Security policy searching method research of IPSec VPN based on multi-core network processor

Liang CHEN,Jian WANG,Yong ZHAO
DOI: https://doi.org/10.3778/j.issn.1002-8331.1606-0006
2017-01-01
Abstract:In order to meet the security requirements of modern high bandwidth Internet application environment, an IPSec VPN architecture based on Tilera GX36 multi-core network processor is proposed, and program function modules of control plane and data plane are designed according to SDN architecture to achieve flexible security control on network traffic. To meet the security strategy retrieval performance requirement, a three-level security policy flow-table structure based on Hash algorithm is put forward, and a security policy search method is designed using security association flow-table cached on tile CPUs as fast retrieval data source. The test results show that the system can achieve the processing performance in 40 Gb/s Internet applications under the typical short, medium and long package-length circumstance.
What problem does this paper attempt to address?