利用网络功能虚拟化技术建立基于云的VPN的研究

Sankili Santhanamahalingam, Saravanan Alagarsamy, Karthik Subramanian
{"title":"利用网络功能虚拟化技术建立基于云的VPN的研究","authors":"Sankili Santhanamahalingam, Saravanan Alagarsamy, Karthik Subramanian","doi":"10.1109/ICOSEC54921.2022.9951894","DOIUrl":null,"url":null,"abstract":"Network Function Virtualization is the process of moving networking functions like Firewall, Load Balancing, Virtual Private networks (VPN), Gateway Antivirus, etc. away from proprietary hardware to the virtual server. This paper suggests enabling VPN security features to business customers by moving VPN features away from dedicated hardware and applying the feature by instantiating the corresponding VNF template from the virtual server. This paper aspires to develop a suitable architecture model with Software-Defined Network and Network Function Virtualization as its core techniques that can render a cloud design for VPN.The proposed model consists of three parts that include forwarding plane, signaling & control plane, and data plane. The forwarding plane contains a tunnel that can be accomplished with technologies such as VPN, VXLAN, etc., and policy information. The signaling & control plane contains entire topology information, Bgp-evpn protocols, SDN controller functions, and NFV Orchestrator functions. The Data plane contains an open flow protocol and underlay network components such as distributed switch or router to handle L2-L4 rules. The model is evaluated using a simulation on a testbed with order processing and order orchestration of the cloud VPN feature.","PeriodicalId":221953,"journal":{"name":"2022 3rd International Conference on Smart Electronics and Communication (ICOSEC)","volume":"55 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-10-20","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":"{\"title\":\"A study of cloud-based VPN establishment using network function virtualization technique\",\"authors\":\"Sankili Santhanamahalingam, Saravanan Alagarsamy, Karthik Subramanian\",\"doi\":\"10.1109/ICOSEC54921.2022.9951894\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Network Function Virtualization is the process of moving networking functions like Firewall, Load Balancing, Virtual Private networks (VPN), Gateway Antivirus, etc. away from proprietary hardware to the virtual server. This paper suggests enabling VPN security features to business customers by moving VPN features away from dedicated hardware and applying the feature by instantiating the corresponding VNF template from the virtual server. This paper aspires to develop a suitable architecture model with Software-Defined Network and Network Function Virtualization as its core techniques that can render a cloud design for VPN.The proposed model consists of three parts that include forwarding plane, signaling & control plane, and data plane. The forwarding plane contains a tunnel that can be accomplished with technologies such as VPN, VXLAN, etc., and policy information. The signaling & control plane contains entire topology information, Bgp-evpn protocols, SDN controller functions, and NFV Orchestrator functions. The Data plane contains an open flow protocol and underlay network components such as distributed switch or router to handle L2-L4 rules. The model is evaluated using a simulation on a testbed with order processing and order orchestration of the cloud VPN feature.\",\"PeriodicalId\":221953,\"journal\":{\"name\":\"2022 3rd International Conference on Smart Electronics and Communication (ICOSEC)\",\"volume\":\"55 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2022-10-20\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"1\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2022 3rd International Conference on Smart Electronics and Communication (ICOSEC)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICOSEC54921.2022.9951894\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 3rd International Conference on Smart Electronics and Communication (ICOSEC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICOSEC54921.2022.9951894","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

摘要

网络功能虚拟化是将防火墙、负载平衡、虚拟专用网(VPN)、网关防病毒等网络功能从专有硬件转移到虚拟服务器的过程。本文建议通过将VPN功能从专用硬件移开,并通过从虚拟服务器实例化相应的VNF模板来应用该功能,从而为企业客户启用VPN安全功能。本文希望以软件定义网络和网络功能虚拟化为核心技术,开发一种合适的架构模型,实现VPN的云化设计。该模型由转发平面、信令控制平面和数据平面三部分组成。转发平面包含一个隧道,可以通过VPN、VXLAN等技术和策略信息来实现。信令控制平面包含完整的拓扑信息、Bgp-evpn协议、SDN控制器功能、NFV Orchestrator功能。数据平面包含开放流协议和底层网络组件(如分布式交换机或路由器),用于处理L2-L4规则。利用云VPN的订单处理和订单编排特性在测试平台上进行了仿真,对模型进行了评估。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
A study of cloud-based VPN establishment using network function virtualization technique
Network Function Virtualization is the process of moving networking functions like Firewall, Load Balancing, Virtual Private networks (VPN), Gateway Antivirus, etc. away from proprietary hardware to the virtual server. This paper suggests enabling VPN security features to business customers by moving VPN features away from dedicated hardware and applying the feature by instantiating the corresponding VNF template from the virtual server. This paper aspires to develop a suitable architecture model with Software-Defined Network and Network Function Virtualization as its core techniques that can render a cloud design for VPN.The proposed model consists of three parts that include forwarding plane, signaling & control plane, and data plane. The forwarding plane contains a tunnel that can be accomplished with technologies such as VPN, VXLAN, etc., and policy information. The signaling & control plane contains entire topology information, Bgp-evpn protocols, SDN controller functions, and NFV Orchestrator functions. The Data plane contains an open flow protocol and underlay network components such as distributed switch or router to handle L2-L4 rules. The model is evaluated using a simulation on a testbed with order processing and order orchestration of the cloud VPN feature.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信