Analysis and practical validation of a standard SDN-based framework for IPsec management

被引:10
|
作者
Lopez-Millan, Gabriel [1 ,4 ]
Marin-Lopez, Rafael [1 ]
Pereniguez-Garcia, Fernando [2 ]
Canovas, Oscar [3 ]
Espin, Jose Antonio Parra [1 ]
机构
[1] Univ Murcia, Dept Informat & Commun Engn, Murcia 30100, Spain
[2] Univ Def Ctr Spanish Air Force Acad, Dept Engn & Appl Technol, Murcia 30720, Spain
[3] Univ Murcia, Dept Comp Engn, Murcia 30100, Spain
[4] Fac Informat, Campus Espinardo S-N, Murcia 30100, Spain
关键词
IPSec; IKE; Management; SDN; Performance;
D O I
10.1016/j.csi.2022.103665
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The Internet Engineering Task Force (IETF), the international standardization organism for the Internet, has recently approved a standard, RFC 9061, which defines an interface and framework with which to manage IPsec SAs autonomously by using the Software Defined Networking (SDN) paradigm. In this framework, a centralized entity, the controller, sends configuration information to IPsec-enabled nodes in the network in order to create IPsec SAs. Two cases are presented: IKE-case, in which the nodes ship an IKE implementation that is configured by the controller or IKE-less, in which the controller sends the IPsec SAs directly to the nodes, among other relevant security information.This paper analyzes both cases in depth, provides a design for the controller's operation based on Mealy state machines and obtains experimental results from a virtualized testbed so as to compare these cases, which are missing parts in the standard.
引用
收藏
页数:13
相关论文
共 50 条
  • [31] SDN-Based Framework for the PEV Integrated Smart Grid
    Chen, Nan
    Wang, Miao
    Zhang, Ning
    Shen, Xuemin
    Zhao, Dongmei
    [J]. IEEE NETWORK, 2017, 31 (02): : 14 - 21
  • [32] Multilayer Network Analytics With SDN-Based Monitoring Framework
    Yan, Shuangyi
    Aguado, Alejandro
    Ou, Yanni
    Wang, Rui
    Nejabati, Reza
    Simeonidou, Dimitra
    [J]. JOURNAL OF OPTICAL COMMUNICATIONS AND NETWORKING, 2017, 9 (02) : A271 - A279
  • [33] Brew: A Security Policy Analysis Framework for Distributed SDN-Based Cloud Environments
    Pisharody, Sandeep
    Natarajan, Janakarajan
    Chowdhary, Ankur
    Alshalan, Abdullah
    Huang, Dijiang
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2019, 16 (06) : 1011 - 1025
  • [34] Dynamic Resource Management in SDN-based Virtualized Networks
    Mijumbi, Rashid
    Serrat, Joan
    Rubio-Loyola, Javier
    Bouten, Niels
    De Turck, Filip
    Latre, Steven
    [J]. 2014 10TH INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE MANAGEMENT (CNSM), 2014, : 412 - 417
  • [35] Reservation based Resource Management for SDN-based UE Cloud
    Sun, Guolin
    Kefyalew, Dawit
    Liu, Guisong
    [J]. KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2016, 10 (12): : 5174 - 5190
  • [36] SDMob: SDN-Based Mobility Management for IoT Networks
    Rabet, Iliar
    Selvaraju, Shunmuga Priyan
    Fotouhi, Hossein
    Alves, Mario
    Vahabi, Maryam
    Balador, Ali
    Bjorkman, Mats
    [J]. JOURNAL OF SENSOR AND ACTUATOR NETWORKS, 2022, 11 (01)
  • [37] SDN-Based Traffic Management Middleware for Spontaneous WMNs
    Paolo Bellavista
    Alessandro Dolci
    Carlo Giannelli
    Dmitrij David Padalino Montenero
    [J]. Journal of Network and Systems Management, 2020, 28 : 1575 - 1609
  • [38] A Management Model for SDN-based Data Center Networks
    Xu, Yifei
    Yan, Yue
    Dai, Zhuyun
    Wang, Xiaolin
    [J]. 2014 IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (INFOCOM WKSHPS), 2014, : 113 - +
  • [39] SDN-Based Traffic Management Middleware for Spontaneous WMNs
    Bellavista, Paolo
    Dolci, Alessandro
    Giannelli, Carlo
    Montenero, Dmitrij David Padalino
    [J]. JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2020, 28 (04) : 1575 - 1609
  • [40] FENet: An SDN-Based Scheme for Virtual Network Management
    Liu, Kun
    Wo, Tianyu
    Cui, Lei
    Shi, Bin
    Xu, Jie
    [J]. 2014 20TH IEEE INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED SYSTEMS (ICPADS), 2014, : 249 - 256