On the Effectiveness of IP-Routable Entire-Packet Encryption Service Over Public Networks (November 2018)

The Internet is an unsecured public network accessed by approximately half of the world population. There are several techniques, such as cryptography, end-to-end encryption, and tunneling, used to preserve data security and integrity and to reduce information theft. This is because the security of...

Full description

Bibliographic Details
Main Authors: Rajitha Tennekoon, Janaka Wijekoon, Hiroaki Nishi
Format: Article
Language:English
Published: IEEE 2018-01-01
Series:IEEE Access
Subjects:
Online Access:https://ieeexplore.ieee.org/document/8540818/
_version_ 1818615247406104576
author Rajitha Tennekoon
Janaka Wijekoon
Hiroaki Nishi
author_facet Rajitha Tennekoon
Janaka Wijekoon
Hiroaki Nishi
author_sort Rajitha Tennekoon
collection DOAJ
description The Internet is an unsecured public network accessed by approximately half of the world population. There are several techniques, such as cryptography, end-to-end encryption, and tunneling, used to preserve data security and integrity and to reduce information theft. This is because the security of data transmission over public networks is an ever-questionable issue. However, none of the above techniques are capable of providing the flexibility of changing either the algorithm or its key at the intermediary routers according to the requirements of stakeholders, e.g., ISPs or Internet users. Although the transmitted data are encrypted and unreadable, the metadata contained in the packet headers are readable during traversal. Nonetheless, service-based Internet architectures, e.g., IoT architectures, demand the analysis the data streams at the intermediary routers to provide smart services such as strengthening the security of the data streams. To this end, this paper proposes a method to use service-oriented routers for providing secure data transmission by encrypting data packets including the header and trailer information. A prototype of the proposed method is implemented on the ns-3 simulator, and this paper discusses the implementation notes and evaluation of the test results. The test results demonstrate that there is only an average processing cost of 180.14/191.35, 213.96/257.41, 157.56/170.68, and 235.48/<inline-formula> <tex-math notation="LaTeX">$249.49~\mu \text{s}$ </tex-math></inline-formula> for encrypting the total encrypted combined packets/total encrypted separate packets using IDEA, DES, AES-GCM, and AES-CTR encryption algorithms, respectively, with a 256-bit key space. This is significantly lower than the tolerable transmission delay (150 ms) defined by the ITU-T.
first_indexed 2024-12-16T16:30:52Z
format Article
id doaj.art-e7cd2ff0b49841c18b06684bbb8bb67b
institution Directory Open Access Journal
issn 2169-3536
language English
last_indexed 2024-12-16T16:30:52Z
publishDate 2018-01-01
publisher IEEE
record_format Article
series IEEE Access
spelling doaj.art-e7cd2ff0b49841c18b06684bbb8bb67b2022-12-21T22:24:36ZengIEEEIEEE Access2169-35362018-01-016731707317910.1109/ACCESS.2018.28823908540818On the Effectiveness of IP-Routable Entire-Packet Encryption Service Over Public Networks (November 2018)Rajitha Tennekoon0https://orcid.org/0000-0001-5902-0696Janaka Wijekoon1Hiroaki Nishi2Department of System Design Engineering, Faculty of Science and Technology, Hiroaki Nishi Laboratory, Keio University, Kohoku-ku, Yokohama, JapanDepartment of System Design Engineering, Faculty of Science and Technology, Hiroaki Nishi Laboratory, Keio University, Kohoku-ku, Yokohama, JapanDepartment of System Design Engineering, Faculty of Science and Technology, Hiroaki Nishi Laboratory, Keio University, Kohoku-ku, Yokohama, JapanThe Internet is an unsecured public network accessed by approximately half of the world population. There are several techniques, such as cryptography, end-to-end encryption, and tunneling, used to preserve data security and integrity and to reduce information theft. This is because the security of data transmission over public networks is an ever-questionable issue. However, none of the above techniques are capable of providing the flexibility of changing either the algorithm or its key at the intermediary routers according to the requirements of stakeholders, e.g., ISPs or Internet users. Although the transmitted data are encrypted and unreadable, the metadata contained in the packet headers are readable during traversal. Nonetheless, service-based Internet architectures, e.g., IoT architectures, demand the analysis the data streams at the intermediary routers to provide smart services such as strengthening the security of the data streams. To this end, this paper proposes a method to use service-oriented routers for providing secure data transmission by encrypting data packets including the header and trailer information. A prototype of the proposed method is implemented on the ns-3 simulator, and this paper discusses the implementation notes and evaluation of the test results. The test results demonstrate that there is only an average processing cost of 180.14/191.35, 213.96/257.41, 157.56/170.68, and 235.48/<inline-formula> <tex-math notation="LaTeX">$249.49~\mu \text{s}$ </tex-math></inline-formula> for encrypting the total encrypted combined packets/total encrypted separate packets using IDEA, DES, AES-GCM, and AES-CTR encryption algorithms, respectively, with a 256-bit key space. This is significantly lower than the tolerable transmission delay (150 ms) defined by the ITU-T.https://ieeexplore.ieee.org/document/8540818/Service-oriented routerper-hop data encryptionentire-packet encryptionencryptionns-3
spellingShingle Rajitha Tennekoon
Janaka Wijekoon
Hiroaki Nishi
On the Effectiveness of IP-Routable Entire-Packet Encryption Service Over Public Networks (November 2018)
IEEE Access
Service-oriented router
per-hop data encryption
entire-packet encryption
encryption
ns-3
title On the Effectiveness of IP-Routable Entire-Packet Encryption Service Over Public Networks (November 2018)
title_full On the Effectiveness of IP-Routable Entire-Packet Encryption Service Over Public Networks (November 2018)
title_fullStr On the Effectiveness of IP-Routable Entire-Packet Encryption Service Over Public Networks (November 2018)
title_full_unstemmed On the Effectiveness of IP-Routable Entire-Packet Encryption Service Over Public Networks (November 2018)
title_short On the Effectiveness of IP-Routable Entire-Packet Encryption Service Over Public Networks (November 2018)
title_sort on the effectiveness of ip routable entire packet encryption service over public networks november 2018
topic Service-oriented router
per-hop data encryption
entire-packet encryption
encryption
ns-3
url https://ieeexplore.ieee.org/document/8540818/
work_keys_str_mv AT rajithatennekoon ontheeffectivenessofiproutableentirepacketencryptionserviceoverpublicnetworksnovember2018
AT janakawijekoon ontheeffectivenessofiproutableentirepacketencryptionserviceoverpublicnetworksnovember2018
AT hiroakinishi ontheeffectivenessofiproutableentirepacketencryptionserviceoverpublicnetworksnovember2018