16th Annual Computer Security Applications Conference (ACSAC'00)
Virtual enterprise networks: the next generation of secure enterprise networking
New Orleans, Louisiana
December 11-December 15
ISBN: 0-7695-0859-6
G. Caronni, Sun Microsyst. Labs., Palo Alto, CA, USA
S. Kumar, Sun Microsyst. Labs., Palo Alto, CA, USA
C. Schuba, Sun Microsyst. Labs., Palo Alto, CA, USA
G. Scott, Sun Microsyst. Labs., Palo Alto, CA, USA
We present a vision of computing environments in which enterprise networks are built using untrusted public infrastructures. The vision allows for networks to dynamically change depending on the need of their users, rather than forcing the users to build organizations around networks. This vision is realized through a design abstraction called virtual enterprise networking, or short Supernetworking. A first prototype of such a Supernet has been implemented on Linux. Supernetworking introduces a new layer of abstraction in a layered model of computer networking. The Supernet layer sits directly above the network layer and includes its own addressing structure and security services which protect all data transmitted by the network layer. A key component of a Supernet is communications tunneling. Instead of the traditional two endpoints, our tunnels have as many endpoints as there are computers participating in a Supernet. While tunneling has been repeatedly used to implement infrastructure services such as multicasting, virtual private networks, and support for mobility, we distill these technologies into a single, simple abstraction. This new abstraction enables the ability to out-source network infrastructure services in a transparent and secure manner, mobility, and the creation and administration of secure ad-hoc virtual computer networks.
Index Terms:
business communication; computer network reliability; Unix; security of data; telecommunication security; network operating systems; business data processing; virtual enterprise networking; secure enterprise network; untrusted public infrastructures; organizations; Supernetworking; Linux; computer network; communications tunneling; network infrastructure services; mobility
Citation:
G. Caronni, S. Kumar, C. Schuba, G. Scott, "Virtual enterprise networks: the next generation of secure enterprise networking," acsac, pp.42, 16th Annual Computer Security Applications Conference (ACSAC'00), 2000