISO MPEG-2 Transport Stream as TS Private Data. ULE specifies a base encapsulation format and supports an extension format that allows it to carry additional header information to assist in network/Receiver processing. The encapsulation satisfies the design and architectural requirement for a lightweight encapsulation defined in RFC 4259 [7] , which states that ULE must be robust to errors and
منابع مشابه
Performance Characterization of Rohc for Satellite-based Unidirectional Links Using Error-free Channels
Satellite communication systems play a vital role in providing Wide Area Network (WAN) due broader coverage but at the same time impose challenge for IP services in unidirectional Satellite link. This research evaluates RObust Header Compression (ROHC) for Unidirectional Lightweight Encapsulation (ULE) in terms of network performance and practical implementation design of a ROHC via Satellite t...
متن کاملUnified Link Layer Security Design for IP Encapsulation using Unidirectional Lightweight Encapsulation over Satellites
There is growing interest in providing multimedia and broadband access over satellites. However there are several technical challenges need to be addressed. One challenge is security in terms of understanding threats and providing an effective security system. Also this paper presents a ULE security solution using ULE mandatory extension headers. The design issues and choices are discussed. The...
متن کاملPLATINE: DVB-S2/RCS enhanced testbed for next generation satellite networks
Emulation is a cost effective and efficient tool to perform performances evaluation and innovative access and network techniques validation. Its ability to interconnect real equipments with real applications provides excellent demonstrations means. The main problem is to overcome the emulation weakness which is the accuracy of the model reproducing the systems to be evaluated. Owing to its modu...
متن کاملFrom simulation to emulation - an integrated approach for network security evaluation
We present a virtual test bed for network security evaluation in mid-scale telecommunication networks. Migration from simulation scenarios towards the test bed is supported and enables researchers to evaluate experiments in a more realistic environment. We provide a comprehensive interface to manage, run and evaluate experiments. On basis of a concrete example we show how the proposed test bed ...
متن کاملFramework for End-to-end Qos Measurement over Dvb-rcs Network
Satellites are popular due to their wide area coverage and for providing connectivity in remote regions of the world. The future development of satellite systems providing services based on the Internet Protocol (IP) needs to be validated on a real satellite network. This paper presents the end-to-end quality of service (QoS) measurements taken at European Space Agency (ESA) testbed over DVB-RC...
متن کامل