Token as a Service for Software-Defined Zero Trust Networking

被引:0
|
作者
Erel-Ozcevik, Muge [1 ]
机构
[1] Manisa Celal Bayar Univ, Software Engn Deparment, Acarlar st, TR-45400 Manisa, Turkiye
关键词
Zero trust network; Software defined network; Authentication; Software as a service; Genetic algorithm;
D O I
10.1007/s10922-024-09894-w
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Zero Trust Networking (ZTN) is more challenging in a multi-tenant environment. To meet different service requirements of multi-tenants and minimize the risk of physical deployment with low operational and capital expenditures, investments in Software-Defined Networks (SDN) based ZTN have been increased. The research question is whether is there any SDN-based architecture to maintain a trusted zone in a complex multi-tenant environment, where each network equipment can be dynamically configurable by many SDN controllers in a distributed way without security breach. Therefore, this paper proposes a novel Software-Defined Zero Trust Networking (SDZTN) decoupling Cyber and Physical layers. To maintain a trusted zone, it proposes a novel Token as a Service (TaaS) that executes genetic algorithm-based service optimization and generates unique tokens by its solution and using a simply implemented JSON Web Token (JWT). It reduces authentication/authorization load in cloud servers by simplifying and distributing databases in each OpenFlow switch. According to the proposed Zero Trust Evaluation (ZTE) metric considering the token similarity and infection probability, SDZTN results in 25% higher trust than the conventional one. It also overcomes several infection attacks which have the potential to revolutionize token management systems by providing decentralized, easily implementable, and trusted solutions.
引用
收藏
页数:20
相关论文
共 50 条
  • [1] SDNaaS: Software-Defined Networking as an IXP Service
    Mendoza, John Robert
    Frias, Levin
    Austria, Isabel
    Festin, Cedric
    Ocampo, Roel
    2022 IEEE CONFERENCE ON NETWORK FUNCTION VIRTUALIZATION AND SOFTWARE DEFINED NETWORKS (IEEE NFV-SDN), 2022, : 59 - 65
  • [2] Service as a standard [software-defined networking concept]
    Courtney, M.
    Engineering and Technology, 2012, 7 (11): : 64 - 67
  • [3] Software-defined networking
    Greene, Kate
    Technology Review, 2009, 112 (02)
  • [4] Software-Defined Networking
    Kirkpatrick, Keith
    COMMUNICATIONS OF THE ACM, 2013, 56 (09) : 16 - 19
  • [5] Software-Defined Networking
    Zhili Sun
    Jiandong Li
    Kun Yang
    ZTE Communications, 2014, 12 (02) : 1 - 2
  • [6] StEERING: A Software-Defined Networking for Inline Service Chaining
    Zhang, Ying
    Beheshti, Neda
    Beliveau, Ludovic
    Lefebvre, Geoffrey
    Manghirmalani, Ravi
    Mishra, Ramesh
    Patney, Ritun
    Shirazipour, Meral
    Subrahmaniam, Ramesh
    Truchan, Catherine
    Tatipamula, Mallik
    2013 21ST IEEE INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP), 2013,
  • [7] An algorithm to improve quality of service for software-defined networking
    Abdelghany H.M.
    Zaki F.W.
    Ashour M.M.
    Journal of Ambient Intelligence and Humanized Computing, 2023, 14 (08) : 10823 - 10832
  • [8] Video Streaming Service Identification on Software-Defined Networking
    Castaneda Herrera, Luis Miguel
    Campo Munoz, Wilmar Yesid
    Duque-Torres, Alejandra
    INTERNATIONAL JOURNAL OF COMPUTERS COMMUNICATIONS & CONTROL, 2021, 16 (05)
  • [9] A security and trust framework for virtualized networks and software-defined networking
    Yan, Zheng
    Zhang, Peng
    Vasilakos, Athanasios V.
    SECURITY AND COMMUNICATION NETWORKS, 2016, 9 (16) : 3059 - 3069
  • [10] An intelligent zero trust secure framework for software defined networking
    Guo, Xian
    Xian, Hongbo
    Feng, Tao
    Jiang, Yongbo
    Zhang, Di
    Fang, Junli
    PEERJ COMPUTER SCIENCE, 2023, 9