Application-Independent End-to-End Security in Shared-Link Access Networks

  • Authors:
  • Jose Carlos Brustoloni;Juan A. Garay

  • Affiliations:
  • -;-

  • Venue:
  • NETWORKING '00 Proceedings of the IFIP-TC6 / European Commission International Conference on Broadband Communications, High Performance Networking, and Performance of Communication Networks
  • Year:
  • 2000

Quantified Score

Hi-index 0.00

Visualization

Abstract

ISPs now offer Internet access via cable modem or DSL, which provide much higher bandwidth than does PSTN. Higher access bandwidths allow ISP customers to exploit NAT (network address and port translation) to amortize the cost of an ISP account among multiple computers. The reduced per-computer cost may encourage airport lounges, hotels, and other businesses that serve "road warriors" to provide Internet connectivity to their clients. Unfortunately, NAT may not interoperate with IPSec, which provides application-independent security in VPNs (virtual private networks). A VPN is necessary, e.g., to connect a "road warrior" securely to a corporate Intranet via the untrusted Internet. We propose a simple DHCP extension that allows client IPSec implementations to interoperate with NAT. The resulting architecture, EASE, makes "road warrior" access easy, secure, and economical.