通信学报

• •    下一篇

10 Gbit网络访问控制网关的设计与实现

张晓军,崔 建,马 皓,张 蓓   

  1. 北京大学 计算中心,北京 100871
  • 出版日期:2014-10-25 发布日期:2014-12-16
  • 基金资助:
    国家发改委2011信息安全专项基金资助项目

Design and implementation of 10 Gbit network access control gateway

  • Online:2014-10-25 Published:2014-12-16

摘要: 为适应10 Gbit以太网传输速率,依照开放通用设计原则,重新设计和实现了第二代网络访问控制网关IPcG-10G。该系统根据认证用户的网络授权情况动态控制其访问网络资源,建立起网络实名访问机制,在加强网络安全的同时,保障网络带宽的合理使用。IPcG-10G采用多种优化技术提高10Gbit/s流量转发的性能,突破第一代吉比特IPcG系统的传输瓶颈,解决了速率不匹配带来的诸多问题,便于网络链路的管理和规划。

Abstract: To meet the 10 gigabit Ethernet transmission rate, a second generation network access control gateway (IPcG-10G) is redeveloped following the open and general design principle. IPcG-10G can dynamically control authenticated users to access to network resources based on their network authorization, thereby establishing the real-name registration network accessing mechanism in order to strengthen the network security and guarantee the rational use of network bandwidth. By utilizing a variety of optimal techniques, like zero-copy and socket buffer recycling, this system improves the performance of 10Gbps traffic forwarding. IPcG-10G breaks through the transmission bottleneck of the first generation gigabit IPcG, thus solving the mismatched rate problem and facilitating the network link management and planning.

No Suggested Reading articles found!