期刊文献+

可升级的虚拟专用网络在全球信息栅格中的应用 被引量:3

Application of Scalable VPNs on the Global Information Grid
下载PDF
导出
摘要 在民用网络安全通信中,虚拟专用网络(Virtual Private Network,VPN)是一种优先选择的通信机制;传统的VPN网关配置是按照手动进行的;然而,在网关静态配置的通信传输中,由美国国防部研制开发的全球信息栅格(Global Information Grid,GIG)存在一定的局限性;一方面GIGVPN由成千个可靠的网络组成,网关的配置要比以前的配置在数量级上要大的多;另一方面在由陆军集团或舰艇组成的可靠网络的作战领域中,由于作战单元是动态的,要求在GIG网络通信中实现无缝链接;为了解决当前VPN在动态网络中存在的可测量性和支持性问题;通过使用动态路由器协议,提出了一种利用安全广告前缀在VPN网关内部网络中实现与同级别网关的链接;实验结果表明,在由成千上万个VPN网关协议组成的GIG网络体系结构通信信息传输过程中,该方法是切实可行的。 Virtual Private Network (VPN) are the preferred mechanism for securing sensitive traffic crossing public networks. Traditionally, configuration of VPN gateways has been done manually. However, static configuration of gateways is particularly problematic within the context of the Global Information Grid (GIG), the next--generation network of networks developed by the US government. For one, GIG VPN are expected to consist of tens to hundreds of trusted networks, which is an order of magnitude greater than current deployments. Moreover, trusted networks that essentially comprise of units in the field (army companies or ships) need to be seamlessly connected to the GIG even while they are mobile. It' s goal in this paper is to address the lack of scalability and support for mobility that exists in current VPN. This paper does by providing a dynamic routing protocol which VPN gateways use to securely advertise prefixes of their internal network to peering gateways. Experiments show that this method is feasible, and it' s protocol can scale reasonably well in the GIG to over a thousand VPN gateways.
出处 《计算机测量与控制》 CSCD 北大核心 2011年第2期452-455,共4页 Computer Measurement &Control
关键词 全球信息栅格 虚拟专用网络 信息技术 网关 global information grid virtual private networks information tecbnology gateways
  • 相关文献

参考文献14

  • 1Arkko J, Devarapalli V, Dupont F. Using IPsec to Protect Mobile IPv6 Signaling Between Mobile Nodes and Home Agents [R]. 北京:中国国防科技信息中心,2004.
  • 2Baker F, Bose P, Voce D. Routing in a Nested VPN [R].北京:中国国防科技信息中心,2005.
  • 3Hoffman P, Arrko J. IKEv2 Mobility and Multi-homing Working Group[R].北京:中国国防科技信息中心,2004.
  • 4Kamara S, Davis D, Ballard L. An Extensible Platform for Evaluating Security Protocols [R]. 北京:中国国防科技信息中心,2005.
  • 5Kniveton T, Ernst T. Network Mobility Working Group [R].北京:中国国防科技信息中心,2004.
  • 6Pei D, Massey D, Zhang L. Formal Specification of RIP Protocol[R].北京:中国国防科技信息中心,2005.
  • 7United State Department of Defense: About GIG Enterprise Services[R].北京:中国国防科技信息中心,2004.
  • 8Lenstra A K, Verheul E R. Selecting Cryptographic Key Sizes [J]. The Journal of the International Association for Cryptologic Research, 2004, 14 (4): 255-293.
  • 9Kohl J, Neuman C. RFC: The Kerberos Network Authentication Service[R].北京:中国国防科技信息中心,2003.
  • 10Steiner J, Neuman C. An Authentication Service for Open Net-work Systems [R].北京:中国国防科技信息中心,2005.

二级参考文献19

  • 1龚勇,陈亚滨,张林.全球信息网格体系结构与企业级服务分析[J].现代电子技术,2005,28(8):12-14. 被引量:10
  • 2朱孟平,谢芊,宋自林.GIG栅格体系结构分析[J].军事通信技术,2005,26(3):66-70. 被引量:4
  • 3康质彬,赵新国,黄程林.全球信息栅格中的通信体系结构研究[J].装备指挥技术学院学报,2006,17(1):97-101. 被引量:15
  • 4DoD of USA. Global Information Grid Net-Centric Implementation Document, Quality of Service (T300) [R].北京:中国国防科技信息中心,April2007.
  • 5DoD of USA, Technical Decision Paper, "GIG QoS-2E: Interoperability"[R].北京:中国国防科技信息中心,June2006.
  • 6DoD of USA. IETF RFC 2598, "An Expedited Forwarding PHB"[R].北京:中国国防科技信息中心,June1999.
  • 7DoD of USA. IETF RFC 4594, "Configuration Guidelines for Diff- Serv Service Classes" [R].北京:中国国防科技信息中心,August 2006.
  • 8DoD of USA. IETF Internet Draft, "RSVP Proxy Approaches"[R].北京:中国国防科技信息中心,July2007.
  • 9DoD of USA . IETF RFC 2597, "Assured Forwarding PHB Group"[R].北京:中国国防科技信息中心,June 1999.
  • 10DoD of USA . IETF RFC 4860, "Generic Aggregate Resource Reservation Protocol Reservations" [R].北京:中国国防科技信息中心,May 2007.

共引文献4

同被引文献6

引证文献3

二级引证文献18

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部