On the Effectiveness of IP-Routable Entire-Packet Encryption Service Over Public Networks (November 2018)
The Internet is an unsecured public network accessed by approximately half of the world population. There are several techniques, such as cryptography, end-to-end encryption, and tunneling, used to preserve data security and integrity and to reduce information theft. This is because the security of...
Main Authors: | , , |
---|---|
Format: | Article |
Language: | English |
Published: |
IEEE
2018-01-01
|
Series: | IEEE Access |
Subjects: | |
Online Access: | https://ieeexplore.ieee.org/document/8540818/ |
_version_ | 1818615247406104576 |
---|---|
author | Rajitha Tennekoon Janaka Wijekoon Hiroaki Nishi |
author_facet | Rajitha Tennekoon Janaka Wijekoon Hiroaki Nishi |
author_sort | Rajitha Tennekoon |
collection | DOAJ |
description | The Internet is an unsecured public network accessed by approximately half of the world population. There are several techniques, such as cryptography, end-to-end encryption, and tunneling, used to preserve data security and integrity and to reduce information theft. This is because the security of data transmission over public networks is an ever-questionable issue. However, none of the above techniques are capable of providing the flexibility of changing either the algorithm or its key at the intermediary routers according to the requirements of stakeholders, e.g., ISPs or Internet users. Although the transmitted data are encrypted and unreadable, the metadata contained in the packet headers are readable during traversal. Nonetheless, service-based Internet architectures, e.g., IoT architectures, demand the analysis the data streams at the intermediary routers to provide smart services such as strengthening the security of the data streams. To this end, this paper proposes a method to use service-oriented routers for providing secure data transmission by encrypting data packets including the header and trailer information. A prototype of the proposed method is implemented on the ns-3 simulator, and this paper discusses the implementation notes and evaluation of the test results. The test results demonstrate that there is only an average processing cost of 180.14/191.35, 213.96/257.41, 157.56/170.68, and 235.48/<inline-formula> <tex-math notation="LaTeX">$249.49~\mu \text{s}$ </tex-math></inline-formula> for encrypting the total encrypted combined packets/total encrypted separate packets using IDEA, DES, AES-GCM, and AES-CTR encryption algorithms, respectively, with a 256-bit key space. This is significantly lower than the tolerable transmission delay (150 ms) defined by the ITU-T. |
first_indexed | 2024-12-16T16:30:52Z |
format | Article |
id | doaj.art-e7cd2ff0b49841c18b06684bbb8bb67b |
institution | Directory Open Access Journal |
issn | 2169-3536 |
language | English |
last_indexed | 2024-12-16T16:30:52Z |
publishDate | 2018-01-01 |
publisher | IEEE |
record_format | Article |
series | IEEE Access |
spelling | doaj.art-e7cd2ff0b49841c18b06684bbb8bb67b2022-12-21T22:24:36ZengIEEEIEEE Access2169-35362018-01-016731707317910.1109/ACCESS.2018.28823908540818On the Effectiveness of IP-Routable Entire-Packet Encryption Service Over Public Networks (November 2018)Rajitha Tennekoon0https://orcid.org/0000-0001-5902-0696Janaka Wijekoon1Hiroaki Nishi2Department of System Design Engineering, Faculty of Science and Technology, Hiroaki Nishi Laboratory, Keio University, Kohoku-ku, Yokohama, JapanDepartment of System Design Engineering, Faculty of Science and Technology, Hiroaki Nishi Laboratory, Keio University, Kohoku-ku, Yokohama, JapanDepartment of System Design Engineering, Faculty of Science and Technology, Hiroaki Nishi Laboratory, Keio University, Kohoku-ku, Yokohama, JapanThe Internet is an unsecured public network accessed by approximately half of the world population. There are several techniques, such as cryptography, end-to-end encryption, and tunneling, used to preserve data security and integrity and to reduce information theft. This is because the security of data transmission over public networks is an ever-questionable issue. However, none of the above techniques are capable of providing the flexibility of changing either the algorithm or its key at the intermediary routers according to the requirements of stakeholders, e.g., ISPs or Internet users. Although the transmitted data are encrypted and unreadable, the metadata contained in the packet headers are readable during traversal. Nonetheless, service-based Internet architectures, e.g., IoT architectures, demand the analysis the data streams at the intermediary routers to provide smart services such as strengthening the security of the data streams. To this end, this paper proposes a method to use service-oriented routers for providing secure data transmission by encrypting data packets including the header and trailer information. A prototype of the proposed method is implemented on the ns-3 simulator, and this paper discusses the implementation notes and evaluation of the test results. The test results demonstrate that there is only an average processing cost of 180.14/191.35, 213.96/257.41, 157.56/170.68, and 235.48/<inline-formula> <tex-math notation="LaTeX">$249.49~\mu \text{s}$ </tex-math></inline-formula> for encrypting the total encrypted combined packets/total encrypted separate packets using IDEA, DES, AES-GCM, and AES-CTR encryption algorithms, respectively, with a 256-bit key space. This is significantly lower than the tolerable transmission delay (150 ms) defined by the ITU-T.https://ieeexplore.ieee.org/document/8540818/Service-oriented routerper-hop data encryptionentire-packet encryptionencryptionns-3 |
spellingShingle | Rajitha Tennekoon Janaka Wijekoon Hiroaki Nishi On the Effectiveness of IP-Routable Entire-Packet Encryption Service Over Public Networks (November 2018) IEEE Access Service-oriented router per-hop data encryption entire-packet encryption encryption ns-3 |
title | On the Effectiveness of IP-Routable Entire-Packet Encryption Service Over Public Networks (November 2018) |
title_full | On the Effectiveness of IP-Routable Entire-Packet Encryption Service Over Public Networks (November 2018) |
title_fullStr | On the Effectiveness of IP-Routable Entire-Packet Encryption Service Over Public Networks (November 2018) |
title_full_unstemmed | On the Effectiveness of IP-Routable Entire-Packet Encryption Service Over Public Networks (November 2018) |
title_short | On the Effectiveness of IP-Routable Entire-Packet Encryption Service Over Public Networks (November 2018) |
title_sort | on the effectiveness of ip routable entire packet encryption service over public networks november 2018 |
topic | Service-oriented router per-hop data encryption entire-packet encryption encryption ns-3 |
url | https://ieeexplore.ieee.org/document/8540818/ |
work_keys_str_mv | AT rajithatennekoon ontheeffectivenessofiproutableentirepacketencryptionserviceoverpublicnetworksnovember2018 AT janakawijekoon ontheeffectivenessofiproutableentirepacketencryptionserviceoverpublicnetworksnovember2018 AT hiroakinishi ontheeffectivenessofiproutableentirepacketencryptionserviceoverpublicnetworksnovember2018 |