F. J. G. Clemente, Gabriel López Millán, Jesús D. Jiménez Re, G. Pérez, A. Gómez-Skarmeta
{"title":"Deployment of a Policy-Based Management System for the Dynamic Provision of IPsec-Based VPNs in IPv6 Networks","authors":"F. J. G. Clemente, Gabriel López Millán, Jesús D. Jiménez Re, G. Pérez, A. Gómez-Skarmeta","doi":"10.1109/SAINTW.2005.50","DOIUrl":null,"url":null,"abstract":"Security is considered as a key service in IP networks. This is equally true for IPv4- and IPv6-based networks, and for them the IPsec protocol was defined to provide security at the network layer. IPsec can be used in different scenarios, being the VPN the most widely used. However, IPsec-based VPNs are experiencing important limitations mainly because they are usually based on information manually configured, and the integration with PKI-related services is still under definition and is far from being mature. This is especially true in IPv6 networks where IPsec is defined as a mandatory component to be implemented in all stacks and PKI services in these networks are just starting to be designed and deployed. This paper describes how IPsec-based VPNs can be dynamically deployed in an IPv6 network as the one designed in the Euro6IX EU IST project. Such dynamicity is provided using a new management paradigm based on security policies.","PeriodicalId":220913,"journal":{"name":"2005 Symposium on Applications and the Internet Workshops (SAINT 2005 Workshops)","volume":"76 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2005-01-31","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"6","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2005 Symposium on Applications and the Internet Workshops (SAINT 2005 Workshops)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SAINTW.2005.50","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 6
Abstract
Security is considered as a key service in IP networks. This is equally true for IPv4- and IPv6-based networks, and for them the IPsec protocol was defined to provide security at the network layer. IPsec can be used in different scenarios, being the VPN the most widely used. However, IPsec-based VPNs are experiencing important limitations mainly because they are usually based on information manually configured, and the integration with PKI-related services is still under definition and is far from being mature. This is especially true in IPv6 networks where IPsec is defined as a mandatory component to be implemented in all stacks and PKI services in these networks are just starting to be designed and deployed. This paper describes how IPsec-based VPNs can be dynamically deployed in an IPv6 network as the one designed in the Euro6IX EU IST project. Such dynamicity is provided using a new management paradigm based on security policies.
安全被认为是IP网络中的一项关键服务。这同样适用于基于IPv4和ipv6的网络,并且为它们定义了IPsec协议来提供网络层的安全性。IPsec可以应用于不同的场景,是应用最广泛的VPN。然而,基于ipsec的vpn存在着重要的局限性,主要是因为它们通常基于手动配置的信息,并且与pki相关业务的集成仍处于定义阶段,远未成熟。在IPv6网络中尤其如此,IPsec被定义为所有栈中必须实现的组件,而这些网络中的PKI服务才刚刚开始设计和部署。本文描述了基于ipsec的vpn如何在IPv6网络中动态部署,如Euro6IX EU IST项目所设计的那样。这种动态是使用基于安全策略的新管理范例提供的。