Distributed processing system, distributed processing method, and program
A distributed processing system distributes IPsec tunnel termination processes among multiple devices, enhancing communication speed by managing ISAKMP messages and IPsec SA parameters, addressing the bottleneck in existing systems.
Patent Information
- Application Number
- JP2024524547
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-05-30
- Publication Date
- 2025-10-01
- Estimated Expiration
- 2042-05-30
AI Technical Summary
The processing performance of IPsec tunnel termination units in existing communication systems is limited, acting as a bottleneck for communication speed due to high processing loads, particularly in AH/ESP tunnel termination processes.
A distributed processing system is implemented, comprising a tunnel starting point, multiple tunnel termination points, and distributed processing units that distribute tunnel termination processing among multiple devices, including ISAKMP message termination and IPsec SA parameter management, with IP address conversion for VPN formation.
The system improves tunnel termination processing performance by scaling out the processing load, enabling efficient communication through distributed processing units that manage IPsec tunnel termination across multiple devices.
Smart Images

Figure 0007747197000001 
Figure 0007747197000002 
Figure 0007747197000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a distributed processing system, a distributed processing method, and a program. [Background technology]
[0002] IPsec (Security Architecture for Internet Protocol) is a set of protocols for protecting IP communications at the network layer by authenticating and encrypting each IP packet in a data stream (Non-Patent Document 1). IPsec uses encryption technology to provide tamper detection and confidentiality functions for each IP packet. By employing IPsec, it is possible to prevent interception and tampering of communication content along the communication path, even when using a transport layer or application that does not support encryption.
[0003] IPsec has often been implemented using dedicated equipment. However, there are methods to implement IPsec termination processing inexpensively using software on a server, such as strongSwan in Non-Patent Document 2. [Prior art documents] [Non-patent literature]
[0004] [Non-Patent Document 1] "IPSRC", RFC6071, Internet<URL:https: / / tex2e.github.io / rfc-translater / html / rfc6071.html> [Non-patent document 2] IPsec termination software (strongSwan), Internet<URL:https: / / www.strongswan.org / > Summary of the Invention [Problem to be solved by the invention]
[0005] The problem to be solved by the present invention will be described using the configuration diagram of a communication system employing IPsec according to a comparative example shown in FIG. The communication system 1A is configured to include a tunnel initiation point 31 and a tunnel termination point 32. The tunnel initiation point 31 and the tunnel termination point 32 are configured by installing IPsec termination software on, for example, an IA (Intel Architecture) server. An IPsec tunnel 5 is stretched between the tunnel initiation point 31 and the tunnel termination point 32. The tunnel initiation point 31 is a functional unit that performs IPsec tunnel initiation processing. The tunnel termination point 32 is a functional unit that performs IPsec tunnel termination processing.
[0006] The opposite device 21 is communicatively connected to the tunnel starting point 31, and communicates with the opposite device 22 via this communication system 1A. The opposite device 22 is communicatively connected to the tunnel ending point 32, and communicates with the opposite device 21 via this communication system 1A.
[0007] In communication between the opposite device 21 and the opposite device 22, the communication system 1A forms an IPsec tunnel 5 between the tunnel starting point 31 and the tunnel terminal unit 32. In this case, the tunnel terminal unit 32 cannot achieve a processing performance higher than that of the IA server constituting the tunnel terminal unit 32.
[0008] The processing load of the tunnel termination process is larger than that of the encryption process of AH (Authentication Header) / ESP (Encapsulated Security Payload) than that of the ISAKAMP SA (Internet Security Association and Key Management Protocol Security Association). In other words, the limitations on the processing performance of the IA server constituting the tunnel termination unit 32 became a bottleneck in the communication speed of the communication system 1A.
[0009] Therefore, an object of the present invention is to distribute the tunnel termination processing among a plurality of devices. [Means for solving the problem]
[0010] In order to solve the above-mentioned problems, the distributed processing system of the present invention comprises a tunnel start point arranged on one side of a tunnel through which a packet flows, a plurality of tunnel end points arranged on the other side of the tunnel, and a plurality of tunnel end points arranged on the other side of the tunnel. and in front of the end portions of the plurality of tunnels a first distributed processing unit that configures a VPN between the first and second tunnel termination units; The latter part of and a second distributed processing unit connected to the Other means will be described in the detailed description of the invention. [Effects of the Invention]
[0011] According to the present invention, it is possible to distribute the tunnel termination process among multiple devices. [Brief explanation of the drawings]
[0012] [Figure 1] 1 is a configuration diagram of a communication system according to an embodiment of the present invention. [Figure 2] FIG. 10 is a sequence diagram showing pre-authentication of a tunnel termination point. [Figure 3] FIG. 10 is a sequence diagram showing key exchange (at connection establishment) at the end of an ISAKMP message in the IKE phase. [Figure 4] FIG. 10 is a diagram showing IP address conversion (during encrypted communication) for forming an AH / ESP tunnel in upstream communication. [Figure 5] FIG. 10 is a sequence diagram showing IP address conversion (during encrypted communication) for forming an AH / ESP tunnel in upstream communication. [Figure 6] FIG. 10 is a diagram showing IP address conversion (during encrypted communication) for forming an AH / ESP tunnel in downstream communication. [Figure 7] FIG. 10 is a sequence diagram showing IP address conversion (during encrypted communication) for forming an AH / ESP tunnel in downstream communication. [Figure 8]FIG. 1 is a configuration diagram of a communication system employing IPsec according to a comparative example. DETAILED DESCRIPTION OF THE INVENTION
[0013] Hereinafter, embodiments of the present invention will be described in detail with reference to the accompanying drawings. FIG. 1 is a configuration diagram of a communication system 1 according to this embodiment. The communication system 1 is configured to include a tunnel starting point 31 and multiple tunnel ending points 32a, 32b, ..., 32n. The tunnel starting point 31 and the multiple tunnel ending points 32a, 32b, ..., 32n are configured by installing IPsec termination software on an IA server, for example, and an IPsec tunnel 5 is stretched between them.
[0014] Tunnel initiation point 31 is a functional unit that performs IPsec tunnel initiation processing, and is located on one side of tunnel 5 through which packets flow. Multiple tunnel termination points 32a, 32b, ..., 32n are functional units that perform IPsec tunnel termination processing, and are located on the other side of tunnel 5. Tunnel initiation point 31 and multiple tunnel termination points 32a, 32b, ..., 32n are constructed on an IA server, which is a computer, and are realized by this IA server executing a distributed processing program.
[0015] The communication system 1 further includes a distributed processing unit 41 disposed in front of the plurality of tunnel termination units 32a, 32b, ..., 32n, and a distributed processing unit 42 disposed behind the plurality of tunnel termination units 32a, 32b, ..., 32n. The distributed processing unit 41 is a first distributed processing unit disposed inside the tunnel 5 and constituting a VPN with the tunnel starting end 31. The distributed processing unit 42 is a second distributed processing unit connected to the plurality of tunnel termination units 32a, 32b, ..., 32n.
[0016] The communication system 1 has an architecture in which a plurality of tunnel termination units 32a, 32b, . . . , 32n are arranged, thereby improving the tunnel termination processing performance through distributed processing.
[0017] The distributed processing unit 41 may distribute packets to any of the plurality of tunnel termination units 32a, 32b, ..., 32n. The distributed processing unit 41 distributes packets evenly to the plurality of tunnel termination units 32a, 32b, ..., 32n by using a distribution method such as round robin. By increasing the number of these tunnel termination units 32a, 32b, ..., 32n, the tunnel termination processing performance of the communication system 1 can be scaled out.
[0018] When a connection is established, the distributed processing unit 41 terminates an Internet Security Association and Key Management Protocol (ISAKMP) message, which is an Internet Key Exchange (IKE) phase.
[0019] Tunnel termination units 32a, 32b, ..., 32n perform AH / ESP tunnel termination processing. IPsec SA parameters are stored in distributed processing unit 41. Tunnel termination units 32a, 32b, ..., 32n refer to the IPsec SA parameters stored in distributed processing unit 41 and form SAs (Security Associations), which are connections.
[0020] Here, the AH protocol is a protocol that performs packet integrity checks. The ESP protocol encrypts packet data and optionally performs integrity checks, thereby preventing eavesdropping and tampering. In the communication system 1 of this embodiment, communication is protected in IPsec tunnel mode between the tunnel starting point 31 and the tunnel ending points 32a, 32b, ..., 32n.
[0021] The distributed processing units 41 and 42 are units for distributing AH / ESP packets to the multiple tunnel termination units 32a, 32b, ..., 32n. The distributed processing units 41 and 42 also perform termination processing of ISAKMP messages. Furthermore, the distributed processing units 41 and 42 are functional units that rewrite the virtual destination IP address, which forms a VPN endpoint as the termination IP address of the tunnel starting point 31, to one of the destination IP addresses of the multiple tunnel termination units 32a, 32b, ..., 32n.
[0022] FIG. 2 is a sequence diagram showing the pre-authentication of the tunnel termination units 32a, 32b, . . . , 32n. The distributed processing units 41 and 42 authenticate in advance the plurality of tunnel termination units 32a, 32b, . . . , 32n with which they communicate.
[0023] Specifically, tunnel terminal unit 32a transmits an authentication request to distributed processing unit 41 (step S10) and transmits an authentication request to distributed processing unit 42 (step S11). Tunnel terminal unit 32b transmits an authentication request to distributed processing unit 41 (step S12) and transmits an authentication request to distributed processing unit 42 (step S13). Similarly, tunnel terminal unit 32n transmits an authentication request to distributed processing unit 41 (step S14) and transmits an authentication request to distributed processing unit 42 (step S15).
[0024] Next, the distributed processing unit 41 sends a message of successful authentication to the tunnel termination unit 32a (step S16). The distributed processing unit 42 sends a message of successful authentication to the tunnel termination unit 32a (step S17). The distributed processing unit 41 sends a message of successful authentication to the tunnel termination unit 32b (step S18). The distributed processing unit 42 sends a message of successful authentication to the tunnel termination unit 32b (step S19). Similarly, the distributed processing unit 41 sends a message of successful authentication to the tunnel termination unit 32n (step S20). The distributed processing unit 42 sends a message of successful authentication to the tunnel termination unit 32n (step S21).
[0025] After the authentication, the distributed processing units 41 and 42 communicate only with the tunnel termination units 32a, 32b, . . . , 32n that have been authenticated in advance.
[0026] Authentication between the distributed processing units 41 and 42 and the plurality of tunnel termination units 32a, 32b, . . . , 32n may be performed using, for example, the existing technology of radius or diameter.
[0027] FIG. 3 is a sequence diagram showing key exchange (when a connection is established) at the end of an ISAKMP message in the IKE phase.
[0028] The tunnel starting end 31 transmits each parameter proposal of the SA to the distributed processing unit 41 (step S30). Then, after determining each parameter of the SA, the distributed processing unit 41 transmits each determined parameter of the SA to the tunnel starting end 31 (step S31). The tunnel starting end 31 transmits a public key to the distributed processing unit 41 (step S32).
[0029] Next, distributed processing unit 41 transmits the key information to tunnel terminal unit 32a (step S33), and transmits the key information to tunnel terminal unit 32b (step S34). Similarly, distributed processing unit 41 transmits the key information to tunnel terminal unit 32n (step S35).
[0030] Then, tunnel terminal unit 32a transmits an ACK (acknowledgement) to distributed processing unit 41 (step S36). Tunnel terminal unit 32b transmits an ACK (acknowledgement) to distributed processing unit 41 (step S37). Similarly, tunnel terminal unit 32n transmits an ACK (acknowledgement) to distributed processing unit 41 (step S38).
[0031] The distributed processing unit 41 transmits the nonce value to the tunnel starting end 31 to exchange keys (step S39). Here, the nonce value corresponds to the value of the private key. The tunnel starting point 31 authenticates the distributed processing unit 41 as a VPN device of the other party of communication (step S40). The distributed processing unit 41 authenticates the tunnel starting point 31 as a VPN device of the other party of communication (step S41).
[0032] Here, the distributed processing unit 41 terminates the ISAKMP message. Furthermore, the distributed processing unit 41 forms connections with the plurality of tunnel termination units 32a, 32b, ..., 32n.
[0033] FIG. 4 is a diagram showing IP address conversion (during encrypted communication) for forming an AH / ESP tunnel in upstream communication.
[0034] The tunnel starting point 31 forms a VPN endpoint with the temporary destination IP address XXX254 as the end IP address. The distributed processing unit 41 converts the virtual destination IP address XXX254 into the IP addresses XXX1, XXX2, ..., XXXn of the multiple tunnel termination units 32a, 32b, ..., 32n in order, and transfers the packet to the multiple tunnel termination units 32a, 32b, ..., 32n in order.
[0035] FIG. 5 is a sequence diagram showing IP address conversion (during encrypted communication) for forming an AH / ESP tunnel in upstream communication. First, the opposing device 21 transmits a packet to the tunnel starting point 31 (step S50). The tunnel starting point 31 encrypts and encapsulates the packet, sets the IP address XXX254 as a temporary destination, and forwards the encapsulated packet (step S52).
[0036] The encapsulated packet is transmitted from the tunnel starting point 31 to the distributed processing unit 41. The distributed processing unit 41 converts the temporary destination IP address XXX254 of the encapsulated packet into the IP addresses XXX1, XXX2, ..., XXXn of the multiple tunnel termination units 32a, 32b, ..., 32n in order (step S54). The encapsulated packet is then transmitted from the distributed processing unit 41 to the tunnel termination unit 32a (step S55). The distributed processing unit 41 transmits the encapsulated packet to the multiple tunnel termination units 32a, 32b, ..., 32n in a round robin manner, for example.
[0037] The tunnel termination unit 32a decrypts and decapsulates the encapsulated packet (step S56). Thereafter, the tunnel termination unit 32a transmits the packet to the distributed processing unit 42 (step S57). The distributed processing unit 42 relays the packet to the opposing device 22 (step S58).
[0038] FIG. 6 is a diagram showing IP address conversion (during encrypted communication) for forming an AH / ESP tunnel in downstream communication.
[0039] The distributed processing unit 41 converts the source IP addresses XXX1, XXX2, ..., XXXn into a temporary destination IP address XXX254. As a result, the communication system 1 forwards the packet while maintaining a state in which the tunnel starting point 31 forms a VPN endpoint with the temporary destination IP address XXX254.
[0040] When the tunnel termination units 32a, 32b, ..., 32n encrypt packets, they are encrypted based on the IPsec parameters of the distributed processing unit 41. As a result, the same IP address XXX254 is encrypted as the source address at all of the tunnel termination units 32a, 32b, ..., 32n.
[0041] FIG. 7 is a sequence diagram showing IP address conversion (during encrypted communication) for forming an AH / ESP tunnel in downstream communication. First, the opposing device 22 transmits a packet to the distributed processing unit 42 (step S60). The distributed processing unit 42 performs distribution processing (step S61) and transfers the packet to one of the plurality of tunnel termination units 32a, 32b, ..., 32n (step S62). The distribution processing is, for example, round robin. Here, the distributed processing unit 42 transmits the packet to the tunnel termination unit 32a (step S62).
[0042] The tunnel termination unit 32a encrypts and encapsulates this packet (step S63), and transmits the encapsulated packet to the distributed processing unit 41 (step S64). The distributed processing unit 41 converts the source IP address XXX1 into the temporary source IP address XXX254 (step S65), and relays the encapsulated packet to the tunnel starting end 31 (step S66).
[0043] The tunnel starting point 31 decapsulates and decrypts this packet (step S67), and then relays it to the opposing device 21 (step S68).
[0044] Effects resulting from the invention By distributing the tunnel termination processing required for an SA, which is one IPsec connection, it is possible to improve the tunnel termination processing performance.
[0045] <Key points of the invention> The present invention is a configuration that realizes scaling out of the tunnel termination section by arranging the distributed processing sections 41 and 42.
[0046] The present invention is configured such that the termination of ISAKMP messages in the IKE phase is performed by the distributed processing unit 41, and the AH / ESP tunnel termination processing is performed by a plurality of tunnel termination units 32a, 32b, . . . , 32n. The present invention is configured such that IPsec SA parameters are arranged in the distributed processing unit 41 and are referenced by the tunnel termination units 32a, 32b, . . . , 32n. In the present invention, in the upstream direction of communication, the distributed processing unit 41 rewrites the virtual destination IP address, which forms the VPN endpoint as the termination IP address of the tunnel starting point 31, into the destination IP addresses of multiple tunnel termination points 32a, 32b, ..., 32n.
[0047] In the present invention, in the downstream communication, the distributed processing unit 41 rewrites the IP addresses of multiple tunnel termination points 32a, 32b, ..., 32n to a virtual destination IP address where the tunnel starting point 31 forms a VPN endpoint as the termination IP address.
[0048] (Variation) The present invention is not limited to the above-described embodiment, and modifications can be made without departing from the spirit of the present invention, for example, the following (a) to (c) are possible.
[0049] (a) The temporary destination IP address XXX254 is an example, and any address may be selected. (b) The ESP protocol is an example. The present invention may also be implemented using the AH protocol. (c) In the above embodiment, the end processing of the tunnel 5 is distributed, but the start processing of the tunnel 5 may also be distributed.
[0050] "effect" The effects of the distributed processing system according to the present invention will be described below.
[0051] 《Claim 1》 a tunnel start point disposed on one side of the tunnel through which packets flow; a plurality of tunnel terminations disposed on the other side of the tunnel; a first distributed processing unit disposed in the tunnel and configuring a VPN between the first distributed processing unit and the tunnel starting end; a second distributed processing unit connected to the plurality of tunnel termination units; A distributed processing system comprising:
[0052] This allows the tunnel termination process to be distributed among multiple devices.
[0053] 《Claim 2》 the first distributed processing unit distributes packets to the plurality of tunnel termination units; 2. The distributed processing system according to claim 1, wherein:
[0054] This allows the tunnel termination process to be distributed among multiple devices.
[0055] 《Claim 3》 The first distributed processing unit terminates an ISAKMP message. 2. The distributed processing system according to claim 1, wherein:
[0056] This allows termination processing using the same key at multiple tunnel termination points.
[0057] 《Claim 4》 When relaying a packet to the tunnel termination unit, the first distributed processing unit converts the destination IP address of the packet from a virtual IP address forming a VPN endpoint to an IP address of one of the tunnel termination units. 4. The distributed processing system according to claim 1, wherein:
[0058] This makes it possible to distribute the tunnel termination processing of upstream packets among multiple devices.
[0059] 《Claim 5》 When relaying a packet to the tunnel starting point, the first distributed processing unit converts the source address of the packet from an IP address of one of the tunnel ending points to a virtual IP address that forms a VPN endpoint. 4. The distributed processing system according to claim 1, wherein:
[0060] This makes it possible to distribute the tunnel termination processing of downstream packets among multiple devices.
[0061] 《Claim 6》 the second distributed processing unit relays the packet to one of the plurality of tunnel termination units; 4. The distributed processing system according to claim 1, wherein:
[0062] This allows the tunnel termination process to be distributed among multiple devices.
[0063] 《Claim 7》 A computer placed inside the tunnel through which packets flow a procedure for constructing a VPN between a tunnel starting point located on one side of the tunnel; a step of translating a destination IP address of a packet received from the tunnel starting point from a virtual IP address forming a VPN endpoint to an IP address of one of the tunnel ending points located on the other side of the tunnel; A program to execute.
[0064] This allows the tunnel termination process to be distributed among multiple devices.
[0065] 《Claim 8》 A step in which a distributed processing unit arranged in a tunnel through which packets flow configures a VPN between itself and a tunnel starting end arranged on one side of the tunnel; converting a destination IP address of a packet received from the tunnel starting point from a virtual IP address forming a VPN endpoint to an IP address of one of the tunnel ending points located on the other side of the tunnel; A distributed processing method comprising:
[0066] This allows the tunnel termination process to be distributed among multiple devices. [Explanation of symbols]
[0067] 1. Communication Systems (Distributed Processing Systems) 1A Communication System 31 Tunnel start 32 Tunnel end 32a, 32b, ..., 32n Tunnel end 5. Tunnel 21 Opposite device 22 Opposite device 41 Distributed processing unit (first distributed processing unit) 42 Distributed processing unit (second distributed processing unit)
Claims
1. a tunnel start point disposed on one side of the tunnel through which packets flow; a plurality of tunnel terminations disposed on the other side of the tunnel; a first distributed processing unit that is disposed in the tunnel and in front of the plurality of tunnel termination units and that configures a VPN between the first distributed processing unit and the tunnel starting unit; a second distributed processing unit connected to a subsequent stage of the plurality of tunnel termination units; A distributed processing system comprising:
2. the first distributed processing unit distributes upstream communication packets to the plurality of tunnel termination units; 2. The distributed processing system according to claim 1.
3. The first distributed processing unit terminates an ISAKMP message.
2. The distributed processing system according to claim 1.
4. When relaying an upstream communication packet to the tunnel termination unit, the first distributed processing unit converts the destination IP address of the upstream communication packet from a virtual IP address forming a VPN endpoint to an IP address of one of the tunnel termination units.
4. The distributed processing system according to claim 1, wherein:
5. When relaying a downstream communication packet to the tunnel starting point, the first distributed processing unit converts a source address of the downstream communication packet from an IP address of one of the tunnel ending points to a virtual IP address that forms a VPN endpoint.
4. The distributed processing system according to claim 1, wherein:
6. the second distributed processing unit relays downstream communication packets to any one of the plurality of tunnel termination units; 4. The distributed processing system according to claim 1, wherein:
7. A computer placed inside the tunnel through which packets flow a procedure for constructing a VPN between a tunnel starting point located on one side of the tunnel; a step of translating a destination IP address of a packet received from the tunnel starting point from a virtual IP address forming a VPN endpoint to an IP address of one of a plurality of tunnel ending points located on the other side of the tunnel; A program to execute.
8. A step in which a distributed processing unit arranged in a tunnel through which packets flow configures a VPN between the distributed processing unit and a tunnel starting end arranged on one side of the tunnel; converting a destination IP address of a packet received from the tunnel starting point from a virtual IP address forming a VPN endpoint to an IP address of one of a plurality of tunnel ending points located on the other side of the tunnel; A distributed processing method comprising:
Citation Information
Patent Citations
Proxy tunnel end point unit, communication system for scalable network virtualization having the same and communication method for scalable network virtualization
US20160065384A1