The Design and Implementation of IPSec Conflict Avoiding and Recovering System

Hung-Min Sun,Shih-Ying Chang,Yao-Hsin Chen,Bing-Zhe He,Cheng-Kai Chen
DOI: https://doi.org/10.1109/tencon.2007.4429003
2007-01-01
Abstract:IPSec has been popularly used in protecting data over IP network; however, how to detect and avoid policy conflicts is a big challenge. Under current architecture, user- space process can directly manipulate security associations database (SADB) or security policies database (SPDB) causing inter-application conflict, lack of access control, lack of conflict avoiding and recovering, and conflict diffusion. Previous proposed algorithms can only detect conflicts afterward instead of preventing them in advance. Therefore we propose a new architecture to avoid conflicts and provide recovery mechanism. Finally, we implement these functionalities and the evaluation of performance shows that this architecture is realistic and practical.
What problem does this paper attempt to address?