IPSEC and the Internet

dc.contributor.advisorBaras, John S.en_US
dc.contributor.authorKarir, Manishen_US
dc.contributor.departmentISRen_US
dc.contributor.departmentCSHCNen_US
dc.date.accessioned2007-05-23T10:08:51Z
dc.date.available2007-05-23T10:08:51Z
dc.date.issued1999en_US
dc.description.abstractSecure and efficient communication between computers is becoming more essential as companies attempt to utilize the public network infrastructure for supporting communication between their various sites.<p>The IPSEC protocols have been proposed as a solution to balance the needs of security and networking between computers. The basic IPSEC protocols are based on the end-to-end security model and when used in the most secure mode do not allow any intermediate nodes in the network to access and obtain information from packet headers encrypted by the security end-points.<p>However, with the advent of smart applications in the middle of the network, which attempt to make it more efficient, a tradeoff is created between security and efficiency. This tradeoff is the result of the need for these intelligent applications to access packet header information which is not possible with secure IPSEC flows. <p>This thesis analyzes and evaluates several possible solutions to this problem and argues why they all involve an unacceptable loss in the level of security or are not practical in any real system. On the basis of these arguments it thenproposes the use of Layered IPSEC to solve the problem. Layered IPSEC adds flexibility to the current IPSEC protocols by providing the ability to use multiple encryption algorithms with separate encryption keys for different parts of a packet.<p>We also describe an experimental implementation of the concept and provide timing measurements from it. On the basis of our experience with the implementation and our experimental measurements we argue for the feasiblity and usefulness of this scheme.en_US
dc.format.extent4666483 bytes
dc.format.mimetypeapplication/pdf
dc.identifier.urihttp://hdl.handle.net/1903/6108
dc.language.isoen_USen_US
dc.relation.ispartofseriesISR; MS 1999-14en_US
dc.relation.ispartofseriesCSHCN; MS 1999-9en_US
dc.subjectIPSECen_US
dc.subjectlayered IPSECen_US
dc.subjectsecurityen_US
dc.subjectInternet,en_US
dc.titleIPSEC and the Interneten_US
dc.typeThesisen_US

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
MS_99-14.pdf
Size:
4.45 MB
Format:
Adobe Portable Document Format