Analysis and practical validation of a standard SDN-based framework for IPsec management

被引:10
|
作者
Lopez-Millan, Gabriel [1 ,4 ]
Marin-Lopez, Rafael [1 ]
Pereniguez-Garcia, Fernando [2 ]
Canovas, Oscar [3 ]
Espin, Jose Antonio Parra [1 ]
机构
[1] Univ Murcia, Dept Informat & Commun Engn, Murcia 30100, Spain
[2] Univ Def Ctr Spanish Air Force Acad, Dept Engn & Appl Technol, Murcia 30720, Spain
[3] Univ Murcia, Dept Comp Engn, Murcia 30100, Spain
[4] Fac Informat, Campus Espinardo S-N, Murcia 30100, Spain
关键词
IPSec; IKE; Management; SDN; Performance;
D O I
10.1016/j.csi.2022.103665
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The Internet Engineering Task Force (IETF), the international standardization organism for the Internet, has recently approved a standard, RFC 9061, which defines an interface and framework with which to manage IPsec SAs autonomously by using the Software Defined Networking (SDN) paradigm. In this framework, a centralized entity, the controller, sends configuration information to IPsec-enabled nodes in the network in order to create IPsec SAs. Two cases are presented: IKE-case, in which the nodes ship an IKE implementation that is configured by the controller or IKE-less, in which the controller sends the IPsec SAs directly to the nodes, among other relevant security information.This paper analyzes both cases in depth, provides a design for the controller's operation based on Mealy state machines and obtains experimental results from a virtualized testbed so as to compare these cases, which are missing parts in the standard.
引用
收藏
页数:13
相关论文
共 50 条
  • [1] Towards a standard SDN-based IPsec management framework
    Lopez-Millan, Gabriel
    Marin-Lopez, Rafael
    Pereniguez-Garcia, Fernando
    [J]. COMPUTER STANDARDS & INTERFACES, 2019, 66
  • [2] Establishment of IPsec Security Associations with Diffie-Hellman following a SDN-based framework: Analysis and practical validation
    Parra-Espin, Jose Antonio
    Marin-Lopez, Rafael
    Lopez-Millan, Gabriel
    [J]. COMPUTER NETWORKS, 2024, 253
  • [3] A Practical SDN-Based Data Offloading Framework
    Lee, Hyukjoon
    Kim, Hwasung
    Kim, Younghan
    [J]. 2017 31ST INTERNATIONAL CONFERENCE ON INFORMATION NETWORKING (ICOIN), 2017, : 604 - 607
  • [4] SDN-based automated rekey of IPsec security associations: Design and practical validations
    Parra-Espin, Jose Antonio
    Marin-Lopez, Rafael
    Lopez-Millan, Gabriel
    Pereniguez-Garcia, Fernando
    Canovas, Oscar
    [J]. COMPUTER NETWORKS, 2023, 233
  • [5] A General and Practical Framework for Realization of SDN-based Vehicular Networks
    Leon, Juan, V
    Bautista, Oscar G.
    Aydeger, Abdullah
    Mercan, Suat
    Akkaya, Kemal
    [J]. 2021 IEEE INTERNATIONAL PERFORMANCE, COMPUTING, AND COMMUNICATIONS CONFERENCE (IPCCC), 2021,
  • [6] SDN-based Access Authentication and Automatic Configuration for IPSec
    Li, Yunchun
    Mao, Jutao
    [J]. PROCEEDINGS OF 2015 4TH INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND NETWORK TECHNOLOGY (ICCSNT 2015), 2015, : 996 - 999
  • [7] Demand Response Application as a Service: An SDN-Based Management Framework
    Montazerolghaem, Ahmadreza
    Yaghmaee, Mohammad Hossein
    [J]. IEEE TRANSACTIONS ON SMART GRID, 2022, 13 (03) : 1952 - 1966
  • [8] RFlow+ : An SDN-based WLAN Monitoring and Management Framework
    Jang, RhongHo
    Cho, DongGyu
    Noh, Youngtae
    Nyang, DaeHun
    [J]. IEEE INFOCOM 2017 - IEEE CONFERENCE ON COMPUTER COMMUNICATIONS, 2017,
  • [9] A QoS framework for SDN-based Networks
    Ghalwash, Haitham
    Huang, Chun-Hsi
    [J]. 2018 4TH IEEE INTERNATIONAL CONFERENCE ON COLLABORATION AND INTERNET COMPUTING (CIC 2018), 2018, : 98 - 105
  • [10] Horizon: a QoS management framework for SDN-based data center networks
    Junjie Pang
    Gaochao Xu
    Xiaodong Fu
    Kuo Zhao
    [J]. Annals of Telecommunications, 2017, 72 : 597 - 605