A New VPN Solution Based on Asymmetrical SSL Tunnels
Jingli Zhou, Hongtao Xia, Xiaofeng Wang, Jifeng Yu · 2006
Conventional SSL tunnel of SSL-based virtual private network is symmetric, in which the data must be encrypted at one end and decrypted at the other end, or contrariwise for the reverse direction. Because all data flows of VPN are relayed by VPN server via SSL tunnels, those symmetric SSL tunnels cause a lot of computational load concentrated in VPN server, and make it the bottleneck of VPN. This paper proposes a cheap solution to eliminate that bottleneck for larger scale SSL VPNs: The VPN based on asymmetric SSL tunnels (AST). It is coupled with two algorithms: IP packet engrafting and UDP diffusing. In this solution, portion of computational load is distributed to disengaged internal application servers. Experiment shows that the overall throughput of VPN can be greatly improved by adopting AST solution