A survey on oblivious comparison of firewall policies in VPN
K. Sivanandham, Omanakuttan Sheela Nisha · IEEE-International Conference On Advances In Engineering, Science And Management · 2012
The widely using Virtual Private Network (VPN) technology allows roaming users to build an encrypted tunnel to a VPN server, which henceforth allows roaming users to access some resources as if that computer were residing on their Home network. Although VPN technology is very useful, it imposes security threats on the remote network because its firewall does not know what traffic is flowing inside the VPN Tunnel. To address this issue, we propose Advance Oblivious comparison and VGuard, a framework that allows a Client and Server to collaboratively determine whether the request satisfies the policy. An efficient protocol, called Xhash, for Advance Oblivious comparison, which allows two parties, where each party has a number, to compare whether they have the same number, Then, we present the VGuard framework that uses Xhash as the basic building block. The basic idea of Guard is to first convert a firewall policy to non-overlapping numerical rules and then uses Xhash to check whether a request matches a rule. After then datas were transfered from vpn server to home network.