A network-based VPN architecture using virtual routing - Springer Link

4 downloads 226 Views 426KB Size Report
May 25, 2004 - an extended DS (Differenliated Services) code to support muhi path ..... IEEE Transactions on Sof?z~re Engineering,. 1995,21(2) :63-68.
WUJNS

Vol.10

No. 1 2005 161-164

Wuhan University Journal of Natural Sciences

Article ID:1007 1202(2005)01-0161-04

A Network.Based VPN Architecture Using Virtual Routing 0 [ ] ZHANG Bao-liang t'2, HU Han-ping ''2., WU Xiao-gang ''2 , KONG Tao a 1. State Education Ministry Key I.ahoratory of Image Information and Intelligent Control, Wuhan 430074, Hubei, China 2. Institute of Pattem Recognition and Artificial Intelligonce, Huazhong University of Science and Technolo gy, Wuhan 430074, Hubei, China; 3. 709th Research Institute of China Shipbuilding Engineering ~)ciely, Wuban 430074, Hubei, China

Abstract:

A network-based Virtual Private Network (VPN) architecture by using fundamental routing mechanism is proposed. This network is a virlual overlay network based on the relay of IP-in-IP tunneling of virtual routing modules. The packet format employs the encapsulatk)n of IPSec ESP (Encapsulating Security Payload), an impact path code and an extended DS (Differenliated Services) code to support muhi path routing and QoS. Comparing with other models of VPN, this network system can be depk)yed in the current network with little investment, and it is easy to implement. The simulation result shows its performance is better than the traditional VPN system of black box mode. Key words: virtual routing; network based VPN; proaclive defense

CLC number: TP 393.08

Received date: 2004 05 25 Foundation item: Supported by the National Natural Science Foundation of China (90104029) Biography: ZHANG BacHiang ( 1969-), male, Ph. D candidate, re search direction: nelwork security, processing of intelligent informa lion, network architecture. E mail: sacc2000@sina, corn t "Ib whom correspondence should he addressed. Kmail: hphu(w, mail. hust. edu. cn

Introduction

he traditional Virtual Private Network (VPN) uses the CPE-based solutions, such as TLS, IPSec[l'z], but these solutions of point-to-point mode focus only on the security of end system without guarantee of performance. Many malicious attacks exist on this traditional black box model of VPN on the midway[:~' t] Therefore, the drive to offer a proactive, profitable solution is gaining momentum due to the need for increased scalability, manageability, such as the combining Multi-Protocol I.abel Switch (MPLS) and DiffServ with VPN [