SPINAT: Integrating IPsec into Overlay Routing

  • Authors:
  • Jukka Ylitalo;Patrik Salmela;Hannes Tschofenig

  • Affiliations:
  • Ericsson Research NomadicLab, Finland;Ericsson Research NomadicLab, Finland;Siemens, Germany

  • Venue:
  • SECURECOMM '05 Proceedings of the First International Conference on Security and Privacy for Emerging Areas in Communications Networks
  • Year:
  • 2005

Quantified Score

Hi-index 0.01

Visualization

Abstract

Tackling the major Internet security, scalability and mobility problems without essentially changing the existing Internet architecture has turned out to be a very challenging task. The overlay routing approaches fortunately seem to offer a sound way to mitigate most of these issues. Basically, they decouple the end-point identifiers from locators by defining a new namespace. Overlay routing is based on the dynamic binding, at middle-boxes, between the two namespaces. The approach is very close to Network Address Translation (NAT) principles. Therefore, the IPsec NAT traversal related problems apply also to overlay architectures. In this paper, we integrate IPsec into the overlay routing using Security Parameter Index (SPI) multiplexed NAT (SPINAT). Our approach reduces tunneling overhead and supports asymmetric communication paths. We believe that the SPINAT will be a key component in securing overlay routing infrastructures, like in the Internet IndirectionInfrastructure (i^3).