Browse > Article

IPSec based Network Design for the Mobile and Secure Military Communications  

Jung, Youn-Chan (가톨릭대학교 정보통신전자공학부 통신네트워크 연구실)
Abstract
Full-mesh IPSec tunnels, which constitute a black network, are required so that the dynamically changing PT (Plain Text) networks can be reachable across the black network in military environments. In the secure and mobile black networks, dynamically re-configuring IPSec tunnels and security policy database (SPD) is very difficult to manage. In this paper, for the purpose of solving mobility and security issues in military networks, we suggest the relating main technologies in association with DMIDP (Dynamic Multicast-based IPSec Discovery Protocol) based on existing IPSec ESP (Encapsulating Security Payload) tunnels and IPSec key managements. We investigate the main parameters of the proposed DMIDP techniques and their operational schemes which have effects on mobility and analyze operational effectivemess of the DMIDP with proposed parameters.
Keywords
IPSec Tunnels; Military Networks; Security Policy Database; Virtual Private Network; IPSec Discovery Protocol;
Citations & Related Records
연도 인용수 순위
  • Reference
1 A. Perrig, D. Song, and J. Tygar, "ELK, a new protocol for efficient large-group key distribution," IEEE Security and Privacy Symposium 2001, May. 2001
2 Brian J. Matt, Matt Mundy, "Adaptive Multicast Key Management for Tactical Networks," IEEE MILCOM, pp. 1-10, Oct. 2006
3 Trung H. Tran, "Proactive Multicast-based IPSec Discovery Protocol and Multicast Extension," IEEE MILCOM, pp. 1-7, Oct. 2006
4 INSC2/TASK2/DU/003, "Secure Multicast Architecture," Office of Naval Research, the United States, Aug. 2004
5 INSC II/TASK1/D/002, "Test and Demonstration Architecture," Office of Naval Research, the United States, Feb. 2005
6 정윤찬, 임진우, 황인용, 허미정, "멀티케스 기반의 Proactive IPSec 탐지 프로토콜의 설계," 제12차 통신/전자 학술대회 프로시팅, 국방과학연구소(서울) 10월 2008
7 RFC 2407, "The Internet Security Association Key Management Protocol," Nov. 1998
8 RFC 2401, "Security Architecture for the Internet Protocol," Nov. 1998
9 RFC 2406, "IP Encapsulating Security Payload (ESP)," Nov. 1998
10 L. Gong, "Enclaves: Enabling Secure Collaboration over me Internet," IEEE J. Select. Areas Commun., pp.567-575, Apr. 1997
11 RFC 2409, "The Internet Key Exchange (IKE)," Nov. 1998