Skip to content

Repository files navigation

Proxy Agent

Contents

Introduction

Proxy agent is an intermediate module between the CCIPS Controller and the CCIPS Agent. This module is in charge of managing the key request between the different endpoints that will form the ipsec tunnel.


It will receive a json packet from the CCIPS Controller, this packet information is based on the RFC 9061 model.We can think of this model as a template for building ipsec infrastructure.

With the parameters contained in this template, the proxy agent will construct an ETSI GS QKD 004 request that it will send to the hybridization module.

The hybridization module will reply with the key for that request and the proxy agent will end up inserting this key in the original template sent by the CCIPS Controller.

Finally, with the template filled in, it will communicate with the CCIPS Agent to install the relevant security associations.

Installation

Bare installation

In order to have the Proxy Agent working we only need to create a virtual environment and run the proxy_agent.py script. An example is attached:

python3 -m venv .venv
source .venv/bin/activate
pip install -r requirements.txt

To run the Proxy Agent we only need to run the "proxy_agent.py" script with the configuration file. An exaple is attached:

python src/proxy_agent.py config/proxy_agent.json

Another option is adding the path to the configuration file in the environmental variable CFGFILE. The proxy agent will use the value of this variable as a backup if it does not receive arguments.

Docker

While the proxy agent can be run directly, the tool that is usually used when deploying this component is Docker. Whether you use base docker or docker compose there are some things you may need to know:

  • The docker building process does not copy the configuration files into the docker, this means that both the main configuration and the public node information must be copied to the repository at running time, this can be archived using a bind mount. This way the same image can be used for machines with different configurations.
  • When running the image you must also provide the path to the config file (The one inside the container) through the environment variable CFGFILE.
  • The proxy agent requires the port in proxy_agent_address expose so it can receive instructions from controllers that do not belong to any docker network the proxy agent belongs.

Configuring the proxy agent

Main configuration

The parameters of the config file are:

{
"input_format" : "encoding_in_which_the_input_of_the_ccips_controller_will_come",
"proxy_agent_address" : {
"host" : "host_where_the_proxy_agent_will_run",
"port" : 3000# Port where the proxy will run
},
"log":{
"file": "logger_file",
"level": "logger_level"
},
"hybrid_module": {
"address": {
"host" : "host_where_the_hybrid_module_is_located",
"port" : 24030# Port where the hybridation module is located
},
"public_node_info_path" : "./path/to/public_node_info.json",
"qkd_required_if_used" : false// Whether the qkd source is required or optional when used.
},
"ccips_agent": {
"address": {
"host" : "host_where_the_ccips_agent_is_located",
"port" : 12938# Port where the ccips agent is located
},
"credentials" : {
"username": "username_to_access_to_ccips_agent_netconf_server",
"password": "password_for_ccips_agent_netconf_server"
}
}
}

Check the config/proxy_agent.json to see an example correctly formatted and configured.

Public node information

This files contain usefull information about the nodes in the QKD/Hybridization network:

Note: The keys in the dictionary are the prefix of the side of the ipsec tunnel the information belongs to.

{
"10.0.0.11/32": {
"node_id":"aaaaaaaa-aaaa-aaaa-aaaa-aaaaaaaaaaaa",
"proxy_agent_ip": "192.168.159.35",
"role": {
"192.168.123.200": "SERVER",
"192.168.123.300": "SERVER"
}
},
"10.0.0.20/32":{
"node_id": "bbbbbbbb-bbbb-bbbb-bbbb-bbbbbbbbbbbb",
"proxy_agent_ip": "192.168.159.21",
"role": {
"192.168.123.100": "CLIENT",
"192.168.123.300": "SERVER"
}
},
"192.168.123.300": {
"node_id": "cccccccc-cccc-cccc-cccc-cccccccccccc",
"proxy_agent_ip": "192.168.159.37",
"role": {
"192.168.123.100": "CLIENT",
"192.168.123.200": "CLIENT"
}
}
}

About

Proxy agent is an intermediate module between the CCIPS Controller and the CCIPS Agent. This module is in charge of managing the key request between the different endpoints that will form the ipsec tunnel.

Resources

Stars

1 star

Watchers

3 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
GitHub - QUBIP/proxyagent: Proxy agent is an intermediate module between the CCIPS Controller and the CCIPS Agent. This module is in charge of managing the key request between the different endpoints that will form the ipsec tunnel. · GitHub
Skip to content

Repository files navigation

Proxy Agent

Contents

Introduction

Proxy agent is an intermediate module between the CCIPS Controller and the CCIPS Agent. This module is in charge of managing the key request between the different endpoints that will form the ipsec tunnel.


It will receive a json packet from the CCIPS Controller, this packet information is based on the RFC 9061 model.We can think of this model as a template for building ipsec infrastructure.

With the parameters contained in this template, the proxy agent will construct an ETSI GS QKD 004 request that it will send to the hybridization module.

The hybridization module will reply with the key for that request and the proxy agent will end up inserting this key in the original template sent by the CCIPS Controller.

Finally, with the template filled in, it will communicate with the CCIPS Agent to install the relevant security associations.

Installation

Bare installation

In order to have the Proxy Agent working we only need to create a virtual environment and run the proxy_agent.py script. An example is attached:

python3 -m venv .venv
source .venv/bin/activate
pip install -r requirements.txt

To run the Proxy Agent we only need to run the "proxy_agent.py" script with the configuration file. An exaple is attached:

python src/proxy_agent.py config/proxy_agent.json

Another option is adding the path to the configuration file in the environmental variable CFGFILE. The proxy agent will use the value of this variable as a backup if it does not receive arguments.

Docker

While the proxy agent can be run directly, the tool that is usually used when deploying this component is Docker. Whether you use base docker or docker compose there are some things you may need to know:

  • The docker building process does not copy the configuration files into the docker, this means that both the main configuration and the public node information must be copied to the repository at running time, this can be archived using a bind mount. This way the same image can be used for machines with different configurations.
  • When running the image you must also provide the path to the config file (The one inside the container) through the environment variable CFGFILE.
  • The proxy agent requires the port in proxy_agent_address expose so it can receive instructions from controllers that do not belong to any docker network the proxy agent belongs.

Configuring the proxy agent

Main configuration

The parameters of the config file are:

{
"input_format" : "encoding_in_which_the_input_of_the_ccips_controller_will_come",
"proxy_agent_address" : {
"host" : "host_where_the_proxy_agent_will_run",
"port" : 3000# Port where the proxy will run
},
"log":{
"file": "logger_file",
"level": "logger_level"
},
"hybrid_module": {
"address": {
"host" : "host_where_the_hybrid_module_is_located",
"port" : 24030# Port where the hybridation module is located
},
"public_node_info_path" : "./path/to/public_node_info.json",
"qkd_required_if_used" : false// Whether the qkd source is required or optional when used.
},
"ccips_agent": {
"address": {
"host" : "host_where_the_ccips_agent_is_located",
"port" : 12938# Port where the ccips agent is located
},
"credentials" : {
"username": "username_to_access_to_ccips_agent_netconf_server",
"password": "password_for_ccips_agent_netconf_server"
}
}
}

Check the config/proxy_agent.json to see an example correctly formatted and configured.

Public node information

This files contain usefull information about the nodes in the QKD/Hybridization network:

Note: The keys in the dictionary are the prefix of the side of the ipsec tunnel the information belongs to.

{
"10.0.0.11/32": {
"node_id":"aaaaaaaa-aaaa-aaaa-aaaa-aaaaaaaaaaaa",
"proxy_agent_ip": "192.168.159.35",
"role": {
"192.168.123.200": "SERVER",
"192.168.123.300": "SERVER"
}
},
"10.0.0.20/32":{
"node_id": "bbbbbbbb-bbbb-bbbb-bbbb-bbbbbbbbbbbb",
"proxy_agent_ip": "192.168.159.21",
"role": {
"192.168.123.100": "CLIENT",
"192.168.123.300": "SERVER"
}
},
"192.168.123.300": {
"node_id": "cccccccc-cccc-cccc-cccc-cccccccccccc",
"proxy_agent_ip": "192.168.159.37",
"role": {
"192.168.123.100": "CLIENT",
"192.168.123.200": "CLIENT"
}
}
}

About

Proxy agent is an intermediate module between the CCIPS Controller and the CCIPS Agent. This module is in charge of managing the key request between the different endpoints that will form the ipsec tunnel.

Resources

Stars

1 star

Watchers

3 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - QUBIP/proxyagent: Proxy agent is an intermediate module between the CCIPS Controller and the CCIPS Agent. This module is in charge of managing the key request between the different endpoints that will form the ipsec tunnel. · GitHub
Skip to content

Repository files navigation

Proxy Agent

Contents

Introduction

Proxy agent is an intermediate module between the CCIPS Controller and the CCIPS Agent. This module is in charge of managing the key request between the different endpoints that will form the ipsec tunnel.


It will receive a json packet from the CCIPS Controller, this packet information is based on the RFC 9061 model.We can think of this model as a template for building ipsec infrastructure.

With the parameters contained in this template, the proxy agent will construct an ETSI GS QKD 004 request that it will send to the hybridization module.

The hybridization module will reply with the key for that request and the proxy agent will end up inserting this key in the original template sent by the CCIPS Controller.

Finally, with the template filled in, it will communicate with the CCIPS Agent to install the relevant security associations.

Installation

Bare installation

In order to have the Proxy Agent working we only need to create a virtual environment and run the proxy_agent.py script. An example is attached:

python3 -m venv .venv
source .venv/bin/activate
pip install -r requirements.txt

To run the Proxy Agent we only need to run the "proxy_agent.py" script with the configuration file. An exaple is attached:

python src/proxy_agent.py config/proxy_agent.json

Another option is adding the path to the configuration file in the environmental variable CFGFILE. The proxy agent will use the value of this variable as a backup if it does not receive arguments.

Docker

While the proxy agent can be run directly, the tool that is usually used when deploying this component is Docker. Whether you use base docker or docker compose there are some things you may need to know:

  • The docker building process does not copy the configuration files into the docker, this means that both the main configuration and the public node information must be copied to the repository at running time, this can be archived using a bind mount. This way the same image can be used for machines with different configurations.
  • When running the image you must also provide the path to the config file (The one inside the container) through the environment variable CFGFILE.
  • The proxy agent requires the port in proxy_agent_address expose so it can receive instructions from controllers that do not belong to any docker network the proxy agent belongs.

Configuring the proxy agent

Main configuration

The parameters of the config file are:

{
"input_format" : "encoding_in_which_the_input_of_the_ccips_controller_will_come",
"proxy_agent_address" : {
"host" : "host_where_the_proxy_agent_will_run",
"port" : 3000# Port where the proxy will run
},
"log":{
"file": "logger_file",
"level": "logger_level"
},
"hybrid_module": {
"address": {
"host" : "host_where_the_hybrid_module_is_located",
"port" : 24030# Port where the hybridation module is located
},
"public_node_info_path" : "./path/to/public_node_info.json",
"qkd_required_if_used" : false// Whether the qkd source is required or optional when used.
},
"ccips_agent": {
"address": {
"host" : "host_where_the_ccips_agent_is_located",
"port" : 12938# Port where the ccips agent is located
},
"credentials" : {
"username": "username_to_access_to_ccips_agent_netconf_server",
"password": "password_for_ccips_agent_netconf_server"
}
}
}

Check the config/proxy_agent.json to see an example correctly formatted and configured.

Public node information

This files contain usefull information about the nodes in the QKD/Hybridization network:

Note: The keys in the dictionary are the prefix of the side of the ipsec tunnel the information belongs to.

{
"10.0.0.11/32": {
"node_id":"aaaaaaaa-aaaa-aaaa-aaaa-aaaaaaaaaaaa",
"proxy_agent_ip": "192.168.159.35",
"role": {
"192.168.123.200": "SERVER",
"192.168.123.300": "SERVER"
}
},
"10.0.0.20/32":{
"node_id": "bbbbbbbb-bbbb-bbbb-bbbb-bbbbbbbbbbbb",
"proxy_agent_ip": "192.168.159.21",
"role": {
"192.168.123.100": "CLIENT",
"192.168.123.300": "SERVER"
}
},
"192.168.123.300": {
"node_id": "cccccccc-cccc-cccc-cccc-cccccccccccc",
"proxy_agent_ip": "192.168.159.37",
"role": {
"192.168.123.100": "CLIENT",
"192.168.123.200": "CLIENT"
}
}
}

About

Proxy agent is an intermediate module between the CCIPS Controller and the CCIPS Agent. This module is in charge of managing the key request between the different endpoints that will form the ipsec tunnel.

Resources

Stars

1 star

Watchers

3 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - QUBIP/proxyagent: Proxy agent is an intermediate module between the CCIPS Controller and the CCIPS Agent. This module is in charge of managing the key request between the different endpoints that will form the ipsec tunnel. · GitHub
Skip to content

Repository files navigation

Proxy Agent

Contents

Introduction

Proxy agent is an intermediate module between the CCIPS Controller and the CCIPS Agent. This module is in charge of managing the key request between the different endpoints that will form the ipsec tunnel.


It will receive a json packet from the CCIPS Controller, this packet information is based on the RFC 9061 model.We can think of this model as a template for building ipsec infrastructure.

With the parameters contained in this template, the proxy agent will construct an ETSI GS QKD 004 request that it will send to the hybridization module.

The hybridization module will reply with the key for that request and the proxy agent will end up inserting this key in the original template sent by the CCIPS Controller.

Finally, with the template filled in, it will communicate with the CCIPS Agent to install the relevant security associations.

Installation

Bare installation

In order to have the Proxy Agent working we only need to create a virtual environment and run the proxy_agent.py script. An example is attached:

python3 -m venv .venv
source .venv/bin/activate
pip install -r requirements.txt

To run the Proxy Agent we only need to run the "proxy_agent.py" script with the configuration file. An exaple is attached:

python src/proxy_agent.py config/proxy_agent.json

Another option is adding the path to the configuration file in the environmental variable CFGFILE. The proxy agent will use the value of this variable as a backup if it does not receive arguments.

Docker

While the proxy agent can be run directly, the tool that is usually used when deploying this component is Docker. Whether you use base docker or docker compose there are some things you may need to know:

  • The docker building process does not copy the configuration files into the docker, this means that both the main configuration and the public node information must be copied to the repository at running time, this can be archived using a bind mount. This way the same image can be used for machines with different configurations.
  • When running the image you must also provide the path to the config file (The one inside the container) through the environment variable CFGFILE.
  • The proxy agent requires the port in proxy_agent_address expose so it can receive instructions from controllers that do not belong to any docker network the proxy agent belongs.

Configuring the proxy agent

Main configuration

The parameters of the config file are:

{
"input_format" : "encoding_in_which_the_input_of_the_ccips_controller_will_come",
"proxy_agent_address" : {
"host" : "host_where_the_proxy_agent_will_run",
"port" : 3000# Port where the proxy will run
},
"log":{
"file": "logger_file",
"level": "logger_level"
},
"hybrid_module": {
"address": {
"host" : "host_where_the_hybrid_module_is_located",
"port" : 24030# Port where the hybridation module is located
},
"public_node_info_path" : "./path/to/public_node_info.json",
"qkd_required_if_used" : false// Whether the qkd source is required or optional when used.
},
"ccips_agent": {
"address": {
"host" : "host_where_the_ccips_agent_is_located",
"port" : 12938# Port where the ccips agent is located
},
"credentials" : {
"username": "username_to_access_to_ccips_agent_netconf_server",
"password": "password_for_ccips_agent_netconf_server"
}
}
}

Check the config/proxy_agent.json to see an example correctly formatted and configured.

Public node information

This files contain usefull information about the nodes in the QKD/Hybridization network:

Note: The keys in the dictionary are the prefix of the side of the ipsec tunnel the information belongs to.

{
"10.0.0.11/32": {
"node_id":"aaaaaaaa-aaaa-aaaa-aaaa-aaaaaaaaaaaa",
"proxy_agent_ip": "192.168.159.35",
"role": {
"192.168.123.200": "SERVER",
"192.168.123.300": "SERVER"
}
},
"10.0.0.20/32":{
"node_id": "bbbbbbbb-bbbb-bbbb-bbbb-bbbbbbbbbbbb",
"proxy_agent_ip": "192.168.159.21",
"role": {
"192.168.123.100": "CLIENT",
"192.168.123.300": "SERVER"
}
},
"192.168.123.300": {
"node_id": "cccccccc-cccc-cccc-cccc-cccccccccccc",
"proxy_agent_ip": "192.168.159.37",
"role": {
"192.168.123.100": "CLIENT",
"192.168.123.200": "CLIENT"
}
}
}

About

Proxy agent is an intermediate module between the CCIPS Controller and the CCIPS Agent. This module is in charge of managing the key request between the different endpoints that will form the ipsec tunnel.

Resources

Stars

1 star

Watchers

3 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' GitHub - QUBIP/proxyagent: Proxy agent is an intermediate module between the CCIPS Controller and the CCIPS Agent. This module is in charge of managing the key request between the different endpoints that will form the ipsec tunnel. · GitHub
Skip to content

Repository files navigation

Proxy Agent

Contents

Introduction

Proxy agent is an intermediate module between the CCIPS Controller and the CCIPS Agent. This module is in charge of managing the key request between the different endpoints that will form the ipsec tunnel.


It will receive a json packet from the CCIPS Controller, this packet information is based on the RFC 9061 model.We can think of this model as a template for building ipsec infrastructure.

With the parameters contained in this template, the proxy agent will construct an ETSI GS QKD 004 request that it will send to the hybridization module.

The hybridization module will reply with the key for that request and the proxy agent will end up inserting this key in the original template sent by the CCIPS Controller.

Finally, with the template filled in, it will communicate with the CCIPS Agent to install the relevant security associations.

Installation

Bare installation

In order to have the Proxy Agent working we only need to create a virtual environment and run the proxy_agent.py script. An example is attached:

python3 -m venv .venv
source .venv/bin/activate
pip install -r requirements.txt

To run the Proxy Agent we only need to run the "proxy_agent.py" script with the configuration file. An exaple is attached:

python src/proxy_agent.py config/proxy_agent.json

Another option is adding the path to the configuration file in the environmental variable CFGFILE. The proxy agent will use the value of this variable as a backup if it does not receive arguments.

Docker

While the proxy agent can be run directly, the tool that is usually used when deploying this component is Docker. Whether you use base docker or docker compose there are some things you may need to know:

  • The docker building process does not copy the configuration files into the docker, this means that both the main configuration and the public node information must be copied to the repository at running time, this can be archived using a bind mount. This way the same image can be used for machines with different configurations.
  • When running the image you must also provide the path to the config file (The one inside the container) through the environment variable CFGFILE.
  • The proxy agent requires the port in proxy_agent_address expose so it can receive instructions from controllers that do not belong to any docker network the proxy agent belongs.

Configuring the proxy agent

Main configuration

The parameters of the config file are:

{
"input_format" : "encoding_in_which_the_input_of_the_ccips_controller_will_come",
"proxy_agent_address" : {
"host" : "host_where_the_proxy_agent_will_run",
"port" : 3000# Port where the proxy will run
},
"log":{
"file": "logger_file",
"level": "logger_level"
},
"hybrid_module": {
"address": {
"host" : "host_where_the_hybrid_module_is_located",
"port" : 24030# Port where the hybridation module is located
},
"public_node_info_path" : "./path/to/public_node_info.json",
"qkd_required_if_used" : false// Whether the qkd source is required or optional when used.
},
"ccips_agent": {
"address": {
"host" : "host_where_the_ccips_agent_is_located",
"port" : 12938# Port where the ccips agent is located
},
"credentials" : {
"username": "username_to_access_to_ccips_agent_netconf_server",
"password": "password_for_ccips_agent_netconf_server"
}
}
}

Check the config/proxy_agent.json to see an example correctly formatted and configured.

Public node information

This files contain usefull information about the nodes in the QKD/Hybridization network:

Note: The keys in the dictionary are the prefix of the side of the ipsec tunnel the information belongs to.

{
"10.0.0.11/32": {
"node_id":"aaaaaaaa-aaaa-aaaa-aaaa-aaaaaaaaaaaa",
"proxy_agent_ip": "192.168.159.35",
"role": {
"192.168.123.200": "SERVER",
"192.168.123.300": "SERVER"
}
},
"10.0.0.20/32":{
"node_id": "bbbbbbbb-bbbb-bbbb-bbbb-bbbbbbbbbbbb",
"proxy_agent_ip": "192.168.159.21",
"role": {
"192.168.123.100": "CLIENT",
"192.168.123.300": "SERVER"
}
},
"192.168.123.300": {
"node_id": "cccccccc-cccc-cccc-cccc-cccccccccccc",
"proxy_agent_ip": "192.168.159.37",
"role": {
"192.168.123.100": "CLIENT",
"192.168.123.200": "CLIENT"
}
}
}

About

Proxy agent is an intermediate module between the CCIPS Controller and the CCIPS Agent. This module is in charge of managing the key request between the different endpoints that will form the ipsec tunnel.

Resources

Stars

1 star

Watchers

3 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - QUBIP/proxyagent: Proxy agent is an intermediate module between the CCIPS Controller and the CCIPS Agent. This module is in charge of managing the key request between the different endpoints that will form the ipsec tunnel. · GitHub
Skip to content

Repository files navigation

Proxy Agent

Contents

Introduction

Proxy agent is an intermediate module between the CCIPS Controller and the CCIPS Agent. This module is in charge of managing the key request between the different endpoints that will form the ipsec tunnel.


It will receive a json packet from the CCIPS Controller, this packet information is based on the RFC 9061 model.We can think of this model as a template for building ipsec infrastructure.

With the parameters contained in this template, the proxy agent will construct an ETSI GS QKD 004 request that it will send to the hybridization module.

The hybridization module will reply with the key for that request and the proxy agent will end up inserting this key in the original template sent by the CCIPS Controller.

Finally, with the template filled in, it will communicate with the CCIPS Agent to install the relevant security associations.

Installation

Bare installation

In order to have the Proxy Agent working we only need to create a virtual environment and run the proxy_agent.py script. An example is attached:

python3 -m venv .venv
source .venv/bin/activate
pip install -r requirements.txt

To run the Proxy Agent we only need to run the "proxy_agent.py" script with the configuration file. An exaple is attached:

python src/proxy_agent.py config/proxy_agent.json

Another option is adding the path to the configuration file in the environmental variable CFGFILE. The proxy agent will use the value of this variable as a backup if it does not receive arguments.

Docker

While the proxy agent can be run directly, the tool that is usually used when deploying this component is Docker. Whether you use base docker or docker compose there are some things you may need to know:

  • The docker building process does not copy the configuration files into the docker, this means that both the main configuration and the public node information must be copied to the repository at running time, this can be archived using a bind mount. This way the same image can be used for machines with different configurations.
  • When running the image you must also provide the path to the config file (The one inside the container) through the environment variable CFGFILE.
  • The proxy agent requires the port in proxy_agent_address expose so it can receive instructions from controllers that do not belong to any docker network the proxy agent belongs.

Configuring the proxy agent

Main configuration

The parameters of the config file are:

{
"input_format" : "encoding_in_which_the_input_of_the_ccips_controller_will_come",
"proxy_agent_address" : {
"host" : "host_where_the_proxy_agent_will_run",
"port" : 3000# Port where the proxy will run
},
"log":{
"file": "logger_file",
"level": "logger_level"
},
"hybrid_module": {
"address": {
"host" : "host_where_the_hybrid_module_is_located",
"port" : 24030# Port where the hybridation module is located
},
"public_node_info_path" : "./path/to/public_node_info.json",
"qkd_required_if_used" : false// Whether the qkd source is required or optional when used.
},
"ccips_agent": {
"address": {
"host" : "host_where_the_ccips_agent_is_located",
"port" : 12938# Port where the ccips agent is located
},
"credentials" : {
"username": "username_to_access_to_ccips_agent_netconf_server",
"password": "password_for_ccips_agent_netconf_server"
}
}
}

Check the config/proxy_agent.json to see an example correctly formatted and configured.

Public node information

This files contain usefull information about the nodes in the QKD/Hybridization network:

Note: The keys in the dictionary are the prefix of the side of the ipsec tunnel the information belongs to.

{
"10.0.0.11/32": {
"node_id":"aaaaaaaa-aaaa-aaaa-aaaa-aaaaaaaaaaaa",
"proxy_agent_ip": "192.168.159.35",
"role": {
"192.168.123.200": "SERVER",
"192.168.123.300": "SERVER"
}
},
"10.0.0.20/32":{
"node_id": "bbbbbbbb-bbbb-bbbb-bbbb-bbbbbbbbbbbb",
"proxy_agent_ip": "192.168.159.21",
"role": {
"192.168.123.100": "CLIENT",
"192.168.123.300": "SERVER"
}
},
"192.168.123.300": {
"node_id": "cccccccc-cccc-cccc-cccc-cccccccccccc",
"proxy_agent_ip": "192.168.159.37",
"role": {
"192.168.123.100": "CLIENT",
"192.168.123.200": "CLIENT"
}
}
}

About

Proxy agent is an intermediate module between the CCIPS Controller and the CCIPS Agent. This module is in charge of managing the key request between the different endpoints that will form the ipsec tunnel.

Resources

Stars

1 star

Watchers

3 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - QUBIP/proxyagent: Proxy agent is an intermediate module between the CCIPS Controller and the CCIPS Agent. This module is in charge of managing the key request between the different endpoints that will form the ipsec tunnel. · GitHub
Skip to content

Repository files navigation

Proxy Agent

Contents

Introduction

Proxy agent is an intermediate module between the CCIPS Controller and the CCIPS Agent. This module is in charge of managing the key request between the different endpoints that will form the ipsec tunnel.


It will receive a json packet from the CCIPS Controller, this packet information is based on the RFC 9061 model.We can think of this model as a template for building ipsec infrastructure.

With the parameters contained in this template, the proxy agent will construct an ETSI GS QKD 004 request that it will send to the hybridization module.

The hybridization module will reply with the key for that request and the proxy agent will end up inserting this key in the original template sent by the CCIPS Controller.

Finally, with the template filled in, it will communicate with the CCIPS Agent to install the relevant security associations.

Installation

Bare installation

In order to have the Proxy Agent working we only need to create a virtual environment and run the proxy_agent.py script. An example is attached:

python3 -m venv .venv
source .venv/bin/activate
pip install -r requirements.txt

To run the Proxy Agent we only need to run the "proxy_agent.py" script with the configuration file. An exaple is attached:

python src/proxy_agent.py config/proxy_agent.json

Another option is adding the path to the configuration file in the environmental variable CFGFILE. The proxy agent will use the value of this variable as a backup if it does not receive arguments.

Docker

While the proxy agent can be run directly, the tool that is usually used when deploying this component is Docker. Whether you use base docker or docker compose there are some things you may need to know:

  • The docker building process does not copy the configuration files into the docker, this means that both the main configuration and the public node information must be copied to the repository at running time, this can be archived using a bind mount. This way the same image can be used for machines with different configurations.
  • When running the image you must also provide the path to the config file (The one inside the container) through the environment variable CFGFILE.
  • The proxy agent requires the port in proxy_agent_address expose so it can receive instructions from controllers that do not belong to any docker network the proxy agent belongs.

Configuring the proxy agent

Main configuration

The parameters of the config file are:

{
"input_format" : "encoding_in_which_the_input_of_the_ccips_controller_will_come",
"proxy_agent_address" : {
"host" : "host_where_the_proxy_agent_will_run",
"port" : 3000# Port where the proxy will run
},
"log":{
"file": "logger_file",
"level": "logger_level"
},
"hybrid_module": {
"address": {
"host" : "host_where_the_hybrid_module_is_located",
"port" : 24030# Port where the hybridation module is located
},
"public_node_info_path" : "./path/to/public_node_info.json",
"qkd_required_if_used" : false// Whether the qkd source is required or optional when used.
},
"ccips_agent": {
"address": {
"host" : "host_where_the_ccips_agent_is_located",
"port" : 12938# Port where the ccips agent is located
},
"credentials" : {
"username": "username_to_access_to_ccips_agent_netconf_server",
"password": "password_for_ccips_agent_netconf_server"
}
}
}

Check the config/proxy_agent.json to see an example correctly formatted and configured.

Public node information

This files contain usefull information about the nodes in the QKD/Hybridization network:

Note: The keys in the dictionary are the prefix of the side of the ipsec tunnel the information belongs to.

{
"10.0.0.11/32": {
"node_id":"aaaaaaaa-aaaa-aaaa-aaaa-aaaaaaaaaaaa",
"proxy_agent_ip": "192.168.159.35",
"role": {
"192.168.123.200": "SERVER",
"192.168.123.300": "SERVER"
}
},
"10.0.0.20/32":{
"node_id": "bbbbbbbb-bbbb-bbbb-bbbb-bbbbbbbbbbbb",
"proxy_agent_ip": "192.168.159.21",
"role": {
"192.168.123.100": "CLIENT",
"192.168.123.300": "SERVER"
}
},
"192.168.123.300": {
"node_id": "cccccccc-cccc-cccc-cccc-cccccccccccc",
"proxy_agent_ip": "192.168.159.37",
"role": {
"192.168.123.100": "CLIENT",
"192.168.123.200": "CLIENT"
}
}
}

About

Proxy agent is an intermediate module between the CCIPS Controller and the CCIPS Agent. This module is in charge of managing the key request between the different endpoints that will form the ipsec tunnel.

Resources

Stars

1 star

Watchers

3 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); GitHub - QUBIP/proxyagent: Proxy agent is an intermediate module between the CCIPS Controller and the CCIPS Agent. This module is in charge of managing the key request between the different endpoints that will form the ipsec tunnel. · GitHub
Skip to content

Repository files navigation

Proxy Agent

Contents

Introduction

Proxy agent is an intermediate module between the CCIPS Controller and the CCIPS Agent. This module is in charge of managing the key request between the different endpoints that will form the ipsec tunnel.


It will receive a json packet from the CCIPS Controller, this packet information is based on the RFC 9061 model.We can think of this model as a template for building ipsec infrastructure.

With the parameters contained in this template, the proxy agent will construct an ETSI GS QKD 004 request that it will send to the hybridization module.

The hybridization module will reply with the key for that request and the proxy agent will end up inserting this key in the original template sent by the CCIPS Controller.

Finally, with the template filled in, it will communicate with the CCIPS Agent to install the relevant security associations.

Installation

Bare installation

In order to have the Proxy Agent working we only need to create a virtual environment and run the proxy_agent.py script. An example is attached:

python3 -m venv .venv
source .venv/bin/activate
pip install -r requirements.txt

To run the Proxy Agent we only need to run the "proxy_agent.py" script with the configuration file. An exaple is attached:

python src/proxy_agent.py config/proxy_agent.json

Another option is adding the path to the configuration file in the environmental variable CFGFILE. The proxy agent will use the value of this variable as a backup if it does not receive arguments.

Docker

While the proxy agent can be run directly, the tool that is usually used when deploying this component is Docker. Whether you use base docker or docker compose there are some things you may need to know:

  • The docker building process does not copy the configuration files into the docker, this means that both the main configuration and the public node information must be copied to the repository at running time, this can be archived using a bind mount. This way the same image can be used for machines with different configurations.
  • When running the image you must also provide the path to the config file (The one inside the container) through the environment variable CFGFILE.
  • The proxy agent requires the port in proxy_agent_address expose so it can receive instructions from controllers that do not belong to any docker network the proxy agent belongs.

Configuring the proxy agent

Main configuration

The parameters of the config file are:

{
"input_format" : "encoding_in_which_the_input_of_the_ccips_controller_will_come",
"proxy_agent_address" : {
"host" : "host_where_the_proxy_agent_will_run",
"port" : 3000# Port where the proxy will run
},
"log":{
"file": "logger_file",
"level": "logger_level"
},
"hybrid_module": {
"address": {
"host" : "host_where_the_hybrid_module_is_located",
"port" : 24030# Port where the hybridation module is located
},
"public_node_info_path" : "./path/to/public_node_info.json",
"qkd_required_if_used" : false// Whether the qkd source is required or optional when used.
},
"ccips_agent": {
"address": {
"host" : "host_where_the_ccips_agent_is_located",
"port" : 12938# Port where the ccips agent is located
},
"credentials" : {
"username": "username_to_access_to_ccips_agent_netconf_server",
"password": "password_for_ccips_agent_netconf_server"
}
}
}

Check the config/proxy_agent.json to see an example correctly formatted and configured.

Public node information

This files contain usefull information about the nodes in the QKD/Hybridization network:

Note: The keys in the dictionary are the prefix of the side of the ipsec tunnel the information belongs to.

{
"10.0.0.11/32": {
"node_id":"aaaaaaaa-aaaa-aaaa-aaaa-aaaaaaaaaaaa",
"proxy_agent_ip": "192.168.159.35",
"role": {
"192.168.123.200": "SERVER",
"192.168.123.300": "SERVER"
}
},
"10.0.0.20/32":{
"node_id": "bbbbbbbb-bbbb-bbbb-bbbb-bbbbbbbbbbbb",
"proxy_agent_ip": "192.168.159.21",
"role": {
"192.168.123.100": "CLIENT",
"192.168.123.300": "SERVER"
}
},
"192.168.123.300": {
"node_id": "cccccccc-cccc-cccc-cccc-cccccccccccc",
"proxy_agent_ip": "192.168.159.37",
"role": {
"192.168.123.100": "CLIENT",
"192.168.123.200": "CLIENT"
}
}
}

About

Proxy agent is an intermediate module between the CCIPS Controller and the CCIPS Agent. This module is in charge of managing the key request between the different endpoints that will form the ipsec tunnel.

Resources

Stars

1 star

Watchers

3 watching

Forks

Releases

Packages

Contributors

Languages