E2E: An optimized IPsec architecture for secure and fast offload

  • Daniel Migault
  • , Daniel Palomares
  • , Emmanuel Herbert
  • , Wei You
  • , Gabriel Ganne
  • , Ghada Arfaoui
  • , Maryline Laurent

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

When mobile End Users are offloaded from aRadio Access Network (RAN) to a WLAN, current I-WLAN [1]offloaded architectures consider traffic converging to a commonSecurity Gateway. In this paper, we propose an alternativeEnd-to-End security (E2E) architecture based on the MOBIKE-X [2] protocol, which extends the MOBIKE [3] Mobility andMultihoming features to Multiple Interfaces and to the Transportmode of IPsec. The benefits of this E2E architecture are mostlyload reduction and a better End User experience. First, E2Eoffloads the ISP CORE and backhaul networks, then E2E usesIPsec Transport mode instead of Tunnel mode, which removesnetworking and security overhead. This reduces CPU load by20%, enhances Mobility and Multihoming operations by about15%, and makes the system 2.9 times more reactive for detectingmodifications of interfaces.

Original languageEnglish
Title of host publicationProceedings - 2012 7th International Conference on Availability, Reliability and Security, ARES 2012
PublisherIEEE Computer Society
Pages365-374
Number of pages10
ISBN (Print)9780769547756
DOIs
Publication statusPublished - 1 Jan 2012
Event2012 7th International Conference on Availability, Reliability and Security, ARES 2012 - Prague, Czech Republic
Duration: 20 Aug 201224 Aug 2012

Publication series

NameProceedings - 2012 7th International Conference on Availability, Reliability and Security, ARES 2012

Conference

Conference2012 7th International Conference on Availability, Reliability and Security, ARES 2012
Country/TerritoryCzech Republic
CityPrague
Period20/08/1224/08/12

Keywords

  • IKEv2
  • IPsec
  • MOBIKE
  • MOBIKE-X
  • Mobility
  • Multihoming

Fingerprint

Dive into the research topics of 'E2E: An optimized IPsec architecture for secure and fast offload'. Together they form a unique fingerprint.

Cite this