Vol.54 No (June 2013) GSRAv2 1,a) 1,b) 1,c) 1,d) , IPsec-VPN SSL-VPN OpenVPN PacketiX VPN GSRA Group-based Secure Remote

Similar documents
GSRA IPsec-VPN NAT SSL-VPN GSRA Performance Evaluation of Group-based Secure Remote Access Kenta SUZUKI, 1 Hidekazu SUZUKI 1 and Akira WATANABE

NAT-f SIP NAT 1 1, 2 1 IP SIP NAT NAT NAT NAT-f NAT-free protocol NAT-f SIP Session Initiation Protocol NAT-f SIP NAT Researches on NAT traversal for

Vol. 52 No (Sep. 2011) NAT 1, IPsec DPRP Dynamic Process Resolution Protocol DPRP NAT Network Address Translation NAT-f NAT-free pr

Dual Stack Virtual Network Dual Stack Network RS DC Real Network 一般端末 GN NTM 端末 C NTM 端末 B IPv4 Private Network IPv4 Global Network NTM 端末 A NTM 端末 B

LAN

AirMac ネットワーク構成の手引き

IPSJ SIG Technical Report IPsec-VPN SSL-VPN GSRA Group-based Secure Remote Access CPROXY GSRA CPROXY A proposal of a Remote Access Method that

2ACL DC NTMobile ID ACL(Access Control List) DC Direction Request DC ID Access Check Request DC ACL Access Check Access Check Access Check Response DC

AirMac ネットワーク for Windows

内閣官房情報セキュリティセンター(NISC)

IPSJ SIG Technical Report Secret Tap Secret Tap Secret Flick 1 An Examination of Icon-based User Authentication Method Using Flick Input for

3_39.dvi

(Group-based Secure Remote Access)[4], DLNA GSRA NAT NAT-f(NAT-free protocol)[5],, DMP M-SEARH(Multicast) DLNA 機器の検索 HTTP GET (DDD) サーバの情報取得 機種の一覧表示 D

& Vol.5 No (Oct. 2015) TV 1,2,a) , Augmented TV TV AR Augmented Reality 3DCG TV Estimation of TV Screen Position and Ro

IP IP DHCP..

WMN Wi-Fi MBCR i

IPSJ SIG Technical Report Vol.2009-DPS-141 No.23 Vol.2009-GN-73 No.23 Vol.2009-EIP-46 No /11/27 t-room t-room 2 Development of

TCP/IP Internet Week 2002 [2002/12/17] Japan Registry Service Co., Ltd. No.3 Internet Week 2002 [2002/12/17] Japan Registry Service Co., Ltd. No.4 2

2006 [3] Scratch Squeak PEN [4] PenFlowchart 2 3 PenFlowchart 4 PenFlowchart PEN xdncl PEN [5] PEN xdncl DNCL 1 1 [6] 1 PEN Fig. 1 The PEN

Vol. 48 No. 4 Apr LAN TCP/IP LAN TCP/IP 1 PC TCP/IP 1 PC User-mode Linux 12 Development of a System to Visualize Computer Network Behavior for L


Teradici Corporation # Canada Way, Burnaby, BC V5G 4X8 Canada p f Teradici Corporation Teradi

1_26.dvi

YMS-VPN1_User_Manual

PeerPool IP NAT IP UPnP 2) Bonjour 3) PeerPool CPU 4) 2 UPnP Bonjour PeerPool CPU PeerPool PeerPool PPv2 PPv2 2. PeerPool 2.1 PeerPool PeerPool PoolGW

Vol.55 No (Jan. 2014) saccess 6 saccess 7 saccess 2. [3] p.33 * B (A) (B) (C) (D) (E) (F) *1 [3], [4] Web PDF a m

LAN LAN LAN LAN LAN LAN,, i

28 NTMobile Java Proposal and Implementation of Java Wrapper for NTMobile ( : ) :

Vol.53 No (Mar. 2012) 1, 1,a) 1, 2 1 1, , Musical Interaction System Based on Stage Metaphor Seiko Myojin 1, 1,a


Input image Initialize variables Loop for period of oscillation Update height map Make shade image Change property of image Output image Change time L

IPSJ SIG Technical Report , 2 Andorid Capture-A-Moment Capture-A-Moment Capturing System by SmartPhone to Record Real-Time Scene Kohei Takada,

橡sirahasi.PDF

6 2. AUTOSAR 2.1 AUTOSAR AUTOSAR ECU OSEK/VDX 3) OSEK/VDX OS AUTOSAR AUTOSAR ECU AUTOSAR 1 AUTOSAR BSW (Basic Software) (Runtime Environment) Applicat

17 Proposal of an Algorithm of Image Extraction and Research on Improvement of a Man-machine Interface of Food Intake Measuring System

untitled

Web ( ) [1] Web Shibboleth SSO Web SSO Web Web Shibboleth SAML IdP(Identity Provider) Web Web (SP:ServiceProvider) ( ) IdP Web Web MRA(Mail Retrieval

2011 NTT Information Sharing Platform Laboratories

IPSJ SIG Technical Report Vol.2015-DPS-163 No.4 Vol.2015-MBL-75 No /5/28 IEEE Android 1,a) 1,b) 2 1 IP NTMobile Network Traversal with Mo

VNSTProductDes3.0-1_jp.pdf

258 5) GPS 1 GPS 6) GPS DP 7) 8) 10) GPS GPS ) GPS Global Positioning System

7,, i

"CAS を利用した Single Sign On 環境の構築"

設定例集_Rev.8.03, Rev.9.00, Rev.10.01対応

IPSJ SIG Technical Report Vol.2017-ARC-225 No.12 Vol.2017-SLDM-179 No.12 Vol.2017-EMB-44 No /3/9 1 1 RTOS DefensiveZone DefensiveZone MPU RTOS

NATディスクリプタ機能

1 Web [2] Web [3] [4] [5], [6] [7] [8] S.W. [9] 3. MeetingShelf Web MeetingShelf MeetingShelf (1) (2) (3) (4) (5) Web MeetingShelf

Alliance [1] HNW; Home Network DLNA HNW IPv4 NAT HNW DMS Digital Media Server DLNA DLNA SIP Session Initiation Protocol [2] HNW [3], [4], [5] Web DMS

Web Web Web Web Web, i

ヤマハ ルーター ファイアウォール機能~説明資料~

1 I/F I/F 1 6) MobileIP 7) 8) MN: Monile Node MN AR Mobility Anchor Point(MAP) MobileIP HMIP HMIP HA-MAP MN MAP MN MAP HMIP MAP MN 2 MobileIP Mo

Vol.53 No (July 2012) EV ITS 1,a) , EV 1 EV ITS EV ITS EV EV EV Development and Evaluation of ITS Information Commu

( )

Vol. 42 No. SIG 8(TOD 10) July HTML 100 Development of Authoring and Delivery System for Synchronized Contents and Experiment on High Spe

& Vol.2 No (Mar. 2012) 1,a) , Bluetooth A Health Management Service by Cell Phones and Its Us

i TCP/IP NIC Intel 3com NIC TCP/IP *1 20 IPv4 IPv6 IPv6 TCP/IP TCP/IP *1 3

GSCIP IPsec LAN GSCIP IPsec End-to-End A Proposal and Evaluation for a Remote Access Method using GSCIP and IPsec Keisuke Imamura, Hidekazu Suzuki and

IPSJ SIG Technical Report Vol.2013-GN-86 No.35 Vol.2013-CDS-6 No /1/17 1,a) 2,b) (1) (2) (3) Development of Mobile Multilingual Medical

GPGPU

IPv4aaSを実現する技術の紹介

IPSJ SIG Technical Report * Wi-Fi Survey of the Internet connectivity using geolocation of smartphones Yoshiaki Kitaguchi * Kenichi Nagami and Yutaka

1 IPv6 WG OS SWG PCOSIPv6 Windows Vista 2 3 KAMEUSAGIMacOSX IPv6 2

Mac OS X Server QuickTime Streaming Server 5.0 の管理(バージョン 10.3 以降用)

IPSJ SIG Technical Report Vol.2014-EIP-63 No /2/21 1,a) Wi-Fi Probe Request MAC MAC Probe Request MAC A dynamic ads control based on tra

Q [4] 2. [3] [5] ϵ- Q Q CO CO [4] Q Q [1] i = X ln n i + C (1) n i i n n i i i n i = n X i i C exploration exploitation [4] Q Q Q ϵ 1 ϵ 3. [3] [5] [4]

TCP/IP IEEE Bluetooth LAN TCP TCP BEC FEC M T M R M T 2. 2 [5] AODV [4]DSR [3] 1 MS 100m 5 /100m 2 MD 2 c 2009 Information Processing Society of

1 Table 1: Identification by color of voxel Voxel Mode of expression Nothing Other 1 Orange 2 Blue 3 Yellow 4 SSL Humanoid SSL-Vision 3 3 [, 21] 8 325

ネットワーク化するデジタル情報家電の動向

Vol. 48 No. 3 Mar PM PM PMBOK PM PM PM PM PM A Proposal and Its Demonstration of Developing System for Project Managers through University-Indus

Vol.54 No (July 2013) [9] [10] [11] [12], [13] 1 Fig. 1 Flowchart of the proposed system. c 2013 Information

Faronics Core User Guide

IPv6 トラブルシューティング ホームネットワーク/SOHO編

2. CABAC CABAC CABAC 1 1 CABAC Figure 1 Overview of CABAC 2 DCT 2 0/ /1 CABAC [3] 3. 2 値化部 コンテキスト計算部 2 値算術符号化部 CABAC CABAC

ア 接続 管理 ーバ ー GPS インター ッ S C バス位置情報 バス ー ータ ー バス運行情報 & ニ ース 1 S バス停 ー C コンセン ータ CATV/FTTH GPS Web 2.2 Linux GPS Linux GPS c 2015 Infor

i

Cisco® ASA シリーズルーター向けDigiCert® 統合ガイド

1 DHT Fig. 1 Example of DHT 2 Successor Fig. 2 Example of Successor 2.1 Distributed Hash Table key key value O(1) DHT DHT 1 DHT 1 ID key ID IP value D

1 Gumblar Fig. 1 Flow of Gumblar attack. Fig. 2 2 RequestPolicy Example of operation based on RequestPolicy. (3-b) (4) PC (5) Web Web Web Web Gumblar


tcp/ip.key

<Documents Title Here>

1 4 4 [3] SNS 5 SNS , ,000 [2] c 2013 Information Processing Society of Japan

SRX300 Line of Services Gateways for the Branch

ID 3) 9 4) 5) ID 2 ID 2 ID 2 Bluetooth ID 2 SRCid1 DSTid2 2 id1 id2 ID SRC DST SRC 2 2 ID 2 2 QR 6) 8) 6) QR QR QR QR

Vol.57 No (Mar. 2016) 1,a) , L3 CG VDI VDI A Migration to a Cloud-based Information Infrastructure to Support

Microsoft PowerPoint - Amazon VPCとのVPN接続.pptx

DEIM Forum 2009 E

試験問題での表記規格 標準の名称験午前Ⅱ 問題文中で共通に使用される表記ルール 各問題文中に注記がない限り, 次の表記ルールが適用されているものとする. JIS Q 9001 JIS Q JIS Q JIS Q JIS Q JIS Q 2700

Cisco 1711/1712セキュリティ アクセス ルータの概要

Journal of Geography 116 (6) Configuration of Rapid Digital Mapping System Using Tablet PC and its Application to Obtaining Ground Truth

28 Docker Design and Implementation of Program Evaluation System Using Docker Virtualized Environment

IPSJ SIG Technical Report Vol.2011-IOT-12 No /3/ , 6 Construction and Operation of Large Scale Web Contents Distribution Platfo

IW2002-B5 1 Internet Week ( ) 9:30 12:30 ( ) Copyright 2002 All Rights Reserved, by Seiji Kumagai ADSL FTTH 24 IP LAN

Testing XML Performance

ヤマハ ルーター ファイアウォール機能~説明資料~

23 Fig. 2: hwmodulev2 3. Reconfigurable HPC 3.1 hw/sw hw/sw hw/sw FPGA PC FPGA PC FPGA HPC FPGA FPGA hw/sw hw/sw hw- Module FPGA hwmodule hw/sw FPGA h

[2] OCR [3], [4] [5] [6] [4], [7] [8], [9] 1 [10] Fig. 1 Current arrangement and size of ruby. 2 Fig. 2 Typography combined with printing

Wi-Fi Wi-Fi Wi-Fi Wi-Fi SAS SAS-2 Wi-Fi i

25 About what prevent spoofing of misusing a session information

Transcription:

GSRAv2 1,a) 1,b) 1,c) 1,d) 2012 9 21, 2013 3 1 IPsec-VPN SSL-VPN OpenVPN PacketiX VPN GSRA Group-based Secure Remote Access NAT GSRA GSRA NAT GSRAv2 GSRAv2 NAT VPN Proposal and Evaluation of GSRAv2 that Enables Remote Access from Home Kenta Suzuki 1,a) Hidekazu Suzuki 1,b) Kensaku Asahi 1,c) Akira Watanabe 1,d) Received: September 21, 2012, Accepted: March 1, 2013 Abstract: The demand for remote access technologies is increasing these days. Widely used technologies, such as IPsec-VPN, SSL-VPN, and PacketiX VPN have both merits and demerits. In particular, there appear some constraints if the terminal is in the private address areas. We have proposed GSRA (Group-based Secure Remote Access) that solves demerits of the above technologies in the past. However, it assumes that the terminal has a global address. In this paper, we propose GSRAv2, by which the terminal can have a private address while maintaining the GSRA features. The trial system shows that GSRA has superior performance compared to other technologies. Keywords: remote access, NAT traversal, VPN, access control 1. 1 Graduate School of Science and Technology, Meijo University, Nagoya, Aichi 468 8502, Japan a) kenta.suzuki@wata-lab.meijo-u.ac.jp b) hsuzuki@meijo-u.ac.jp c) asahi@meijo-u.ac.jp d) wtnbakr@meijo-u.ac.jp VPN Virtual Private Network VPN VPN IPsec- VPN [1], [2] SSL-VPN [3] OpenVPN [4] PacketiX VPN [5] GSRA Group-based Secure Remote Access [6], [7] IPsec-VPN SSL-VPN c 2013 Information Processing Society of Japan 1751

OpenVPN PacketiX VPN SSL VPN GSRA GSRA NAT NAT-f NAT-free protocol [8] NAT-f NAT GSRA NAT-f NAT IPsec-VPN NAT NAT IPsec-VPN OpenVPN PacketiX VPN IP IP GSRA GSRA NAT GSRAv2 GSRA NAT FreeBSD GSRAv2 2 3 GSRA 4 GSRAv2 5 6 7 2. IPsec-VPN SSL-VPN OpenVPN PacketiX VPN EN External Node IN Internal Node 2.1 IPsec-VPN IPsec-VPN IPsec VPN IPsec- VPN EN IKE Internet Key Exchange [1] IPsec ESP Encapsulating Security Payload [2] IPsec IP IPsec-VPN NAT IPsec-VPN NAT IPsec 2.2 SSL-VPN SSL-VPN SSL VPN DMZ DeMilitarized Zone SSL-VPN SSL Web EN EN NAT EN EN SSL-VPN Web Web 2.3 OpenVPN OpenVPN TUN/TAP [9] EN OpenVPN c 2013 Information Processing Society of Japan 1752

Ethernet TCP/UDP IP DNS LAN 2.4 PacketiX VPN PacketiX VPN EN IN NIC NIC PacketiX VPN VPN SSL NAT PacketiX VPN VPN SSL PacketiX VPN TCP TCP over TCP *1 [10] 3. GSRA GSRA GSRA NAT-f NAT-f EN NAT EN NAT G x x =NodeID IP P x IP V x IP s d t m G x : s IP G x s Group i GK i Group i G x : s G y : d G x : s G y : d G x : s G y : d G x : s G y : d *1 TCP TCP Fig. 1 1 GSRA An example of a remote access configuration with GSRA. Table 1 Host Name 3.1 GSRA 1 ACT An example of Access Control Table. IP Address Service Group d tcp Group1 Alice P IN e udp Group2 GSRA NAT NAT-f GSRA 1 EN GSRA GSRA GSRA 1 EN Group1 IN1 Group1 IN2 Group2 EN IN1 IN2 GSRA ACT Access Control Table IN IP ACT ACT 1 1 Group1 Alice TCP d Group2 UDP e 3.2 2 GSRA EN GSRA GK EN DNS IN GSRA IP G GR c 2013 Information Processing Society of Japan 1753

2 GSRA Fig. 2 Negotiation of GSRA. EN IN 2 (1) EN DNS IN Alice GSRA IP G GR EN DNS Reply G GR IP V IN EN IN IP V IN IN IP EN GSRA IP EN IN Alice G GR V IN NRT Name Relation Table EN GSRA IP (2) EN V IN EN VAT Virtual Address Translation table VAT (1) EN VAT (3) (4) (3) EN EN IN Alice Group1 Group Authentication Request GSRA GSRA ACT EN IN GSRA EN IN t t Group Authentication Response EN 3 Fig. 3 Remote access with address translation process. GSRA EN Group Authentication Response t VAT (4) GSRA EN GSRA EN (2) G GR : t Mapping Request GSRA GSRA Mapping Request GSRA EN Mapping Response EN GSRA (3) IN (5)IN 3 EN (2) EN IN EN VAT IP / GSRA GSRA / GSRA IN IN EN EN EN IN 4. GSRA EN GSRA NAT HR Home Router c 2013 Information Processing Society of Japan 1754

4.1 GSRA Mapping Request EN / GSRA HR EN HR IP / HR HR Mapping Request HR EN HR NAT SPI Stateful Packet Inspection SPI TCP HR TCP SYN HR EN HR SPI 4.2 4 EN V IN V IN TCP TCP SYN EN ICMP HR ICMP GSRA EN HR EN TCP SYN GSRA HR TCP GSRA IP HR TCP TCP SYN GSRA GSRA ICMP EN HR ICMP EN EN VAT GSRA GSRA GSRA EN VAT GSRA GSRA EN TCP SYN EN TCP SYN HR 2 TCP SYN HR HR SPI 4.3 GSRAv2 5 GSRAv2 GSRAv2 GSRA 4 TCP TCP BReq t UDP UDP BReq u ICMP BReq i BRes i BReq t GSRA TCP SYN GSRA BReq u UDP GSRA 5 TCP UDP BReq t BReq u HR Fig. 4 4 The principle of the proposed method. 5 GSRAv2 Fig. 5 Negotiation of GSRAv2. c 2013 Information Processing Society of Japan 1755

HR Group Authentication Request EN HR GSRA GSRA HR 5. GSRAv2 FreeBSD GSRA EN GSRA IP GSRA GSRA IP 5.1 EN EN 6 IP ip input() ip output() GSRA GSRA GSRA GSRA NRT VAT GSRA GSRAv2 GSRA 5.2 GSRA GSRA 7 GSRA 6 EN Fig. 6 Module configuration of EN. GSRA NAT natd natd FreeBSD NAT GSRA divert natd / GSRA ACT 6. GSRAv2 GSRAv2 6.1 2 HR HR IPsec-VPN HR IPsec HR HR IPsec-VPN OpenVPN PacketiX VPN VPN DHCP IN EN SSL-VPN GSRAv2 HR OpenVPN PacketiX VPN GSRAv2 3 IPsec-VPN OS 2 Table 2 Comparison of remote access methods. 7 GSRA Fig. 7 Module configuration of GSRA router. IPsec- VPN SSL- VPN Open VPN PacketiX VPN GSRA v2 HR c 2013 Information Processing Society of Japan 1756

SSL-VPN Web SSL-VPN Web IPsec 1 1 SSL-VPN 1 1 OpenVPN PacketiX VPN OpenVPN PacketiX VPN GSRA GSRAv2 2 OpenVPN PacketiX VPN 2 PacketiX VPN TCP TCP TCP over TCP 2 GSRAv2 GSRAv2 OS FreeBSD EN GUI 6.2 IPsec-VPN OpenVPN PacketiX VPN 3 IPsec FreeBSD7.2 racoon2-20090327c OpenVPN FreeBSD7.2 openvpn-2.0.6 9 Packetix VPN FreeBSD PacketiX VPN EN Windows7 PacketiX Ver.3.0 8 3 NIC 1000Base-T EN IN Dummynet [11] Dummynet 4 2 A 0 Dummynet B 10 ms 0.05% ping 4 AES 128 bit EN VPN IPsec-VPN IKEv2 [1] OpenVPN TCP UDP TCP over TCP UDP IPsec-VPN ESP OpenVPN PacketiX VPN SSL GSRAv2 PCCOM [12] OpenVPN PacketiX VPN 3 8 Fig. 8 Measurement environment. 3 Table 3 Device specification. OS CPU Memory EN FreeBSD7.2 Pentium4 3.40 GHz 1GB Home Router FreeBSD7.2 Pentium4 3.00 GHz 512 MB Dummynet FreeBSD8.0 Pentium4 2.80 GHz 512 MB VPN Server FreeBSD7.2 Pentium4 3.40 GHz 2GB IN FreeBSD7.2 Pentium4 2.80 GHz 1GB 4 Dummynet Table 4 Parameter of Dummynet. A 0ms 0% B 10 ms 0.05% c 2013 Information Processing Society of Japan 1757

VPN 10 (1) Wireshark *2 EN Wireshark OpenVPN PacketiX VPN EN IPsec-VPN GSRAv2 wget *3 IN 2 9 IPsec-VPN IKE SA IKE SA INIT IPsec SA IKE AUTH 2 212 ms 2 2 =40ms 172 ms 3 IPsec TCP TCP 3 OpenVPN 2.6 SSL VPN SSL 50 PacketiX VPN IPsec-VPN 224 ms EN NIC IP DHCP EN IP PacketiX VPN GSRAv2 61 ms GSRAv2 3 60 ms EN GSRA 1ms GSRA 2 GSRAv2 3 1 20 ms GSRA GSRAv2 (2) EN wget IN wget 1GB *4 PacketiX VPN 10 A GSRAv2 1.3 1000Base-T NIC LAN 932 Mbps NIC HR NAT 98.4 Mbps GSRAv2 91.9 Mbps Fig. 9 9 Result of a measurement of negotiation time. Fig. 10 10 Results of throughput measurement. *2 http://www.wireshark.org/ *3 http://www.gnu.org/software/wget/ *4 dd if=/dev/zero of=dummy.file bs=1m count=1000 c 2013 Information Processing Society of Japan 1758

IPsec-VPN OpenVPN PacketiX VPN GSRA PCCOM GSRA GSRAv2 B PacketiX VPN TCP TCP TCP TCP over TCP 6.3 IPv6 IPv4 IPv6 IPv4 NAT GSRAv2 NAT IPv6 NAT IPv6 NAT [13], [14] GSRAv2 IPv6 7. GSRA GSRA HR GSRAv2 GSRA [1] Kaufman, C., Hoffman, P., Nir, Y. and Eronen, P.: Internet Key Exchange Protocol Version 2 (IKEv2), RFC 5996, IETF (2010). [2] Kent, S.: IP Encapsulating Security Payload (ESP), RFC 4303, IETF (2005). [3] Dierks, T. and Rescorla, E.: The Transport Layer Security (TLS) Protocol, RFC 5246, IETF (2008). [4] OpenVPN Technologies, Inc.: OpenVPN Open Source VPN, available from http://openvpn.net/. [5] SoftEther Corporation: PacketiX VPN 3.0, available from http://www.softether.co.jp/jp/vpn3/. [6] NAT DICOMO2010 Vol.2010, No.1, pp.288 294 (2010). [7] NAT Vol.51, No.9, pp.1881 1891 (2010). [8] NAT NAT-f Vol.48, No.12, pp.3949 3961 (2007). [9] Krasnyansky, M.: Universal TUN/TAP device driver, available from http://www.kernel.org/pub/linux/ kernel/people/marcelo/linux-2.4/documentation/ networking/tuntap.txt. [10] Titz, O.: Why TCP Over TCP Is A Bad Idea, available from http://sites.inka.de/sites/bigred/devel/tcp-tcp. html. [11] Rizzo, L.: Dummynet home page, available from http://info.iet.unipi.it/ luigi/dummynet/. [12] NAT PCCOM Vol.47, No.7, pp.2258 2266 (2006). [13] Thaler, D., Zhang, L. and Lebovitz, G.: IAB Thoughts on IPv6 Network Address Translation, RFC 5902, IETF (2010). [14] Wasserman, M. and Baker, F.: IPv6-to-IPv6 Network Prefix Translation, RFC 6296, IETF (2011). 2010 2012 2004 2006 2009 2008 2010 IEEE c 2013 Information Processing Society of Japan 1759

2001 2003 2008 14 16 IEEE 1974 1976 LAN 1991 2002 IEEE c 2013 Information Processing Society of Japan 1760