论文标题

QPEP:一种基于QUIC的方法,用于加密性能增强高延迟卫星宽带代理

QPEP: A QUIC-Based Approach to Encrypted Performance Enhancing Proxies for High-Latency Satellite Broadband

论文作者

Pavur, James, Strohmeier, Martin, Lenders, Vincent, Martinovic, Ivan

论文摘要

卫星宽带服务是至关重要的基础设施,使高级技术能够在全球最偏远的地区发挥作用。但是,默认情况下通常未加密状态服务,并且容易受到窃听攻击的影响。在本文中,我们挑战了历史上的看法,即,由于绩效增强的代理(PEPS)的深刻检查要求,高线安全性卫星网络中必须与TCP性能进行权衡。 在考虑了为何在此领域的先前工作未能找到广泛采用之后,我们提出了一个开源的默认PEP-QPEP- QPEP-旨在解决这些问题的开源。 QPEP围绕开放式标准构建,设计,因此各个客户可以在没有ISP参与的情况下采用它。 QPEP的性能通过基于可复制的Docker测试床中的模拟进行评估。在许多基准和网络条件中,发现QPEP避免了PEP设计中感知到的安全性加密权衡。与未加密的PEP实施相比,QPEP将平均页面加载时间减少了30%以上,同时也提供了无线隐私。与当今客户可用的传统VPN加密相比,QPEP超过一半的平均页面加载时间。这些实验共同得出的结论是,QPEP代表了一种有希望的新方法来保护现代卫星宽带连接。

Satellite broadband services are critical infrastructures enabling advanced technologies to function in the most remote regions of the globe. However, status-quo services are often unencrypted by default and vulnerable to eavesdropping attacks. In this paper, we challenge the historical perception that over-the-air security must trade off with TCP performance in high-latency satellite networks due to the deep-packet inspection requirements of Performance Enhancing Proxies (PEPs). After considering why prior work in this area has failed to find wide adoption, we present an open-source encrypted-by-default PEP - QPEP - which seeks to address these issues. QPEP is built around the open QUIC standard and designed so individual customers may adopt it without ISP involvement. QPEP's performance is assessed through simulations in a replicable docker-based testbed. Across many benchmarks and network conditions, QPEP is found to avoid the perceived security-encryption trade-off in PEP design. Compared to unencrypted PEP implementations, QPEP reduces average page load times by more than 30% while also offering over-the-air privacy. Compared to the traditional VPN encryption available to customers today, QPEP more than halves average page load times. Together, these experiments lead to the conclusion that QPEP represents a promising new approach to protecting modern satellite broadband connections.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源