物理 化学 生物 历史 地理 政治 教学计划 教学文档 管理文库 范文 考试文库 物业管理教学 生活常识 厨艺教学 驾照考试 毕业论文 求职指南 个人创业



    11-14 22:49:35    浏览次数: 510次    栏目:毕业论文参考文献

标签:论文参考文献格式,英语论文参考文献,会计论文参考文献,http://www.deyou8.com 毕业论文三级目录及摘要和参考文献,
摘  要
无线网络飞速发展,人们在充分享受各种无线接入网络便利的同时,各种安全问题也逐渐暴露出来。由于IPSec 能够提供较好的安全保护,能够有效解决上述问题,应用范围不断扩大。在传统的TCP协议中,假设丢包都是由网络拥塞造成的,这不适用于错误丢包比拥塞丢包更容易发生的无线链路。此时,启用拥塞控制机制,将导致TCP端到端的性能降低。而且现有的很多改进方案无法用于加密通信中,因为IPSec与TCP在无线网络中的改进方案之间存在冲突。在无线通信网络中,要保证通信的安全性和TCP协议的性能,就必须解决他们之间的冲突。而在在VPN系统的大规模应用中,由于其部署环境复杂,也面临不同软件在NDIS内核框架中的冲突和内核模块开发,移植,维护困难等问题。
在对目前流行的基于Windows平台的VPN系统体系结构及其实现技术进行深入分析的基础上,针对嵌入式终端的特点,提出了一种新的基于虚拟网卡的技术,详细阐述了其原理和优点。然后给出了在WinCE VPN系统中实现该技术的体系结构,能够从根本上解决上述问题。
根据应用存在的性能问题,对现有的各种无线网络下TCP性能改进机制与IPSec VPN的兼容性进行了详细的分析,比较各种可能方案之间的优点与缺点。在分析现有改进算法的基础上,提出了一种适用于有线/无线混合网络IPSec兼容的端到端的优化机制。通过接收端数据包到达时间间隔的变化累积来判断无线链路的状况,用ACK标记ELN通知发送端,避免不必要的拥塞控制而导致性能下降。通过NS2仿真实验, 并与TCP Reno进行了性能对比。结果表明,该机制能有效提高TCP在无线移动场景下的网络传输性能,同时和现有的安全机制也相兼容。 关键词:TCP ;VPN体系结构;虚拟网卡;有线无线混合网络;性能评价;拥塞控制;端到端 
While wireless access technology has experienced a rapid growth in recently years.The people while fully are enjoying each kind wireless, a number of security concerns have been raised for wireless networks in general. TCP is originally designed only for wired network and assumes that any loss is due to congestion. However, it is different in wireless situation in that wireless errors are more likely to occur than congestion. Such non-congestion packet loss,  when dealt with invoking a congestion control algorithm, resulting in degrade end-to-end performance. At the same time, many exist approach can not work when the encryption is used in the communication. So the security mechanism and TCP improving mechanism compatibility also is taken into considering of our works. But in the large-scale application of VPN system, because the deployment environment is complex, frequently can face the different software in NDIS kernel frame conflict, simultaneously the kernel module development, the transplant, maintains question and so on difficulty.
This paper deeply analyses the popular architecture and implement technology based on Windows VPN system structure, simultaneously aims at embed terminal characteristic, proposed one kind new based on virtual Network card technology, in detail elaborated its principle and the merit. The produced system has realized this technical system structure in WinCE VPN, could fundamentally solve the above problem.
Aiming at the performance problem of  VPN apply , this paper proposed a new end-to-end TCP performance improving mechanism, by using the interval movement cumulated of the packets received time on receiver, which can estimate the wireless link condition. Then it marks the ELN(Explicit loss notification)bit to notify the sender and TCP could be modified so as to refrain from going into congestion avoidance. Comparing the TCP Reno and the modified TCP ,by simulations using NS2,the results show it achieves an great improvement over mobile wireless networks and can work together with current security mechanism. Keywords:TCP ; Virtual NetWork Card; Wired-cum-Wireless Networks ; Performance Evaluation; Congestion Control end-to-end ; IPSec; VPN Architecture
目  录
学校代码10487              密级 I
摘  要 I
目  录 IV
1 绪  论 1
1.1 研究背景 1
1.2 国内外研究现状 3
1.3 主要研究内容 6
2 无线网络VPN解决方案 8
2.1 无线网络TCP与VPN协议 8
2.2 无线TCP性能改进模型 15
2.3 TCP改进方案性能分析与IPSEC兼容性解决方案 22
2.4 本章小结 24
3 基于虚拟网卡的VPN体系结构 25
3.1 基于WINDOWS VPN系统设计 25
3.2 新的VPN体系结构图 28
3.3 虚拟网卡启动流程 32
3.4 报文处理过程的分析 33
3.5 本章小结 34
4 新的无线TCP性能改进方案 36
4.1 NS2仿真工具的介绍 36
4.2 MODIFIED-TCP的定义 37
4.3 MODIFIED-TCP的设计思想 38
4.4 时间变化累计的计算 42
4.5 MODIFIED-TCP改进的实现 43
4.6 本章小结 45
5 VPN系统结构分析和性能评价 47
5.1 与传统VPN体系结构的比较 47
5.2 TCP改进模型性能的评估标准 47
5.3 MODIFIED-TCP参数分析 48
5.4 MODIFIED-TCP性能分析 49
5.5 本章小结 52
6 总结与展望 54
6.1 总结 54
6.2 展望 55
致  谢 56
附录1  攻读学位期间发表论文目录 60 参考文献  [1]. Majstor, F. WLAN security threats & solutions[C]. in LCN '03. 2003.  [2]. Park, J.S.   Dicoi, D., WLAN security: current and future[J]. Internet Computing, 2003. 7(5): p. 60 - 65.  [3]. Liang, C.Z.H.F.H. A new authentication and key exchange protocol in WLAN[C]. in ITCC 2005. 2005.  [4]. RFC2401, Security Architecture of the Internet Protocol[S], , IETF,*IETF 1998.  [5]. 京京工作室, IPSEC:新一代因特网安全标准. 1999, 北京: 机械工业出版社.  [6]. Alshamsi, A.   Saito, T. A technical comparison of IPSec and SSL [C]. in AINA 2005. 2005.  [7]. 林闯单志广任丰原, 计算机网络的服务质量(QoS). 2004, 北京: 清华大学出版社. 4-9.  [8]. H, B., S. S, and K.R. H, Improving Reliable Transport and Handoff Performance in Cellular Wireless Networks [J]. 1995. 1(4): p. 469-481.  [9]. Hui-min, L.Y.Y.M.Z. Improve TCP performance over wireless link[C]. in PIMRC 2003. 2003. [10]. RFC1631, The IP Network Address Translator (NAT), , IETF,*IETF 1994. [11]. RFC2709, Security Model with Tunnel-mode IPsec for NAT Domains[S], , IETF,*IETF 1999. [12]. RFC2341, Cisco Layer Two Forwarding (Protocol) "L2F", in IETF1998. [13]. RFC2661, Layer Two Tunneling Protocol "L2TP", in IETF1999. [14]. RFC2153, The Point-to-Point Protocol (PPP), , IETF,*IETF 1994. [15]. RFC2865, Remote Authentication Dial In User Service (RADIUS), , IETF,*IETF 2000. [16]. RFC1701, Generic Routing Encapsulation (GRE), , IETF,*IETF 1994. [17]. Bakre, A.   Badrinath, B.R. I-TCP: indirect TCP for mobile hosts[C]. in Distributed Computing Systems, 1995., Proceedings of the 15th International Conference. 1995. [18]. Bakre, A.V.   Badrinath, B.R., Implementation and performance evaluation of Indirect TCP[J]. Computers, 1997. 3(46): p. 260 - 278. [19]. I.Rhee,N.Balaguru,S Seshan, A.G.N.R. MTCP:Scalable TCP-like congest control for reliable multicast[C]. in INFOCOM. 1999. [20]. T.Goff,J. Moronisk, D. S.Phatak, A.V.G. Freeze-TCP:A true end-to-end TCP enhancement mechanism for mobile environments[C]. in INFOCOM. 2000. [21]. 林华生,程时端, 移动自组织网络中TCP性能优化的研究. 计算机工程与应用, 2004. 12(12). [22]. 符刚. 移动VPN解决方案. in 无线及移动通信委员会学术年会论文集. 2004. [23]. G.   De Blas, M.   Patrono, L.   Marra, P.   Tomasicchio, G. An IPSec-aware TCP PEP for integrated mobile satellite networks Ciccarese[C]. in Personal, Indoor and Mobile Radio Communications, 2004. 2004. Italy: IEEE International Symposium on Publication. [24]. 尤晋元史美林陈向群, Windows操作系统原理. 2001, 北京: 机械工业出版社. [25]. 陈向群王雷马洪兵等编著, Windows CE.NET 系统分析及实验教程. 2003, 北京: 机械工业出版社. [26]. Ding W, J.A. A A New Explicit Loss Notification and Acknowledgement for Wireless TCP [C]. in PIMRC 2001. 2001. San Diego CA. [27]. Stevens, W.R., TCP/IP详解卷1. Vol. 1. 2004, 北京: 机械工业出版社. [28]. RFC2409, The Internet Key Exchange(IKE)[S], , IETF,*IETF 1998. [29]. RFC2402, IP Authentication Header [S], , IETF,*IETF 1998. [30]. RFC2406, IP Encapsulation Security Payload (ESP)[S], , IETF,*IETF 1998. [31]. Kurose, J.F. and K.W. Boss, 计算机网络自顶向下方法与Internet特色. 2005, 北京: 机械工业出版社. 335-338 341-355. [32]. RFC2883, An Extension to the Selective Acknowledgement (SACK) Option for TCP, , IETF,*IETF 2000. [33]. Ohzahata, S.   Kimura, S.   Ebihara, Y.   Kawashima, K. A queue management method for improving TCP performance in wireless environments[C]. in WCNC'2004. 2004. [34]. Omotayo, A.   Williamson, C., Multi-layer analysis of Web browsing performance for wireless PDAs[J]. Local Computer Networks, 2004: p. 660 - 667. [35]. Min, X.W.Z.L.J.S.Y., Bit-error identification for TCP performance improvement[C]. Emerging Technologies: Frontiers of Mobile and Wireless Communication, 2004. 2(2): p. 561 - 566. [36]. Shagdar, O.   Shirazi, M.N.B.Z. Improving ECN-based TCP performance over wireless networks using a homogeneous implementation of EWLN[C]. in ICT 2003. 2003. Kyoto, Japan. [37]. 邓晓衡陈志刚,张连明, TCP Yuelu: 一种基于有线/无线混合网络端到端的拥塞控制机制. 计算机学报, 2005(8): p. 1342-1350. [38]. M. Gerla, M. Y. Sanadidi, R.W., TCP Westwood: Bandwidth Estimation for Enhanced Transport over Wireless Links. UCLA Computer Science, 2001. [39]. 江小丹,李宏,李晃等, 显式丢失通告算法的实现及其性能分析. 计算机工程, 2003. 29(18). [40]. Chinta, M.   Helal, A.   Lee, C. ILC-TCP: an interlayer collaboration protocol for TCP performance improvement in mobile and wireless environments[C]. in WCNC 2003. 2003. [41]. Zorzi, M. On the analytical computation of the interference statistics with applications to the performance evaluation of mobile radio systems[C]. in Communications, IEEE Transactions. 1997. [42]. Vacirca, F.   De Vendictis, A.   Baiocchi, A., Optimal Design of Hybrid FEC/ARQ Schemes for TCP over Wireless Links with Rayleigh Fading[J]. Mobile Computing, 2006. 5(4): p. 289 - 302. [43]. Vacirca, F.   De Vendictis, A.   Todini, A.   Baiocchi, A. On the effects of ARQ mechanisms on TCP performance in wireless environments[C]. in GLOBECOM '03. 2003. [44]. Haas, Z.J.   Agrawal, P. Mobile-TCP: an asymmetric transport protocol design for mobile systems[C]. in ICC 97. 1997. [45]. Chan, M.C.   Ramjee, R. Improving TCP/IP performance over third generation wireless networks[C]. in INFOCOM 2004. 2004. [46]. Ratnam, K.   Matta, I. WTCP: an efficient mechanism for improving TCP performance over wireless links[C]. in ISCC '98. 1998. [47]. Yizhou Li   Jacob, L. Proactive-WTCP: an end-to-end mechanism to improve TCP performance over wireless links[C]. in LCN '03. 2003. [48]. RFC2246, Transport Layer Security Version 1.0[S], in IETF1999. [49]. S, B. Transport-friendly ESP (or Layer Violations for Fun and Profit) [C] Network Distributed System Security Symp. in NDSS′99. 1999. San Diego CA. [50]. Nash, A., 公钥基础设施(PKI)—实现和管理电子安全. 2002, 北京: 清华大学出版社. [51]. 武安河, Windows 2000/XP WDM设备驱动程序开发. 第二版 ed. Vol. 3-9. 2005, 北京: 电子工业出版社. [52]. Richter, J., Windows核心编程. 2000, 北京: 机械工业出版社. 190-226 397-410. [53]. 徐雷鸣庞博赵耀, NS与网络模拟. 2003, 北京: 人民邮电出版社. 3-9. [54]. 李之棠刘刚肖凌, 一种与IPSec兼容的基于有线无线混合网络的TCP性能优化机制. 小型微型计算机系统, 2007. [55]. RFC3561, Ad hoc On-Demand Distance Vector (AODV) Routing, in IETF2003. [56]. Wennstrom, A.   Brunstrom, A.   Rendon, J., Impact of GPRS buffering on TCP performance[J]. Electronics Letters, 2004. 40(20): p. 1279 - 1281. [57]. J.Padhye ,V.Firoiu , D.Towsley , J.K. Modeling TCP Throughput:A Simple Model and its Empirical Validation. in ACM SIGCOMM'98. 1998.