Distributed controllers multi-granularity security communication mechanism for software-defined networking

被引:6
|
作者
Shang, Fengjun [1 ]
Li, Yan [1 ]
Fu, Qiang [1 ]
Wang, Wenkai [1 ]
Feng, Jiangfan [1 ]
He, Li [1 ]
机构
[1] Chongqing Univ Posts & Telecommun, Coll Comp Sci & Technol, Chongqing 400065, Peoples R China
基金
中国国家自然科学基金;
关键词
Software defined network; Security architecture; Secure communication; SDN;
D O I
10.1016/j.compeleceng.2017.07.003
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
For the multi-domain software defined network (SDN), different controllers are not able to directly communicate with each other due to the different distances among control planes. Therefore, the exchange of information among different domains is generally unsecure. The main contribution of this paper can be summarized into two parts. Firstly, architecture of multi-granularity security controller is proposed, which includes a basic control module and a multi-granularity security customized module. Secondly, a secure communication mechanism is proposed for distributed controller, where a prototype of this mechanism is implemented. In particular, this mechanism can make use of the border switch as inter domain agents, where special packets are used by the controller to send messages to the secure tunnel. A two-step authentication of the controller can be provided by inter-domain agents and digital certificates. The experimental results demonstrate that the distributed controller secure communication mechanism is capable of effectively improving the security of SDN domain. (C) 2017 Elsevier Ltd. All rights reserved.
引用
收藏
页码:388 / 406
页数:19
相关论文
共 50 条
  • [21] Examining the Quality Metrics of a Communication Network with Distributed Software-Defined Networking Architecture
    Mehmood, Khawaja Tahir
    Atiq, Shahid
    Sajjad, Intisar Ali
    Hussain, Muhammad Majid
    Basit, Malik M. Abdul
    CMES-COMPUTER MODELING IN ENGINEERING & SCIENCES, 2024, 141 (02): : 1673 - 1708
  • [22] Evaluating Software-defined Networking for Deterministic Communication in Distributed Industrial Automation Systems
    Schneider, Ben
    Zoitl, Alois
    Wenger, Monika
    Blech, Jan Olaf
    2017 22ND IEEE INTERNATIONAL CONFERENCE ON EMERGING TECHNOLOGIES AND FACTORY AUTOMATION (ETFA), 2017,
  • [23] A multi-RAT bandwidth aggregation mechanism with software-defined networking
    Yang, Shun-Neng
    Ho, Shu-Wei
    Lin, Yi-Bing
    Gan, Chai-Hien
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2016, 61 : 189 - 198
  • [24] A Security Assessment Mechanism for Software-Defined Networking-Based Mobile Networks
    Luo, Shibo
    Dong, Mianxiong
    Ota, Kaoru
    Wu, Jun
    Li, Jianhua
    SENSORS, 2015, 15 (12): : 31843 - 31858
  • [25] A Security Mechanism for Software-Defined Networking Based Communications in Vehicle-to-Grid
    Zhang, Shanghua
    Li, Qiang
    Wu, Jun
    Li, Jianhua
    Li, Gaolei
    2016 THE 4TH IEEE INTERNATIONAL CONFERENCE ON SMART ENERGY GRID ENGINEERING (SEGE), 2016, : 386 - 391
  • [26] SDSNM: A Software-Defined Security Networking Mechanism to Defend against DDoS Attacks
    Wang, Xiulei
    Chen, Ming
    Xing, Changyou
    2015 NINTH INTERNATIONAL CONFERENCE ON FRONTIER OF COMPUTER SCIENCE AND TECHNOLOGY FCST 2015, 2015, : 115 - 121
  • [27] An Entropy-Based Distributed DDoS Detection Mechanism in Software-Defined Networking
    Wang, Rui
    Jia, Zhiping
    Ju, Lei
    2015 IEEE TRUSTCOM/BIGDATASE/ISPA, VOL 1, 2015, : 310 - 317
  • [28] Comparative Study of Software-Defined Networking (SDN) Traffic Controllers
    Pereira, Goncalo
    Silva, Jose
    Sousa, Pedro
    2019 14TH IBERIAN CONFERENCE ON INFORMATION SYSTEMS AND TECHNOLOGIES (CISTI), 2019,
  • [29] Byzantine Fault Tolerant Software-Defined Networking (SDN) Controllers
    ElDefrawy, Karim
    Kaczmarek, Tyler
    PROCEEDINGS 2016 IEEE 40TH ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE WORKSHOPS (COMPSAC), VOL 2, 2016, : 208 - 213
  • [30] Performance of Software-Defined Networking Controllers for Different Network Topologies
    Alrashedy, Kamel
    Kimmett, Ben
    Gulliver, T. Aaron
    2017 IEEE PACIFIC RIM CONFERENCE ON COMMUNICATIONS, COMPUTERS AND SIGNAL PROCESSING (PACRIM), 2017,