Distributed controllers multi-granularity security communication mechanism for software-defined networking

被引:6
|
作者
Shang, Fengjun [1 ]
Li, Yan [1 ]
Fu, Qiang [1 ]
Wang, Wenkai [1 ]
Feng, Jiangfan [1 ]
He, Li [1 ]
机构
[1] Chongqing Univ Posts & Telecommun, Coll Comp Sci & Technol, Chongqing 400065, Peoples R China
基金
中国国家自然科学基金;
关键词
Software defined network; Security architecture; Secure communication; SDN;
D O I
10.1016/j.compeleceng.2017.07.003
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
For the multi-domain software defined network (SDN), different controllers are not able to directly communicate with each other due to the different distances among control planes. Therefore, the exchange of information among different domains is generally unsecure. The main contribution of this paper can be summarized into two parts. Firstly, architecture of multi-granularity security controller is proposed, which includes a basic control module and a multi-granularity security customized module. Secondly, a secure communication mechanism is proposed for distributed controller, where a prototype of this mechanism is implemented. In particular, this mechanism can make use of the border switch as inter domain agents, where special packets are used by the controller to send messages to the secure tunnel. A two-step authentication of the controller can be provided by inter-domain agents and digital certificates. The experimental results demonstrate that the distributed controller secure communication mechanism is capable of effectively improving the security of SDN domain. (C) 2017 Elsevier Ltd. All rights reserved.
引用
收藏
页码:388 / 406
页数:19
相关论文
共 50 条
  • [41] Managing Industrial Communication Delays with Software-Defined Networking
    Jhaveri, Rutvij H.
    Tan, Rui
    Easwaran, Arvind
    Ramani, Sagar, V
    2019 IEEE 25TH INTERNATIONAL CONFERENCE ON EMBEDDED AND REAL-TIME COMPUTING SYSTEMS AND APPLICATIONS (RTCSA 2019), 2019,
  • [42] Dynamic-scheduling mechanism of controllers based on security policy in software-defined network
    Qi, Chao
    Wu, Jiangxing
    Hu, Hongchao
    Cheng, Guozhen
    ELECTRONICS LETTERS, 2016, 52 (23) : 1918 - 1920
  • [43] SmartSec: A Smart Security Mechanism for the New-Flow Attack in Software-Defined Networking
    Xu, Tong
    Gao, Deyun
    Dong, Ping
    Zheng, Tao
    Sun, Jianan
    2017 IEEE 85TH VEHICULAR TECHNOLOGY CONFERENCE (VTC SPRING), 2017,
  • [44] Role-based intelligent application state computing for OpenFlow distributed controllers in software-defined networking
    Fu, Tao
    Hu, Liang
    Yu, Xiaodi
    Hu, Jiejun
    Zhao, Kuo
    SOFT COMPUTING, 2017, 21 (21) : 6269 - 6277
  • [45] Virtualising redundancy of power equipment controllers using software-defined networking
    von Tüllenburg F.
    Dorfinger P.
    Veichtlbauer A.
    Pache U.
    Langthaler O.
    Kapoun H.
    Bischof C.
    Kupzog F.
    Energy Informatics, 2019, 2 (Suppl 1)
  • [46] Role-based intelligent application state computing for OpenFlow distributed controllers in software-defined networking
    Tao Fu
    Liang Hu
    Xiaodi Yu
    Jiejun Hu
    Kuo Zhao
    Soft Computing, 2017, 21 : 6269 - 6277
  • [47] FREEController: A Framework for Relative Efficiency Evaluation of Software-Defined Networking Controllers
    Klosowski, Eduardo Augusto
    Fiorese, Adriano
    PROCEEDINGS OF THE 21ST INTERNATIONAL CONFERENCE ON ENTERPRISE INFORMATION SYSTEMS (ICEIS), VOL 1, 2019, : 349 - 360
  • [48] Design and Implementation of a Security Control Architecture for Software-Defined Networking
    Liu, Tie-jun
    Lin, Zhao-wen
    Xu, Jie
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON COMPUTER NETWORKS AND COMMUNICATION TECHNOLOGY (CNCT 2016), 2016, 54 : 779 - 785
  • [49] A Taxonomy-based Approach for Security in Software-Defined Networking
    Banse, Christian
    Schuette, Julian
    2017 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2017,
  • [50] Advances in security analysis of software-defined networking flow rules
    Xiong W.
    Mao J.
    Liu Z.
    Liu W.
    Liu J.
    Xi'an Dianzi Keji Daxue Xuebao/Journal of Xidian University, 2023, 50 (06): : 172 - 194