• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2010, Vol. 32 ›› Issue (7): 4-7.doi: 10.3969/j.issn.1007130X.2010.

• 论文 • 上一篇    下一篇

一种新的采用TCP封装的IPSec广域网加速通信研究

梅松   

  1. (华中科技大学计算机科学与技术学院,湖北 武汉 430074)
  • 收稿日期:2009-01-09 修回日期:2009-08-26 出版日期:2010-06-25 发布日期:2010-06-25
  • 通讯作者: 梅松 E-mail:meisong@mail.hust.edu.cn
  • 作者简介:梅松(1977),男,河南信阳人,博士,讲师,研究方向为计算机系统结构和网络安全。
  • 基金资助:

    国家科技部创新基金资助项目(国科发计字[ 2003(375)])

Research on a New IPSec WAN AccelerationCommunication System Based on the TCP Tunnel

MEI Song   

  1. (School of Computer Science and Technology,Huazhong University of Science and Technology,Wuhan 430074,China)
  • Received:2009-01-09 Revised:2009-08-26 Online:2010-06-25 Published:2010-06-25
  • Contact: MEI Song E-mail:meisong@mail.hust.edu.cn

摘要:

本文首先针对广域网上TCP通信比较慢等问题进行了分析,接着再对IPSec体系进行剖析。为了提高IPSec保护的TCP数据的广域网通信性能,本文提出了采用ACK代理、组包和压缩以及IPSec over TCP等机制的TTAP协议,并给出了协议实现的结构和流程。为了对协议模型进行验证,本文以FreeSWAN软件为基础,对TTAP协议进行了设计和实现,并提供了性能测试数据作为比较,最后对新系统的性能进行了分析。

关键词: CP, 广域网, IPSec, FreeSWAN

Abstract:

This paper discusses the slow speed of the TCP communication in WANs,and analyses the architecture of IPSec. To improve the performance of the TCP communication protected by IPSec in WANs, a new TTAP(TCP Tunnel Acceleration Protocol)is proposed including its structure and procedure. The soft structure of FreeSWAN is improved and the performance test data are presented in order to validate this new protocol. Finally, the performance of the new system is analysed detailedly.

Key words: TCP;WAN;IPSec;FreeSWAN