Distributed controllers multi-granularity security communication mechanism for software-defined networking

被引:6
|
作者
Shang, Fengjun [1 ]
Li, Yan [1 ]
Fu, Qiang [1 ]
Wang, Wenkai [1 ]
Feng, Jiangfan [1 ]
He, Li [1 ]
机构
[1] Chongqing Univ Posts & Telecommun, Coll Comp Sci & Technol, Chongqing 400065, Peoples R China
基金
中国国家自然科学基金;
关键词
Software defined network; Security architecture; Secure communication; SDN;
D O I
10.1016/j.compeleceng.2017.07.003
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
For the multi-domain software defined network (SDN), different controllers are not able to directly communicate with each other due to the different distances among control planes. Therefore, the exchange of information among different domains is generally unsecure. The main contribution of this paper can be summarized into two parts. Firstly, architecture of multi-granularity security controller is proposed, which includes a basic control module and a multi-granularity security customized module. Secondly, a secure communication mechanism is proposed for distributed controller, where a prototype of this mechanism is implemented. In particular, this mechanism can make use of the border switch as inter domain agents, where special packets are used by the controller to send messages to the secure tunnel. A two-step authentication of the controller can be provided by inter-domain agents and digital certificates. The experimental results demonstrate that the distributed controller secure communication mechanism is capable of effectively improving the security of SDN domain. (C) 2017 Elsevier Ltd. All rights reserved.
引用
收藏
页码:388 / 406
页数:19
相关论文
共 50 条
  • [31] Leveraging software-defined networking for security policy enforcement
    Liu, Jiaqiang
    Li, Yong
    Wang, Huandong
    Jin, Depeng
    Su, Li
    Zeng, Lieguang
    Vasilakos, Thanos
    INFORMATION SCIENCES, 2016, 327 : 288 - 299
  • [32] Software-defined networking
    Greene, Kate
    Technology Review, 2009, 112 (02)
  • [33] Software-Defined Networking
    Kirkpatrick, Keith
    COMMUNICATIONS OF THE ACM, 2013, 56 (09) : 16 - 19
  • [34] A Survey: Typical Security Issues of Software-Defined Networking
    Liu, Yifan
    Zhao, Bo
    Zhao, Pengyuan
    Fan, Peiru
    Liu, Hui
    CHINA COMMUNICATIONS, 2019, 16 (07) : 13 - 31
  • [35] A Framework for Security Services based on Software-Defined Networking
    Jeong, Jaehoon
    Seo, Jihyeok
    Cho, Geumhwan
    Kim, Hyoungshick
    Park, Jung-Soo
    2015 IEEE 29TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS WORKSHOPS WAINA 2015, 2015, : 150 - 153
  • [36] A Survey: Typical Security Issues of Software-Defined Networking
    Yifan Liu
    Bo Zhao
    Pengyuan Zhao
    Peiru Fan
    Hui Liu
    中国通信, 2019, 16 (07) : 13 - 31
  • [37] Software-Defined Networking
    Zhili Sun
    Jiandong Li
    Kun Yang
    ZTE Communications, 2014, 12 (02) : 1 - 2
  • [38] Software-Defined Networking for Unmanned Aerial Vehicular Networking and Security: A Survey
    Mccoy, James
    Rawat, Danda B.
    ELECTRONICS, 2019, 8 (12)
  • [39] Software-Defined Wireless Networking: Centralized, Distributed, or Hybrid?
    Abolhasan, Mehran
    Lipman, Justin
    Ni, Wei
    Hagelstein, Brett
    IEEE NETWORK, 2015, 29 (04): : 32 - 38
  • [40] Multi-hop communication protocol for LoRa with software-defined networking extension
    Farooq, Muhammad Omer
    INTERNET OF THINGS, 2021, 14