Sammanfattning

The increasing need for secure interconnection of geographically distributed industrial sites has set Virtual Private LAN Service (VPLS) as an effective solution for providing Layer 2 VPNs with low latency and simplicity. However, traditional VPLS implementations rely on trusting the provider’s network, creating risks of unauthorised access and data compromise. Integrating the Host Identity Protocol (HIP) into VPLS introduces a new security paradigm by decoupling endpoint identity from location and leveraging cryptographic host identifiers for authentication and secure communication. HIP enhances the security of VPLS by mitigating IP spoofing, supporting mobility, and enabling strong, identity-based trust without relying on IP addresses alone. In this project, we explore how HIP-enabled VPLS can improve the confidentiality, integrity, and resilience of Layer 2 VPNs, aligning with zero-trust principles by minimising dependency on provider trust. Specifically, while customer edge (CE) devices use encryption at the customer side to ensure end-to-end data confidentiality, provider edge (PE) routers establish a multi-party group key using a modified HIP Base Exchange protocol. This group key secures packet integrity and provides replay protection across the provider's network. To protect the key agreement process against dishonest participants, the protocol incorporates a robust two-round Burmester–Desmedt variant within the HIP handshake, enabling efficient detection and rejection of malicious nodes. The resulting architecture offers a scalable, zero-trust Layer 2 VPN solution that combines the operational simplicity of VPLS with provable security guarantees and enhanced protection against insider and outsider threats. This approach reduces reliance on the security of provider networks, increases customer data autonomy, and ensures compliance with data protection regulations by securing sensitive data before it enters the provider network.

Utforska vidare

Liknande uppsatser

Uppsatser med liknande ämnen och nyckelord.