标题: | 藉由通道数量之最小化及通道转送以便管理虚拟私人网路 Tunnel Minimization and Relay for Managing Virtual Private Networks |
作者: | 陈一玮 I-Wei Chen 林盈达 Ying-Dar Lin 资讯科学与工程研究所 |
关键字: | 通道缩减;IPSec;权力;通道数量最小化;通道路径长度;通道转达程度;通道转达闸道器;tunnel reduction;IPSec;authority;tunnel minimization;TPL;TRD;tunnel relay gateway |
公开日期: | 2002 |
摘要: | 虚拟私人网路(VPN)是一种利用共用网路来传递私人资料的技术,其最大的应用之一为”企业内部之间的虚拟私人网路”,顾名思义,它可以让一个企业的各个分公司之间的内部私人网路达到互通,为了达到这个目的,就必须使用”通道”(tunneling)的技巧,将原来在分公司内部的IP封包给封装(encapsulation)起来,然后将此封装过后的封包以共用网路传送到另一端的私人网路,当封包进入另一端的私人网路前必须先解开此封包的封装。在众多的通道技巧中,IP Security(IPSec)是目前在业界中最受欢迎的一种,因为它不仅提供封包的封装、解封装,还提供了加密、解密、杂凑等功能。然而在每条IPSec通道建立之前通讯双方必须先沟通好许多的参数,通道经常由于参数的设定不正确而无法顺利建立起来。因此,本论文里提出了”权力”(authority)的新概念,藉由减少通道数目来减低通道管理的复杂度。首先,我们提出分别在三种不同条件下做通道数量最小化的问题。这三种条件为: 没有其它限制、通道路径长度(TPL)限制、以及通道转达程度(TRD)限制,并以图形模型来定义这些问题以及相对的演算法。接着我们探讨通道最精减所带来的效果,发现在一般的企业通道拓扑下可以省下相当可观的通道数量,在文中20个点的拓扑下最多可省90%的通道数。最后我们在实际的系统上(NetBSD/IPSec)实作通道转送闸道器(tunnel relay gateway);我们认为此减少通道数量的方法很容易在真实的系统中来实行。 A virtual private network (VPN) is a private data network that uses a shared data network to carry traffic between remote sites. One of the most popular VPN applications is the “Intranet/Extranet VPN”, which establishes network layer connections between remote Intranet sites using various tunneling protocols to create an IP overlay network. IP Security (IPSec), which is very prevalent in industry, is one of these tunneling protocols that not only provide encapsulation/de-capsulation but encryption/decryption and hashing. However, an IPSec tunnel often fails to be established due to the management overhead. In this work, a new concept of authority is proposed to reduce the management overhead by tunnel reduction. We first formalize the problem of tunnel minimization under three conditions: no constraint, constraint of Tunnel Path Length (TPL), and constraint of Tunnel Relay Degree (TRD), and then solve the problems using graph models and Zero-One Integer Programming (0-1 IP) algorithm. Second, we analyze the effect of tunnel minimization, and find that at most 90% of the tunnels can be reduced in a general enterprise topology. Finally, we implement the VPN tunnel relay gateway on NetBSD operating system with IPSec supported, and show that it is viable to deploy this idea in real-world system. |
URI: | http://140.113.39.130/cdrfb3/record/nctu/#NT910394049 http://hdl.handle.net/11536/70220 |
显示于类别: | Thesis |