Token as a Service for Software-Defined Zero Trust Networking

被引:0
|
作者
Erel-Ozcevik, Muge [1 ]
机构
[1] Manisa Celal Bayar Univ, Software Engn Deparment, Acarlar st, TR-45400 Manisa, Turkiye
关键词
Zero trust network; Software defined network; Authentication; Software as a service; Genetic algorithm;
D O I
10.1007/s10922-024-09894-w
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Zero Trust Networking (ZTN) is more challenging in a multi-tenant environment. To meet different service requirements of multi-tenants and minimize the risk of physical deployment with low operational and capital expenditures, investments in Software-Defined Networks (SDN) based ZTN have been increased. The research question is whether is there any SDN-based architecture to maintain a trusted zone in a complex multi-tenant environment, where each network equipment can be dynamically configurable by many SDN controllers in a distributed way without security breach. Therefore, this paper proposes a novel Software-Defined Zero Trust Networking (SDZTN) decoupling Cyber and Physical layers. To maintain a trusted zone, it proposes a novel Token as a Service (TaaS) that executes genetic algorithm-based service optimization and generates unique tokens by its solution and using a simply implemented JSON Web Token (JWT). It reduces authentication/authorization load in cloud servers by simplifying and distributing databases in each OpenFlow switch. According to the proposed Zero Trust Evaluation (ZTE) metric considering the token similarity and infection probability, SDZTN results in 25% higher trust than the conventional one. It also overcomes several infection attacks which have the potential to revolutionize token management systems by providing decentralized, easily implementable, and trusted solutions.
引用
收藏
页数:20
相关论文
共 50 条
  • [31] A Survey of Multicast in Software-Defined Networking
    Gu, Weidong
    Zhang, Xinchang
    Gong, Bin
    Wang, Lu
    PROCEEDINGS OF THE 5TH INTERNATIONAL CONFERENCE ON INFORMATION ENGINEERING FOR MECHANICS AND MATERIALS, 2015, 21 : 1096 - 1100
  • [32] Software-Defined Networking: On the Verge of a Breakthrough?
    Ortiz, Sixto, Jr.
    COMPUTER, 2013, 46 (07) : 10 - 12
  • [33] Verification Framework for Software-Defined Networking
    Kang, Miyoung
    Cho, Jong Jin
    2022 24TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY (ICACT): ARITIFLCIAL INTELLIGENCE TECHNOLOGIES TOWARD CYBERSECURITY, 2022, : 518 - 523
  • [34] A Survey on Multicasting in Software-Defined Networking
    Islam, Salekul
    Muslim, Nasif
    Atwood, J. William
    IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2018, 20 (01): : 355 - 387
  • [35] Misreporting Attacks in Software-Defined Networking
    Burke, Quinn
    McDaniel, Patrick
    La Porta, Thomas
    Yu, Mingli
    He, Ting
    SECURITY AND PRIVACY IN COMMUNICATION NETWORKS (SECURECOMM 2020), PT I, 2020, 335 : 276 - 296
  • [36] Toward Software-Defined Middlebox Networking
    Gember, Aaron
    Prabhu, Prathmesh
    Ghadiyali, Zainab
    Akella, Aditya
    PROCEEDINGS OF THE 11TH ACM WORKSHOP ON HOT TOPICS IN NETWORKS (HOTNETS-XI), 2012, : 7 - 12
  • [37] Software-defined networking (SDN): a survey
    Benzekki, Kamal
    El Fergougui, Abdeslam
    Elalaoui, Abdelbaki Elbelrhiti
    SECURITY AND COMMUNICATION NETWORKS, 2016, 9 (18) : 5803 - 5833
  • [38] Toward Software-Defined Battlefield Networking
    Nobre, Jeferson
    Rosario, Denis
    Both, Cristiano
    Cerqueira, Eduardo
    Gerla, Mario
    IEEE COMMUNICATIONS MAGAZINE, 2016, 54 (10) : 152 - 157
  • [39] Semantic Failover in Software-Defined Networking
    Hsueh, Shu-Wen
    Lin, Tung-Yueh
    Lei, Weng-Ian
    Ngai, Chi-Leung Patrick
    Sheng, Yu-Hang
    Wu, Yu-Sung
    2018 IEEE 23RD PACIFIC RIM INTERNATIONAL SYMPOSIUM ON DEPENDABLE COMPUTING (PRDC), 2018, : 299 - 308
  • [40] A Software-Defined Approach to IoT Networking
    Christian Jacquenet
    Mohamed Boucadair
    ZTE Communications, 2016, 14 (01) : 61 - 66