Token as a Service for Software-Defined Zero Trust Networking

被引:0
|
作者
Erel-Ozcevik, Muge [1 ]
机构
[1] Manisa Celal Bayar Univ, Software Engn Deparment, Acarlar st, TR-45400 Manisa, Turkiye
关键词
Zero trust network; Software defined network; Authentication; Software as a service; Genetic algorithm;
D O I
10.1007/s10922-024-09894-w
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Zero Trust Networking (ZTN) is more challenging in a multi-tenant environment. To meet different service requirements of multi-tenants and minimize the risk of physical deployment with low operational and capital expenditures, investments in Software-Defined Networks (SDN) based ZTN have been increased. The research question is whether is there any SDN-based architecture to maintain a trusted zone in a complex multi-tenant environment, where each network equipment can be dynamically configurable by many SDN controllers in a distributed way without security breach. Therefore, this paper proposes a novel Software-Defined Zero Trust Networking (SDZTN) decoupling Cyber and Physical layers. To maintain a trusted zone, it proposes a novel Token as a Service (TaaS) that executes genetic algorithm-based service optimization and generates unique tokens by its solution and using a simply implemented JSON Web Token (JWT). It reduces authentication/authorization load in cloud servers by simplifying and distributing databases in each OpenFlow switch. According to the proposed Zero Trust Evaluation (ZTE) metric considering the token similarity and infection probability, SDZTN results in 25% higher trust than the conventional one. It also overcomes several infection attacks which have the potential to revolutionize token management systems by providing decentralized, easily implementable, and trusted solutions.
引用
收藏
页数:20
相关论文
共 50 条
  • [41] Software-Defined Networking of Linux Containers
    Costache, Cosmin
    Machidon, Octavian
    Mladin, Adrian
    Sandu, Florin
    Bocu, Razvan
    2014 ROEDUNET CONFERENCE 13TH EDITION: NETWORKING IN EDUCATION AND RESEARCH JOINT EVENT RENAM 8TH CONFERENCE, 2014,
  • [42] Software-Defined Networking: A Comprehensive Survey
    Kreutz, Diego
    Ramos, Fernando M. V.
    Verissimo, Paulo Esteves
    Rothenberg, Christian Esteve
    Azodolmolky, Siamak
    Uhlig, Steve
    PROCEEDINGS OF THE IEEE, 2015, 103 (01) : 14 - 76
  • [43] Modelling Software-Defined Networking: Software and hardware switches
    Singh, Deepak
    Ng, Bryan
    Lai, Yuan-Cheng
    Lin, Ying-Dar
    Seah, Winston K. G.
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2018, 122 : 24 - 36
  • [44] A novel programmable software datapath for Software-Defined Networking
    Osinski, Tomasz
    Pahmaka, Jan
    Kossakowski, Mateusz
    Tran, Frederic Dang
    Bonfoh, El-Fadel
    Tarasiuk, Halina
    PROCEEDINGS OF THE 18TH INTERNATIONAL CONFERENCE ON EMERGING NETWORKING EXPERIMENTS AND TECHNOLOGIES, CONEXT 2022, 2022, : 245 - 260
  • [45] RE-CHECKER: Towards Secure RESTful Service in Software-Defined Networking
    Woo, Seungwon
    Lee, Seungsoo
    Kim, Jinwoo
    Shin, Seungwon
    2018 IEEE CONFERENCE ON NETWORK FUNCTION VIRTUALIZATION AND SOFTWARE DEFINED NETWORKS (NFV-SDN), 2018,
  • [46] Distributed Denial of Service Classification for Software-Defined Networking Using Grammatical Evolution
    Spyrou, Evangelos D.
    Tsoulos, Ioannis
    Stylios, Chrysostomos
    Davoli, Franco
    FUTURE INTERNET, 2023, 15 (12)
  • [47] On the Design of Software-Defined Service-Centric Networking for Mobile Cloud Computing
    Wang, Zihan
    Zhang, Danhong
    Xia, Huiwen
    2019 IEEE 25TH INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED SYSTEMS (ICPADS), 2019, : 1000 - 1005
  • [48] Introducing a Test Framework for Quality of Service Mechanisms in the Context of Software-Defined Networking
    Regencia, Josiah Eleazar T.
    Yu, William Emmanuel S.
    PROCEEDINGS OF SIXTH INTERNATIONAL CONGRESS ON INFORMATION AND COMMUNICATION TECHNOLOGY (ICICT 2021), VOL 2, 2022, 236 : 687 - 699
  • [49] How can a mobile service provider reduce costs with software-defined networking?
    Naudts, Bram
    Kind, Mario
    Verbrugge, Sofie
    Colle, Didier
    Pickavet, Mario
    INTERNATIONAL JOURNAL OF NETWORK MANAGEMENT, 2016, 26 (01) : 56 - 72
  • [50] A Dynamic Placement Mechanism of Service Function Chaining Based on Software-defined Networking
    Liu, Yicen
    Lu, Yu
    Chen, Xingkai
    Li, Xi
    Qiao, Wenxin
    Chen, Liyun
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2018, 12 (10): : 4640 - 4661