Detailed Information

Cited 0 time in webofscience Cited 0 time in scopus
Metadata Downloads

IPsec for high speed network links: Performance analysis and enhancements

Full metadata record
DC Field Value Language
dc.contributor.authorUllah, Sami-
dc.contributor.authorChoi, Joontae-
dc.contributor.authorOh, Heekuck-
dc.date.accessioned2021-06-22T09:04:00Z-
dc.date.available2021-06-22T09:04:00Z-
dc.date.issued2020-06-
dc.identifier.issn0167-739X-
dc.identifier.issn1872-7115-
dc.identifier.urihttps://scholarworks.bwise.kr/erica/handle/2021.sw.erica/1065-
dc.description.abstractNetwork packets security has always been significantly important and well researched topic but the network throughput and latency are not optimal on high speed network links, when using existing IPsec solutions. Network packet processing in Linux kernel is significantly slow (especially for 10-G/40-G link speed) due to context switching associated with system calls, and transitional copy operations in packet traversal through all network layers. Control plane layered packet processing involve copy operation per layer, which increases the packet processing time and consequently decreases the throughput of the network. In contrast to the kernel networking, data plane solutions like DPDK (Data Plane Development Kit) provide direct access to packets (from NIC) in user-space bypassing kernel stack, with zero intermediate copy operations and no context switching. For the normal packets, Intel DPDK claims 10x improvement in the throughput over kernel networking. Being inspired by that remarkable efficiency, we have done empirical evaluation of IPsec performance in data plane. Towards this goal, primarily we have analyzed the performance effect by individual bottleneck modules of strongSwan (an IPsec implementation); by redesigning them with data plane equivalent modules. Secondarily, we have proposed an efficient solution for strongSwan using DPDK API; which eliminates all previously identified bottleneck modules. In the proposed design, multi-cores design has been incorporated in the crypto module and performance is analyzed in terms of throughput and latency. There is an improvement of up to 3.54x in throughput and 2.54x improvement in latency as compared to existing control plane design. With AES128GCM as encryption scheme, a maximum throughput of 4.795 Gbps is achieved, while using only two cores. (C) 2020 Elsevier B.V. All rights reserved.-
dc.format.extent14-
dc.language영어-
dc.language.isoENG-
dc.publisherELSEVIER-
dc.titleIPsec for high speed network links: Performance analysis and enhancements-
dc.typeArticle-
dc.publisher.location네델란드-
dc.identifier.doi10.1016/j.future.2020.01.049-
dc.identifier.scopusid2-s2.0-85078971922-
dc.identifier.wosid000527331800008-
dc.identifier.bibliographicCitationFUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, v.107, pp 112 - 125-
dc.citation.titleFUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE-
dc.citation.volume107-
dc.citation.startPage112-
dc.citation.endPage125-
dc.type.docTypeArticle-
dc.description.isOpenAccessN-
dc.description.journalRegisteredClassscie-
dc.description.journalRegisteredClassscopus-
dc.relation.journalResearchAreaComputer Science-
dc.relation.journalWebOfScienceCategoryComputer Science, Theory & Methods-
dc.subject.keywordAuthorIPsec-
dc.subject.keywordAuthorHigh speed network links security-
dc.subject.keywordAuthorPerformance analysis-
dc.subject.keywordAuthorBottlenecks in IPsec-
dc.subject.keywordAuthorDPDK-
dc.identifier.urlhttps://www.sciencedirect.com/science/article/pii/S0167739X19323143?via%3Dihub-
Files in This Item
Go to Link
Appears in
Collections
COLLEGE OF COMPUTING > ERICA 컴퓨터학부 > 1. Journal Articles

qrcode

Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.

Related Researcher

Researcher Oh, Hee kuck photo

Oh, Hee kuck
ERICA 소프트웨어융합대학 (ERICA 컴퓨터학부)
Read more

Altmetrics

Total Views & Downloads

BROWSE