Sign in to use this feature.

Years

Between: -

Subjects

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Journals

Article Types

Countries / Regions

Search Results (17)

Search Parameters:
Keywords = OpenVPN

Order results
Result details
Results per page
Select all
Export citation of selected articles as:
23 pages, 927 KB  
Article
On the Resilience of Secure Remote-Access VPN Solutions: A System-Level Evaluation of WireGuard, OpenVPN and IPsec (strongSwan)
by Rene Forsung, Rustam Pirmagomedov, Anzhelika Mezina, Jari Nurmi and Aleksandr Ometov
Cryptography 2026, 10(5), 61; https://doi.org/10.3390/cryptography10050061 - 22 Aug 2026
Viewed by 325
Abstract
Remote-access virtual private networks (VPNs) are a key component of enterprise security infrastructures. In practice, the effectiveness of a remote-access VPN is determined not only by cryptographic mechanisms but also by its ability to remain available and recover quickly under realistic operating conditions, [...] Read more.
Remote-access virtual private networks (VPNs) are a key component of enterprise security infrastructures. In practice, the effectiveness of a remote-access VPN is determined not only by cryptographic mechanisms but also by its ability to remain available and recover quickly under realistic operating conditions, which directly affects the operational security guarantees provided by the underlying cryptographic protocols. Enterprise deployments are characterized by heterogeneous client platforms, wireless access networks, and frequent endpoint and network disruptions. In this paper, we execute an exploratory case study of the operation of remote-access VPNs in enterprise environments through an empirical evaluation of WireGuard, OpenVPN, and IPsec. Using a controlled but realistic testbed with a cloud-hosted gateway and heterogeneous client platforms, we evaluate baseline performance as well as behavior under endpoint CPU stress, network impairments, MTU variation, and mobility-related disruptions, reflecting constrained and dynamically changing deployment conditions. The results suggest that VPN operational characteristics are influenced by both protocol design and execution environment. Within the evaluated deployment scenarios, kernel-based implementations generally exhibited higher resilience under endpoint resource contention and faster recovery after disruptions, while layered and virtualized environments exhibited increased variability and sensitivity to network imperfections. These findings underline that resilience in remote-access VPNs should be interpreted as a system-level property emerging from the interaction of implementation architecture, endpoint characteristics, and deployment conditions. Full article
Show Figures

Figure 1

20 pages, 1653 KB  
Article
Design and Greenhouse Sensing-Layer Validation of a Low-Cost Modular Agricultural Robot for Environmental Sensing, Telemetry and Remote Supervision in Precision Agriculture
by Bálint Ambrus, Gergely Teschner, Attila József Kovács, Miklós Neményi, Norbert Boros and Anikó Nyéki
Agronomy 2026, 16(12), 1139; https://doi.org/10.3390/agronomy16121139 - 10 Jun 2026
Viewed by 540
Abstract
Wireless sensor networks (WSNs), IoT-enabled sensing, and mobile platforms are increasingly used in precision agriculture, but fixed stations cannot fully capture within-field or canopy-level variability. This study developed and greenhouse-tested a low-cost modular tracked robot as a wireless environmental-sensing and telemetry research node [...] Read more.
Wireless sensor networks (WSNs), IoT-enabled sensing, and mobile platforms are increasingly used in precision agriculture, but fixed stations cannot fully capture within-field or canopy-level variability. This study developed and greenhouse-tested a low-cost modular tracked robot as a wireless environmental-sensing and telemetry research node for future crop-monitoring applications, rather than as a fully validated autonomous field robot. An open-source tracked chassis was extended with Raspberry Pi edge computing, a Cube Orange autopilot, RTK-capable GNSS, 5G/VPN/MAVLink communication, and BME280, BH1750, MLX90614, RGB camera, and LiDAR-ready sensing. The platform measured 35 × 25 × 40 cm, weighed 6.4 kg, operated from a 12 V supply, and provided about 4 h of runtime under favorable conditions. Sensor data were logged locally and could be transmitted remotely, while telemetry was visualized in QGroundControl. The environmental sensing layer was compared with a calibrated Libelium Smart Agriculture Pro station in a greenhouse using 70 synchronized samples per variable across three sessions. Because the two nodes were placed close to one another but were not strictly co-located, the comparison quantifies operational sensing differences under greenhouse microclimatic gradients rather than pure laboratory sensor error. Regression was retained only as a trend-tracking metric, while method-comparison interpretation was added using bias and Bland–Altman limits of agreement. The pressure channel showed strong trend tracking (R2 = 0.992, RMSE = 0.024 hPa), whereas air temperature (R2 = 0.756, RMSE = 2.537 °C) and relative humidity (R2 = 0.817, RMSE = 5.024%) were suitable mainly for exploratory microclimate mapping and relative trend monitoring unless local calibration is applied. The title, claims and conclusions were therefore narrowed to greenhouse sensing-layer validation and future crop-monitoring deployment. Full article
Show Figures

Figure 1

26 pages, 423 KB  
Article
Hardware-Anchored ES-SPA: A Dynamic Zero-Trust Architecture for Secure eSIM Provisioning in 6G IoT via Moving Target Defense
by Hari N. N., Kurunandan Jain, Prabu P and Prabhakar Krishnan
Future Internet 2026, 18(4), 187; https://doi.org/10.3390/fi18040187 - 1 Apr 2026
Cited by 2 | Viewed by 1426
Abstract
The rapid evolution of 6G networks and large-scale Internet of Things (IoT) deployments intensifies security and privacy challenges in embedded SIM (eSIM) Remote SIM Provisioning (RSP), particularly during the bootstrap and profile delivery phases. Traditional perimeter-based and VPN-centric approaches expose static attack surfaces, [...] Read more.
The rapid evolution of 6G networks and large-scale Internet of Things (IoT) deployments intensifies security and privacy challenges in embedded SIM (eSIM) Remote SIM Provisioning (RSP), particularly during the bootstrap and profile delivery phases. Traditional perimeter-based and VPN-centric approaches expose static attack surfaces, making provisioning workflows vulnerable to denial-of-service (DoS) attacks, reconnaissance, and profile lock-in risks. This paper presents MTD-SDP-eSIM, a hardware-anchored Zero Trust Architecture that secures eSIM provisioning by integrating the embedded Universal Integrated Circuit Card (eUICC) as a root of trust with Software-Defined Perimeter (SDP), Software-Defined Networking (SDN), and Moving Target Defense (MTD). The framework introduces Hardware-Anchored Single Packet Authorization (ES-SPA), which cryptographically binds initial access to tamper-resistant eUICC credentials and enforces an authenticate-before-connect model. A unified Zero Trust controller dynamically orchestrates SDP access control, SDN-based micro-segmentation, and MTD-driven Network Address Shuffling during high-risk provisioning phases. This framework is validated on a high-fidelity 6G testbed built using ns-3, Open5GS, and P4-programmable switches. Experimental results demonstrate a 90% DoS survival rate during provisioning, a 35% scalability improvement over VPN-based baselines, and a 75% reduction in profile lock-in failures through runtime deletion verification. These findings confirm that anchoring dynamic network defenses in hardware-rooted identity significantly enhances the resilience, scalability, and privacy of eSIM provisioning for massive 6G IoT deployments. Full article
Show Figures

Graphical abstract

52 pages, 3006 KB  
Article
Empirical Performance Analysis of WireGuard vs. OpenVPN in Cloud and Virtualised Environments Under Simulated Network Conditions
by Joel Anyam, Rajiv Ranjan Singh, Hadi Larijani and Anand Philip
Computers 2025, 14(8), 326; https://doi.org/10.3390/computers14080326 - 13 Aug 2025
Cited by 8 | Viewed by 17259
Abstract
With the rise in cloud computing and virtualisation, secure and efficient VPN solutions are essential for network connectivity. We present a systematic performance comparison of OpenVPN (v2.6.12) and WireGuard (v1.0.20210914) across Azure and VMware environments, evaluating throughput, latency, jitter, packet loss, and resource [...] Read more.
With the rise in cloud computing and virtualisation, secure and efficient VPN solutions are essential for network connectivity. We present a systematic performance comparison of OpenVPN (v2.6.12) and WireGuard (v1.0.20210914) across Azure and VMware environments, evaluating throughput, latency, jitter, packet loss, and resource utilisation. Testing revealed that the protocol performance is highly context dependent. In VMware environments, WireGuard demonstrated a superior TCP throughput (210.64 Mbps vs. 110.34 Mbps) and lower packet loss (12.35% vs. 47.01%). In Azure environments, both protocols achieved a similar baseline throughput (~280–290 Mbps), though OpenVPN performed better under high-latency conditions (120 Mbps vs. 60 Mbps). Resource utilisation showed minimal differences, with WireGuard maintaining slightly better memory efficiency. Security Efficiency Index calculations revealed environment-specific trade-offs: WireGuard showed marginal advantages in Azure, while OpenVPN demonstrated better throughput efficiency in VMware, though WireGuard remained superior for latency-sensitive applications. Our findings indicate protocol selection should be guided by deployment environment and application requirements rather than general superiority claims. Full article
(This article belongs to the Special Issue Cloud Computing and Big Data Mining)
Show Figures

Figure 1

42 pages, 16651 KB  
Article
Internet of Things-Cloud Control of a Robotic Cell Based on Inverse Kinematics, Hardware-in-the-Loop, Digital Twin, and Industry 4.0/5.0
by Dan Ionescu, Adrian Filipescu, Georgian Simion and Adriana Filipescu
Sensors 2025, 25(6), 1821; https://doi.org/10.3390/s25061821 - 14 Mar 2025
Cited by 9 | Viewed by 3361
Abstract
The main task of the research involves creating a Digital Twin (DT) application serving as a framework for Virtual Commissioning (VC) with Supervisory Control and Data Acquisition (SCADA) and Cloud storage solutions. An Internet of Things (IoT) integrated automation system with Virtual Private [...] Read more.
The main task of the research involves creating a Digital Twin (DT) application serving as a framework for Virtual Commissioning (VC) with Supervisory Control and Data Acquisition (SCADA) and Cloud storage solutions. An Internet of Things (IoT) integrated automation system with Virtual Private Network (VPN) remote control for assembly and disassembly robotic cell (A/DRC) equipped with a six-Degree of Freedom (6-DOF) ABB 120 industrial robotic manipulator (IRM) is presented in this paper. A three-dimensional (3D) virtual model is developed using Siemens NX Mechatronics Concept Designer (MCD), while the Programmable Logic Controller (PLC) is programmed in the Siemens Totally Integrated Automation (TIA) Portal. A Hardware-in-the-Loop (HIL) simulation strategy is primarily used. This concept is implemented and executed as part of a VC approach, where the designed PLC programs are integrated and tested against the physical controller. Closed loop control and RM inverse kinematics model are validated and tested in PLC, following HIL strategy by integrating Industry 4.0/5.0 concepts. A SCADA application is also deployed, serving as a DT operator panel for process monitoring and simulation. Cloud data collection, analysis, supervising, and synchronizing DT tasks are also integrated and explored. Additionally, it provides communication interfaces via PROFINET IO to SCADA and Human Machine Interface (HMI), and through Open Platform Communication—Unified Architecture (OPC-UA) for Siemens NX-MCD with DT virtual model. Virtual A/DRC simulations are performed using the Synchronized Timed Petri Nets (STPN) model for control strategy validation based on task planning integration and synchronization with other IoT devices. The objective is to obtain a clear and understandable representation layout of the A/DRC and to validate the DT model by comparing process dynamics and robot motion kinematics between physical and virtual replicas. Thus, following the results of the current research work, integrating digital technologies in manufacturing, like VC, IoT, and Cloud, is useful for validating and optimizing manufacturing processes, error detection, and reducing the risks before the actual physical system is built or deployed. Full article
Show Figures

Figure 1

37 pages, 10225 KB  
Article
Cloud/VPN-Based Remote Control of a Modular Production System Assisted by a Mobile Cyber–Physical Robotic System—Digital Twin Approach
by Georgian Simion, Adrian Filipescu, Dan Ionescu and Adriana Filipescu
Sensors 2025, 25(2), 591; https://doi.org/10.3390/s25020591 - 20 Jan 2025
Cited by 9 | Viewed by 3345
Abstract
This paper deals with a “digital twin” (DT) approach for processing, reprocessing, and scrapping (P/R/S) technology running on a modular production system (MPS) assisted by a mobile cyber–physical robotic system (MCPRS). The main hardware architecture consists of four line-shaped workstations (WSs), a wheeled [...] Read more.
This paper deals with a “digital twin” (DT) approach for processing, reprocessing, and scrapping (P/R/S) technology running on a modular production system (MPS) assisted by a mobile cyber–physical robotic system (MCPRS). The main hardware architecture consists of four line-shaped workstations (WSs), a wheeled mobile robot (WMR) equipped with a robotic manipulator (RM) and a mobile visual servoing system (MVSS) mounted on the end effector. The system architecture integrates a hierarchical control system where each of the four WSs, in the MPS, is controlled by a Programable Logic Controller (PLC), all connected via Profibus DP to a central PLC. In addition to the connection via Profibus of the four PLCs, related to the WSs, to the main PLC, there are also the connections of other devices to the local networks, LAN Profinet and LAN Ethernet. There are the connections to the Internet, Cloud and Virtual Private Network (VPN) via WAN Ethernet by open platform communication unified architecture (OPC-UA). The overall system follows a DT approach that enables task planning through augmented reality (AR) and uses virtual reality (VR) for visualization through Synchronized Hybrid Petri Net (SHPN) simulation. Timed Petri Nets (TPNs) are used to control the processes within the MPS’s workstations. Continuous Petri Nets (CPNs) handle the movement of the MCPRS. Task planning in AR enables users to interact with the system in real time using AR technology to visualize and plan tasks. SHPN in VR is a combination of TPNs and CPNs used in the virtual representation of the system to synchronize tasks between the MPS and MCPRS. The workpiece (WP) visits stations successively as it is moved along the line for processing. If the processed WP does not pass the quality test, it is taken from the last WS and is transported, by MCPRS, to the first WS where it will be considered for reprocessing or scrapping. Full article
Show Figures

Figure 1

31 pages, 17989 KB  
Article
IoT-Cloud, VPN, and Digital Twin-Based Remote Monitoring and Control of a Multifunctional Robotic Cell in the Context of AI, Industry, and Education 4.0 and 5.0
by Adrian Filipescu, Georgian Simion, Dan Ionescu and Adriana Filipescu
Sensors 2024, 24(23), 7451; https://doi.org/10.3390/s24237451 - 22 Nov 2024
Cited by 22 | Viewed by 4477
Abstract
The monitoring and control of an assembly/disassembly/replacement (A/D/R) multifunctional robotic cell (MRC) with the ABB 120 Industrial Robotic Manipulator (IRM), based on IoT (Internet of Things)-cloud, VPN (Virtual Private Network), and digital twin (DT) technology, are presented in this paper. The approach integrates [...] Read more.
The monitoring and control of an assembly/disassembly/replacement (A/D/R) multifunctional robotic cell (MRC) with the ABB 120 Industrial Robotic Manipulator (IRM), based on IoT (Internet of Things)-cloud, VPN (Virtual Private Network), and digital twin (DT) technology, are presented in this paper. The approach integrates modern principles of smart manufacturing as outlined in Industry/Education 4.0 (automation, data exchange, smart systems, machine learning, and predictive maintenance) and Industry/Education 5.0 (human–robot collaboration, customization, robustness, and sustainability). Artificial intelligence (AI), based on machine learning (ML), enhances system flexibility, productivity, and user-centered collaboration. Several IoT edge devices are engaged, connected to local networks, LAN-Profinet, and LAN-Ethernet and to the Internet via WAN-Ethernet and OPC-UA, for remote and local processing and data acquisition. The system is connected to the Internet via Wireless Area Network (WAN) and allows remote control via the cloud and VPN. IoT dashboards, as human–machine interfaces (HMIs), SCADA (Supervisory Control and Data Acquisition), and OPC-UA (Open Platform Communication-Unified Architecture), facilitate remote monitoring and control of the MRC, as well as the planning and management of A/D/R tasks. The assignment, planning, and execution of A/D/R tasks were carried out using an augmented reality (AR) tool. Synchronized timed Petri nets (STPN) were used as a digital twin akin to a virtual reality (VR) representation of A/D/R MRC operations. This integration of advanced technology into a laboratory mechatronic system, where the devices are organized in a decentralized, multilevel architecture, creates a smart, flexible, and scalable environment that caters to both industrial applications and educational frameworks. Full article
(This article belongs to the Special Issue Intelligent Robotics Sensing Control System)
Show Figures

Figure 1

22 pages, 8922 KB  
Article
A Novel Framework for Cross-Cluster Scaling in Cloud-Native 5G NextGen Core
by Oana-Mihaela Dumitru-Guzu, Vlădeanu Călin and Robert Kooij
Future Internet 2024, 16(9), 325; https://doi.org/10.3390/fi16090325 - 6 Sep 2024
Cited by 4 | Viewed by 2848
Abstract
Cloud-native technologies are widely considered the ideal candidates for the future of vertical application development due to their boost in flexibility, scalability, and especially cost efficiency. Since multi-site support is paramount for 5G, we employ a multi-cluster model that scales on demand, shifting [...] Read more.
Cloud-native technologies are widely considered the ideal candidates for the future of vertical application development due to their boost in flexibility, scalability, and especially cost efficiency. Since multi-site support is paramount for 5G, we employ a multi-cluster model that scales on demand, shifting the boundaries of both horizontal and vertical scaling for shared resources. Our approach is based on the liquid computing paradigm, which has the benefit of adapting to the changing environment. Despite being a decentralized deployment shared across data centers, the 5G mobile core can be managed as a single cluster entity running in a public cloud. We achieve this by following the cloud-native patterns for declarative configuration based on Kubernetes APIs and on-demand resource allocation. Moreover, in our setup, we analyze the offloading of both the Open5GS user and control plane functions under two different peering scenarios. A significant improvement in terms of latency and throughput is achieved for the in-band peering, considering the traffic between clusters is ensured by the Liqo control plane through a VPN tunnel. We also validate three end-to-end network slicing use cases, showcasing the full 5G core automation and leveraging the capabilities of Kubernetes multi-cluster deployments and inter-service monitoring through the applied service mesh solution. Full article
Show Figures

Figure 1

17 pages, 5318 KB  
Article
Orchestrating Isolated Network Slices in 5G Networks
by Ali Esmaeily and Katina Kralevska
Electronics 2024, 13(8), 1548; https://doi.org/10.3390/electronics13081548 - 18 Apr 2024
Cited by 14 | Viewed by 2913
Abstract
Sharing resources through network slicing in a physical infrastructure facilitates service delivery to various sectors and industries. Nevertheless, ensuring security of the slices remains a significant hurdle. In this paper, we investigate the utilization of State-of-the-Art (SoA) Virtual Private Network (VPN) solutions in [...] Read more.
Sharing resources through network slicing in a physical infrastructure facilitates service delivery to various sectors and industries. Nevertheless, ensuring security of the slices remains a significant hurdle. In this paper, we investigate the utilization of State-of-the-Art (SoA) Virtual Private Network (VPN) solutions in 5G networks to enhance security and performance when isolating slices. We deploy and orchestrate cloud-native network functions to create multiple scenarios that emulate real-life cellular networks. We evaluate the performance of the WireGuard, IPSec, and OpenVPN solutions while ensuring confidentiality and data protection within 5G network slices. The proposed architecture provides secure communication tunnels and performance isolation. Evaluation results demonstrate that WireGuard provides slice isolation in the control and data planes with higher throughput for enhanced Mobile Broadband (eMBB) and lower latency for Ultra-Reliable Low-Latency Communications (URLLC) slices compared to IPSec and OpenVPN. Our developments show the potential of implementing WireGuard isolation, as a promising solution, for providing secure and efficient network slicing, which fulfills the 5G key performance indicator values. Full article
Show Figures

Figure 1

25 pages, 2070 KB  
Article
Developing a Novel Hierarchical VPLS Architecture Using Q-in-Q Tunneling in Router and Switch Design
by Morteza Biabani, Nasser Yazdani and Hossein Fotouhi
Computers 2023, 12(9), 180; https://doi.org/10.3390/computers12090180 - 7 Sep 2023
Cited by 3 | Viewed by 3989
Abstract
Virtual Private LAN Services (VPLS) is an ethernet-based Virtual Private Network (VPN) service that provides multipoint-to-multipoint Layer 2 VPN service, where each site is geographically dispersed across a Wide Area Network (WAN). The adaptability and scalability of VPLS are limited despite the fact [...] Read more.
Virtual Private LAN Services (VPLS) is an ethernet-based Virtual Private Network (VPN) service that provides multipoint-to-multipoint Layer 2 VPN service, where each site is geographically dispersed across a Wide Area Network (WAN). The adaptability and scalability of VPLS are limited despite the fact that they provide a flexible solution for connecting geographically dispersed sites. Furthermore, the construction of tunnels connecting customer locations that are separated by great distances adds a substantial amount of latency to the user traffic transportation. To address these issues, a novel Hierarchical VPLS (H-VPLS) architecture has been developed using 802.1Q tunneling (also known as Q-in-Q) on high-speed and commodity routers to satisfy the additional requirements of new VPLS applications. The Vector Packet Processing (VPP) performs as the router’s data plane, and FRRouting (FRR), an open-source network routing software suite, acts as the router’s control plane. The router is designed to seamlessly forward VPLS packets using the Request For Comments (RFCs) 4762, 4446, 4447, 4448, and 4385 from The Internet Engineering Task Force (IETF) integrated with VPP. In addition, the Label Distribution Protocol (LDP) is used for Multi-Protocol Label Switching (MPLS) Pseudo-Wire (PW) signaling in FRR. The proposed mechanism has been implemented on a software-based router in the Linux environment and tested for its functionality, signaling, and control plane processes. The router is also implemented on commodity hardware for testing the functionality of VPLS in the real world. Finally, the analysis of the results verifies the efficiency of the proposed mechanism in terms of throughput, latency, and packet loss ratio. Full article
(This article belongs to the Special Issue Advances in High-Performance Switching and Routing)
Show Figures

Figure 1

33 pages, 1387 KB  
Article
A Machine-Learning-Based Cyberattack Detector for a Cloud-Based SDN Controller
by Alberto Mozo, Amit Karamchandani, Luis de la Cal, Sandra Gómez-Canaval, Antonio Pastor and Lluis Gifre
Appl. Sci. 2023, 13(8), 4914; https://doi.org/10.3390/app13084914 - 13 Apr 2023
Cited by 28 | Viewed by 5044
Abstract
The rapid evolution of network infrastructure through the softwarization of network elements has led to an exponential increase in the attack surface, thereby increasing the complexity of threat protection. In light of this pressing concern, European Telecommunications Standards Institute (ETSI) TeraFlowSDN (TFS), an [...] Read more.
The rapid evolution of network infrastructure through the softwarization of network elements has led to an exponential increase in the attack surface, thereby increasing the complexity of threat protection. In light of this pressing concern, European Telecommunications Standards Institute (ETSI) TeraFlowSDN (TFS), an open-source microservice-based cloud-native Software-Defined Networking (SDN) controller, integrates robust Machine-Learning components to safeguard its network and infrastructure against potential malicious actors. This work presents a comprehensive study of the integration of these Machine-Learning components in a distributed scenario to provide secure end-to-end protection against cyber threats occurring at the packet level of the telecom operator’s Virtual Private Network (VPN) services configured with that feature. To illustrate the effectiveness of this integration, a real-world emerging attack vector (the cryptomining malware attack) is used as a demonstration. Furthermore, to address the pressing challenge of energy consumption in the telecom industry, we harness the full potential of state-of-the-art Green Artificial Intelligence techniques to optimize the size and complexity of Machine-Learning models in order to reduce their energy usage while maintaining their ability to accurately detect potential cyber threats. Additionally, to enhance the integrity and security of TeraFlowSDN’s cybersecurity components, Machine-Learning models are safeguarded from sophisticated adversarial attacks that attempt to deceive them by subtly perturbing input data. To accomplish this goal, Machine-Learning models are retrained with high-quality adversarial examples generated using a Generative Adversarial Network. Full article
(This article belongs to the Special Issue Machine Learning for Network Security)
Show Figures

Figure 1

14 pages, 3537 KB  
Article
Data and Service Security of GNSS Sensors Integrated with Cryptographic Module
by Changhui Xu, Jingkui Zhang, Zhiyou Zhang, Jianning Hou and Xujie Wen
Micromachines 2023, 14(2), 454; https://doi.org/10.3390/mi14020454 - 15 Feb 2023
Cited by 2 | Viewed by 2957
Abstract
Navigation and positioning are of increasing importance because they are becoming a new form of infrastructure. To ensure both development and security, this study designed a technical innovation structure to upgrade the GNSS (Global Navigation Satellite System) data transmission and real-time differential correction [...] Read more.
Navigation and positioning are of increasing importance because they are becoming a new form of infrastructure. To ensure both development and security, this study designed a technical innovation structure to upgrade the GNSS (Global Navigation Satellite System) data transmission and real-time differential correction service system and proposed a new multiple cryptographic fusion algorithm to achieve the encryption and decryption of GNSS data and services. First, a GNSS station encrypts GNSS data with an encryption key and obtains a public key from a GNSS data center to encrypt the GNSS data encryption key. After that, identity authentication of a GNSS station is carried out, and an SSL VPN is established between the GNSS station and a GNSS data center before GNSS data are transmitted to the GNSS data center. Then, the GNSS data center decrypts the received GNSS data. The process of an intelligent terminal for real-time differential corrections is similar to that of the GNSS station and the GNSS data center. A GNSS sensor integrated with a cryptographic module was developed to validate the structure in an open environment. The results showed that the developed GNSS sensor was successful in encrypting the data, and the GNSS data center was able to decrypt the data correctly. For the performance test, a cryptography server was able support the requirements of GNSS applications. However, a cryptography server was optimal in supporting 40~50 GNSS stations simultaneously, whereas a cluster was suggested to be configured if the number of GNSS stations was more than 60. In conclusion, the method was able to ensure the validity, confidentiality, integrity, and non-repudiation of GNSS data and services. The proposed upgrading technology was suitable for coordinating GNSS development and security. Full article
(This article belongs to the Section E:Engineering and Technology)
Show Figures

Figure 1

30 pages, 3059 KB  
Article
A Comprehensive Review of Tunnel Detection on Multilayer Protocols: From Traditional to Machine Learning Approaches
by Zhonghang Sui, Hui Shu, Fei Kang, Yuyao Huang and Guoyu Huo
Appl. Sci. 2023, 13(3), 1974; https://doi.org/10.3390/app13031974 - 3 Feb 2023
Cited by 11 | Viewed by 8059
Abstract
Tunnels, a key technology of traffic obfuscation, are increasingly being used to evade censorship. While providing convenience to users, tunnel technology poses a hidden danger to cybersecurity due to its concealment and camouflage capabilities. In contrast to previous studies of encrypted traffic detection, [...] Read more.
Tunnels, a key technology of traffic obfuscation, are increasingly being used to evade censorship. While providing convenience to users, tunnel technology poses a hidden danger to cybersecurity due to its concealment and camouflage capabilities. In contrast to previous studies of encrypted traffic detection, we perform the first measurement study of tunnel traffic and its unique characteristics and focus on the challenges and solutions in detecting tunnel traffic among traditional and machine learning techniques. This study covers an almost twenty-year research period from 2003 to 2022. First, we present the concepts of two types of tunnels, broad and narrow tunnels, respectively, as well as a framework for major tunnel applications, such as Tor (the second-generation onion router), proxy, VPN, and their relationships. Second, we analyze state-of-the-art methods from traditional to machine learning applications to systematize tunnel traffic detection, including HTTP, HTTPS, DNS, SSH, TCP, ICMP and IPSec. A quantitative evaluation is presented with five crucial indicators applied to the detection methods and reviews. We further discuss the research work based on datasets, feature engineering, and challenges that have are solved, partly solved and unsolved. Finally, by providing open questions and the potential directions, we hope to inspire future work in this area. Full article
Show Figures

Figure 1

16 pages, 1429 KB  
Article
A Deep Learning-Based Encrypted VPN Traffic Classification Method Using Packet Block Image
by Weishi Sun, Yaning Zhang, Jie Li, Chenxing Sun and Shuzhuang Zhang
Electronics 2023, 12(1), 115; https://doi.org/10.3390/electronics12010115 - 27 Dec 2022
Cited by 16 | Viewed by 10205
Abstract
Network traffic classification has great significance for network security, network management and other fields. However, in recent years, the use of VPN and TLS encryption had presented network traffic classification with new challenges. Due to the great performances of deep learning in image [...] Read more.
Network traffic classification has great significance for network security, network management and other fields. However, in recent years, the use of VPN and TLS encryption had presented network traffic classification with new challenges. Due to the great performances of deep learning in image recognition, many solutions have focused on the deep learning-based method and achieved positive results. A traffic classification method based on deep learning is provided in this paper, where the concept of Packet Block is proposed, which is the aggregation of continuous packets in the same direction. The features of Packet Block are extracted from network traffic, and then transformed into images. Finally, convolutional neural networks are used to identify the application type of network traffic. The experiment is conducted using captured OpenVPN dataset and public ISCX-Tor dataset. The results shows that the accuracy is 97.20% in OpenVPN dataset and 93.31% in ISCX-Tor dataset, which is higher than the state-of-the-art methods. This suggests that our approach has the ability to meet the challenges of VPN and TLS encryption. Full article
(This article belongs to the Section Computer Science & Engineering)
Show Figures

Figure 1

27 pages, 6047 KB  
Article
A VPN Performances Analysis of Constrained Hardware Open Source Infrastructure Deploy in IoT Environment
by Antonio Francesco Gentile, Davide Macrì, Floriano De Rango, Mauro Tropea and Emilio Greco
Future Internet 2022, 14(9), 264; https://doi.org/10.3390/fi14090264 - 13 Sep 2022
Cited by 27 | Viewed by 9507
Abstract
Virtual private network (VPN) represents an HW/SW infrastructure that implements private and confidential communication channels that usually travel through the Internet. VPN is currently one of the most reliable technologies to achieve this goal, also because being a consolidated technology, it is possible [...] Read more.
Virtual private network (VPN) represents an HW/SW infrastructure that implements private and confidential communication channels that usually travel through the Internet. VPN is currently one of the most reliable technologies to achieve this goal, also because being a consolidated technology, it is possible to apply appropriate patches to remedy any security holes. In this paper we analyze the performances of open source firmware OpenWrt 21.x compared with a server-side operating system (Debian 11 x64) and Mikrotik 7.x, also virtualized, and different types of clients (Windows 10/11, iOS 15, Android 11, OpenWrt 21.x, Debian 11 x64 and Mikrotik 7.x), observing the performance of the network according to the current implementation of the various protocols and algorithms of VPN tunnel examined on what are the most recent HW and SW for deployment in outdoor locations with poor network connectivity. Specifically, operating systems provide different performance metric values for various combinations of configuration variables. The first pursued goal is to find the algorithms to guarantee a data transmission/encryption ratio as efficiently as possible. The second goal is to research the algorithms capable of guaranteeing the widest spectrum of compatibility with the current infrastructures that support VPN technology, to obtain a connection system secure for geographically scattered IoT networks spread over difficult-to-manage areas such as suburban or rural environments. The third goal is to be able to use open firmware on constrained routers that provide compatibility with different VPN protocols. Full article
(This article belongs to the Special Issue Security and Privacy in Blockchains and the IoT II)
Show Figures

Figure 1

Back to TopTop