vix.ing · top · new · best · stats · spec

Virtual Private Overlays: Secure Group Commounication in NAT-Constrained\n Environments

2010/01/14 by David Isaac Wolinsky, Wolinsky, David Isaac, Kyungyong Lee +7
Computer Science · Social Sciences · #Peer-to-Peer Network Technologies #Caching and Content Delivery #Access Control and Trust

paper · pdf · doi:10.48550/arxiv.1001.2569

Abstract

Structured P2P overlays provide a framework for building distributed\napplications that are self-configuring, scalable, and resilient to node\nfailures. Such systems have been successfully adopted in large-scale Internet\nservices such as content delivery networks and file sharing; however,\nwidespread adoption in small/medium scales has been limited due in part to\nsecurity concerns and difficulty bootstrapping in NAT-constrained environments.\nNonetheless, P2P systems can be designed to provide guaranteed lookup times,\nNAT traversal, point-to-point overlay security, and distributed data stores. In\nthis paper we propose a novel way of creating overlays that are both secure and\nprivate and a method to bootstrap them using a public overlay. Private overlay\nnodes use the public overlay's distributed data store to discover each other,\nand the public overlay's connections to assist with NAT hole punching and as\nrelays providing STUN and TURN NAT traversal techniques. The security framework\nutilizes groups, which are created and managed by users through a web based\nuser interface. Each group acts as a Public Key Infrastructure (PKI) relying on\nthe use of a centrally-managed web site providing an automated Certificate\nAuthority (CA). We present a reference implementation which has been used in a\nP2P VPN (Virtual Private Network). To evaluate our contributions, we apply our\ntechniques to an overlay network modeler, event-driven simulations using\nsimulated time delays, and deployment in the PlanetLab wide-area testbed.\n

Citations

Related