Establishment of IPsec Security Associations with Diffie-Hellman following a SDN-based framework: Analysis and practical validation

被引:0
|
作者
Parra-Espin, Jose Antonio [1 ]
Marin-Lopez, Rafael [1 ]
Lopez-Millan, Gabriel [1 ]
机构
[1] Univ Murcia, Dept Informat & Commun Engn, Murcia 30100, Spain
关键词
IPsec; SDN; Key derivation; Diffie-Hellman; Public-key cryptography; SOFTWARE-DEFINED NETWORKING;
D O I
10.1016/j.comnet.2024.110720
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The centralized management of IPsec Security Associations (SAs) by using Software Defined Network (SDN) paradigm has been already explored and standardized. Datacenters are some of the scenarios where the dynamic establishment of IPsec security associations among network nodes has been deemed relevant. In these scenarios, where nodes do not support protocols like IKEv2, applying solutions where the generation and distribution of keys for IPsec are delegated to the SDN controller. However, these scenarios have the issue that the controller itself generates the IPsec keys for the nodes, posing a higher risk to the system's security in case the controller is compromised. For these scenarios, it would be necessary to define solutions that allow the distribution of this cryptographic material securely, while maintaining the capacity restrictions established by the nodes. To solve this risk, we propose the generation of the IPsec keys using key distribution through the Diffie-Hellman algorithm in such a manner, that the controller will never have access to the IPsec SAs session keys used by the network nodes, mitigating the aforementioned problem. In concrete, our approach makes the nodes responsible for generating their own Diffie-Hellman public and private keypair, while the controller is only in charge of distributing the public keys to the rest of nodes, as well as other parameters needed to install the IPsec SAs. As we will analyze, the distribution of the public keys will be enough to allow the network nodes to generate the session keys. This work presents the design, implementation and validation of this IPsec management solution based on Diffie-Hellman in SDN environments using asymmetric key distribution for negotiating encryption and integrity keys, focusing on the performance in key generation and installation of IPsec SAs.
引用
收藏
页数:13
相关论文
共 5 条
  • [1] Analysis and practical validation of a standard SDN-based framework for IPsec management
    Lopez-Millan, Gabriel
    Marin-Lopez, Rafael
    Pereniguez-Garcia, Fernando
    Canovas, Oscar
    Espin, Jose Antonio Parra
    [J]. COMPUTER STANDARDS & INTERFACES, 2023, 83
  • [2] Study of security of IPsec based on IPv6 and the Diffie-Hellman algorithm
    Yang, Yao
    Liao, Jianming
    Li, JianPing
    Liu, Hui
    Hao, Yujie
    [J]. PROCEEDINGS OF THE INTERNATIONAL CONFERENCE INFORMATION COMPUTING AND AUTOMATION, VOLS 1-3, 2008, : 1233 - +
  • [3] SDN-based automated rekey of IPsec security associations: Design and practical validations
    Parra-Espin, Jose Antonio
    Marin-Lopez, Rafael
    Lopez-Millan, Gabriel
    Pereniguez-Garcia, Fernando
    Canovas, Oscar
    [J]. COMPUTER NETWORKS, 2023, 233
  • [4] Brew: A Security Policy Analysis Framework for Distributed SDN-Based Cloud Environments
    Pisharody, Sandeep
    Natarajan, Janakarajan
    Chowdhary, Ankur
    Alshalan, Abdullah
    Huang, Dijiang
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2019, 16 (06) : 1011 - 1025
  • [5] Security Analysis and Improvement of Authentication Scheme Based on a One-way Hash Function and Diffie-Hellman Key Exchange Using Smart Card
    Kang-seok CHAE
    Dai-hoon KIM
    Jae-duck CHOI
    Souh-wan JUNG
    [J]. Journal of Measurement Science and Instrumentation, 2010, 1 (04) : 360 - 363