A Secure Multi-Tenant Framework for SDN

被引:4
|
作者
Jiang, Hao [1 ]
Bouabdallah, Ahmed [1 ]
Aflatoonian, Amin [1 ]
Bonnin, Jean-Marie [1 ]
Guillouard, Karine [2 ]
机构
[1] Telecom Bretagne, Inst Mines Telecom, Site Rennes, Network Secur & Multimedia Dept, F-35576 Cesson Sevigne, France
[2] Orange Labs, Multi Access Convergence Architecture, 4 Rue Clos Courtel, F-35512 Cesson Sevigne, France
关键词
Software-Defined Networking; Multi-tenancy; Isolation; Access Control;
D O I
10.1145/2947626.2947641
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software-Delined Networking (SDN) promises a flexible and programmable solution for future networks. By extracting the control logic out of forwarding devices into a specific entity as the control plane, it dramatically eases the management work of multi-tenant networks, where several customers share same network resources. Depending on the way and the SDN layer that tenants can interact with, they can be allowed to have higher and differentiated levels of control over their own slices of available resources. This paper discusses multi-tenancy in SDN by proposing a framework on SDN northbound that focuses as a matter of priority on isolation and access control. A new network abstraction layer is introduced between the control layer and application layer on top of which tenants are provided unified APIs with abstract views and pre-defined levels of control over their dedicated virtual networks, with no concerning about the underlying type and number of controllers as well as topology of physical networks. A developed PoC finally shows the soundness of our approach by implementing various levels of isolation together with AAA functions.
引用
收藏
页码:40 / 44
页数:5
相关论文
共 50 条
  • [1] Multi-Tenant Transport Networks with SDN/NFV
    Vilalta, R.
    Mayoral, A.
    Munoz, R.
    Casellas, R.
    Martinez, R.
    [J]. ECOC 2015 41ST EUROPEAN CONFERENCE ON OPTICAL COMMUNICATION, 2015,
  • [2] A Fine-Grained Multi-Tenant Permission Management Framework for SDN and NFV
    Zou, Deqing
    Lu, Yu
    Yuan, Bin
    Chen, Haoyu
    Jin, Hai
    [J]. IEEE ACCESS, 2018, 6 : 25562 - 25572
  • [3] Secure and Multi-tenant Hadoop Cluster - An Experience
    Wankhede, Paresh
    Paul, Nayanjyoti
    [J]. 2016 2ND INTERNATIONAL CONFERENCE ON GREEN HIGH PERFORMANCE COMPUTING (ICGHPC), 2016,
  • [4] The Study on Configuration of Multi-Tenant Networks in SDN Controller
    Shin, Y. Y.
    Kang, S. H.
    Kwak, J. Y.
    Lee, B. Y.
    Yang, S. H.
    [J]. 2014 16TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY (ICACT), 2014, : 1223 - 1226
  • [5] Towards Secure Multi-tenant Virtualized Networks
    Paladi, Nicolae
    Gehrmann, Christian
    [J]. 2015 IEEE TRUSTCOM/BIGDATASE/ISPA, VOL 1, 2015, : 1180 - 1185
  • [6] Multi-Tenant, Secure, Load Disseminated SaaS Architecture
    Pervez, Zeeshan
    Lee, Sungyoung
    Lee, Young-Koo
    [J]. 12TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY: ICT FOR GREEN GROWTH AND SUSTAINABLE DEVELOPMENT, VOLS 1 AND 2, 2010, : 214 - 219
  • [7] Augmented RAN with SDN Orchestration of Multi-tenant Base Stations
    Costanzo, Salvatore
    Xenakis, Dionysis
    Passas, Nikos
    Merakos, Lazaros
    [J]. WIRELESS PERSONAL COMMUNICATIONS, 2017, 96 (02) : 2009 - 2037
  • [8] Augmented RAN with SDN Orchestration of Multi-tenant Base Stations
    Salvatore Costanzo
    Dionysis Xenakis
    Nikos Passas
    Lazaros Merakos
    [J]. Wireless Personal Communications, 2017, 96 : 2009 - 2037
  • [9] A Multi-Tenant Framework for Multimedia Conference System
    Wang Shaofeng
    Shang Yanlei
    Tian Yue
    [J]. 2013 8TH INTERNATIONAL ICST CONFERENCE ON COMMUNICATIONS AND NETWORKING IN CHINA (CHINACOM), 2013, : 161 - 165
  • [10] Framework for Management of Multi-tenant Cloud Environments
    Beranek, Marek
    Kovar, Vladimir
    Feuerlicht, George
    [J]. CLOUD COMPUTING - CLOUD 2018, 2018, 10967 : 309 - 322