SAFE: Software-defined Authentication FramEwork

被引:1
|
作者
Kamath, Aditya V. [1 ]
Sudarshan, S. [1 ]
Kataoka, Kotaro [1 ]
Vijayvergiya, Nishant [1 ]
Reddy, G. Bhargav [1 ]
Phatale, Samrat [1 ]
机构
[1] Indian Inst Technol Hyderabad, Dept Comp Sci & Engn, Sangareddy, Telangana, India
关键词
Authentication; SDN; Network Security; Access Control;
D O I
10.1145/3012695.3012703
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Expanding variety of end devices connected to the Internet has introduced high demand to flexibly authenticate and grant them the necessary access to the network. However, it is not realistic to expect of all the end devices, including less capable and low-cost devices like sensors or embedded systems, to satisfy the requirement of integrated authentication procedure like 802.1x. We propose Software-defined Authentication FramEwork (SAFE) that enables 1) isolation of unauthenticated devices and 2) access control with more flexible modes of authentication. By systematically separating authentication and access control, the networks can have multiple options for authenticating end devices according to their capability, while access control and policy enforcement can be done on a unified platform using SDN. SAFE uses a combined approach of MAC-based identification and location awareness, i.e., the port number and a switch DPID in SDN, to keep unauthenticated devices isolated and still be able to communicate with their affordable authentication server. We examined SAFE in the following 3 scenarios: 1) an emulation environment, 2) a live test bed using production SDN switches and 3) a mixed network with both SDN and non-SDN switches. This paper also implements an alternative and practical mode of authentication expecting IoT devices, which would benefit the most from SAFE.
引用
收藏
页码:57 / 63
页数:7
相关论文
共 50 条
  • [1] Advanced Authentication Protocol for Software-Defined Networks
    Allouzi, Maha Ali
    Khan, Javed, I
    [J]. INTERNATIONAL JOURNAL OF SEMANTIC COMPUTING, 2018, 12 (03) : 361 - 371
  • [2] An LSTM Framework for Software-Defined Measurement
    Lazaris, Aggelos
    Prasanna, Viktor K.
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2021, 18 (01): : 855 - 869
  • [3] Verification Framework for Software-Defined Networking
    Kang, Miyoung
    Cho, Jong Jin
    [J]. 2022 24TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY (ICACT): ARITIFLCIAL INTELLIGENCE TECHNOLOGIES TOWARD CYBERSECURITY, 2022, : 518 - 523
  • [4] A Software-Defined Cloud Resource Management Framework
    Abbasi, Aaqif Afzaal
    Jin, Hai
    Wu, Song
    [J]. ADVANCES IN SERVICES COMPUTING, APSCC 2015, 2015, 9464 : 61 - 75
  • [5] SDSA: A Framework of a Software-Defined Security Architecture
    Liu Yanbing
    Lu Xingyu
    Jian Yi
    Xiao Yunpeng
    [J]. CHINA COMMUNICATIONS, 2016, 13 (02) : 178 - 188
  • [6] A framework for secure download for software-defined radio
    Michael, LB
    Mihaljevic, MJ
    Haruyama, S
    Kohno, R
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2002, 40 (07) : 88 - 96
  • [7] Entrust SDP Authentication to Software-Defined Campus Network (SDCN)
    Karnani, Suruchi
    Shakya, Harish Kumar
    [J]. INTERNATIONAL CONFERENCE ON INNOVATIVE COMPUTING AND COMMUNICATIONS, ICICC 2022, VOL 1, 2023, 473 : 203 - 212
  • [9] A framework for software-defined digital terrestrial television (DTTV)
    Bendov, O.
    [J]. IEEE TRANSACTIONS ON BROADCASTING, 2006, 52 (03) : 404 - 410
  • [10] A comprehensive security assessment framework for software-defined networks
    Lee, Seungsoo
    Kim, Jinwoo
    Woo, Seungwon
    Yoon, Changhoon
    Scott-Hayward, Sandra
    Yegneswaran, Vinod
    Porras, Phillip
    Shin, Seungwon
    [J]. COMPUTERS & SECURITY, 2020, 91