{"title":"基于NGN的宽带和移动VPN架构","authors":"M. Kawashima, Shintaro Mizuno","doi":"10.1109/KINGN.2008.4542265","DOIUrl":null,"url":null,"abstract":"We propose a method for broadband mobile VPN over NGN, which is suitable for office-LAN access by business users and home-LAN access by consumers. The proposed method creates a channel for VPN communication using SIP signaling, allowing the public network and enterprise networks to perform session-based border control and QoS management. In addition, the proposed method achieves the hand-over of a VPN session using the SIP mobility approach. These features lead to the following advantages. First, the network can protect users' home gateways from malicious traffic. Second, enterprises can separate VPN gateways from enterprise firewalls and distribute many VPN gateways for each small segment. Third, the network can perform session-based QoS management. Last, the proposed method enables the mobile terminal to continue a VPN session while switching access networks. These advantages are valuable when we make emerging highspeed LAN applications executable over a public wide-area network.","PeriodicalId":417810,"journal":{"name":"2008 First ITU-T Kaleidoscope Academic Conference - Innovations in NGN: Future Network and Services","volume":"15 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2008-05-12","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":"{\"title\":\"Architecture for broadband and mobile VPN over NGN\",\"authors\":\"M. Kawashima, Shintaro Mizuno\",\"doi\":\"10.1109/KINGN.2008.4542265\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"We propose a method for broadband mobile VPN over NGN, which is suitable for office-LAN access by business users and home-LAN access by consumers. The proposed method creates a channel for VPN communication using SIP signaling, allowing the public network and enterprise networks to perform session-based border control and QoS management. In addition, the proposed method achieves the hand-over of a VPN session using the SIP mobility approach. These features lead to the following advantages. First, the network can protect users' home gateways from malicious traffic. Second, enterprises can separate VPN gateways from enterprise firewalls and distribute many VPN gateways for each small segment. Third, the network can perform session-based QoS management. Last, the proposed method enables the mobile terminal to continue a VPN session while switching access networks. These advantages are valuable when we make emerging highspeed LAN applications executable over a public wide-area network.\",\"PeriodicalId\":417810,\"journal\":{\"name\":\"2008 First ITU-T Kaleidoscope Academic Conference - Innovations in NGN: Future Network and Services\",\"volume\":\"15 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2008-05-12\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"1\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2008 First ITU-T Kaleidoscope Academic Conference - Innovations in NGN: Future Network and Services\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/KINGN.2008.4542265\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2008 First ITU-T Kaleidoscope Academic Conference - Innovations in NGN: Future Network and Services","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/KINGN.2008.4542265","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Architecture for broadband and mobile VPN over NGN
We propose a method for broadband mobile VPN over NGN, which is suitable for office-LAN access by business users and home-LAN access by consumers. The proposed method creates a channel for VPN communication using SIP signaling, allowing the public network and enterprise networks to perform session-based border control and QoS management. In addition, the proposed method achieves the hand-over of a VPN session using the SIP mobility approach. These features lead to the following advantages. First, the network can protect users' home gateways from malicious traffic. Second, enterprises can separate VPN gateways from enterprise firewalls and distribute many VPN gateways for each small segment. Third, the network can perform session-based QoS management. Last, the proposed method enables the mobile terminal to continue a VPN session while switching access networks. These advantages are valuable when we make emerging highspeed LAN applications executable over a public wide-area network.