摘要
在对原有的IPsec模块设计进行性能分析的基础上,结合Linux2.4系统的软中断机制,提出多卡并行加密的设计方案.为了适应该并行设计,采取对原有的IPsec模块细分,添加缓冲链表,以及关键区保护等修改,在Linux2.4上实现了并行系统原型.最后对原型性能进行理论分析,总结出并行加密VPN性能的计算公式,并根据实测数据验证了计算公式的正确性,为进一步提高利用并行技术提高VPN性能提供理论依据.
A paralleled multi-card model was proposed in Virtual Private Network (VPN) design based on original IPSec module and the soft interrupt mechanism of Linux 2.4. In the module of IPSec, some measures, including adding a buffer list and protection of critical codes, were taken in order to meet this paralleled design. The experiments for the performance of VPN were endured based on academic analysis and proved by the accurate data to improve the performance of VPN further.
出处
《华中科技大学学报(自然科学版)》
EI
CAS
CSCD
北大核心
2005年第5期13-15,共3页
Journal of Huazhong University of Science and Technology(Natural Science Edition)
基金
国家网络与信息安全保障持续发展计划资助项目(2004研1917021)
武汉市科学技术局资助项目.
关键词
虚拟专用网
高性能
多卡并行
Virtual private network
performance
multi-card paralleled