WireGuard: Next Generation Kernel Network Tunnel
Jason A. Donenfeld
摘要
WireGuard is a secure network tunnel, operating at layer 3, implemented as a kernel virtual network interface for Linux, which aims to replace both IPsec for most use cases, as well as popular user space and/or TLS-based solutions like OpenVPN, while being more secure, more performant, and easier to use. The virtual tunnel interface is based on a proposed fundamental principle of secure tunnels: an association between a peer public key and a tunnel source IP address. It uses a single round trip key exchange, based on NoiseIK, and handles all session creation transparently to the user using a novel timer state machine mechanism. Short pre-shared static keys-Curve25519 points-are used for mutual authentication in the style of OpenSSH. The protocol provides strong perfect forward secrecy in addition to a high degree of identity hiding. Transport speed is accomplished using ChaCha20Poly1305 authenticated-encryption for encapsulation of packets in UDP. An improved take on IP-binding cookies is used for mitigating denial of service attacks, improving greatly on IKEv2 and DTLS's cookie mechanisms to add encryption and authentication. The overall design allows for allocating no resources in response to received packets, and from a systems perspective, there are multiple interesting Linux implementation techniques for queues and parallelism. Finally, WireGuard can be simply implemented for Linux in less than 4,000 lines of code, making it easily audited and verified.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper26
- Post-Quantum TLS Without Handshake SignaturesPeter Schwabe, Douglas Stebila, Thom WiggersCCS 2020 · 被引用 162 次
- LMAC: efficient carrier-sense multiple access for LoRaAmalinda Gamage, Jansen Christian Liando, Chaojie Gu, Rui Tan 等MobiCom 2020 · 被引用 123 次
- EverCrypt: A Fast, Verified, Cross-Platform Cryptographic ProviderJonathan Protzenko, Bryan Parno, Aymeric Fromherz, Chris Hawblitzel 等S&P 2020 · 被引用 114 次
- Post-quantum WireGuardAndreas Hülsing, Kai-Chun Ning, Peter Schwabe, Florian Weber 等S&P 2021 · 被引用 73 次
- AppSniffer: Towards Robust Mobile App Fingerprinting Against VPNSanghak Oh, Minwook Lee, Hyunwoo Lee, Elisa Bertino 等WWW 2023 · 被引用 26 次
相关 Paper
- A Unified Symbolic Analysis of WireGuardPascal Lafourcade, Dhekra Mahmoud, Sylvain RuhaultNDSS 2024
- Revisiting PQ Wireguard: A Comprehensive Security Analysis with a New Design Using Reinforced KEMsKeitaro Hashimoto, Shuichi Katsumata, Guilhem Niot, Thom WiggersS&P 2026
- A Tale of Two Worlds, a Formal Story of WireGuard HybridizationPascal Lafourcade, Dhekra Mahmoud, Sylvain Ruhault, Abdul Rahman TalebUSENIX Security 2025
- OwlC: Compiling Security Protocols to Verified, Secure, High-Performance LibrariesPratap Singh, Joshua Gancher, Bryan ParnoUSENIX Security 2025
- Sound Verification of Security Protocols: From Design to Interoperable ImplementationsLinard Arquint, Felix A. Wolf, Joseph Lallemand, Ralf Sasse 等S&P 2023
