Preserving Confidentiality in PCE-based Multi-domain Networks

被引:14
|
作者
Paolucci, Francesco [1 ]
Gharbaoui, Molka [1 ]
Giorgetti, Alessio [1 ]
Cugini, Filippo [2 ]
Martini, Barbara [2 ]
Valcarenghi, Luca [1 ]
Castoldi, Piero [1 ]
机构
[1] Scuola Super Sant Anna, I-56124 Pisa, Italy
[2] CNIT, I-56124 Pisa, Italy
关键词
Authorization policy; Confidentiality; Generalized multiprotocol label switching; Multi-domain; Path computation element; PCE protocol; Security; PATH-COMPUTATION;
D O I
10.1364/JOCN.3.000465
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The path computation element (PCE) architecture has been proposed to effectively enable multi-domain traffic engineering (TE) in generalized multiprotocol label switching (GMPLS) networks while providing an adequate level of confidentiality among domains. However, a malicious utilization of the procedures defined within the PCE architecture might affect the confidentiality of network domain information in a multi-domain multi-carrier network scenario. This paper discusses the critical issues of the PCE architecture in terms of confidentiality. A two-step authorization scheme, named the behavior-based PCE authorization policy (BPAP), is proposed. The BPAP includes a novel add-on PCE component and a central authorization policy server to protect against confidentiality breaking. The scheme is based on the PCE protocol (PCEP) client behavior analysis and includes attack pattern detection procedures and possible partial information filtering of the reply message. The applicability of the BPAP scheme is validated in wavelength switched optical networks (WSONs) through simulations focusing on the exchange of a restricted set of available resources. Finally, a BPAP implementation is experimentally evaluated, showing the efficiency of the two-step scheme in terms of scalability, capability to limit the discovery of critical information, and reactivity to confidential attacks.
引用
收藏
页码:465 / 474
页数:10
相关论文
共 50 条
  • [1] Survivable Path Computation in PCE-Based Multi-domain Networks
    Zhang, Qiong
    Hasan, Mohammad M.
    Wang, Xi
    Palacharla, Paparao
    Sekiya, Motoyoshi
    [J]. JOURNAL OF OPTICAL COMMUNICATIONS AND NETWORKING, 2012, 4 (06) : 457 - 467
  • [2] PCE-based fast path control in multi-domain photonic networks
    Iizawa, Yohei
    Araki, Soichiro
    Ishida, Shinya
    Nishioka, Itaru
    Shimada, Kohei
    Hasegawa, Hiroshi
    Sato, Ken-ichi
    [J]. OPTICAL SWITCHING AND NETWORKING, 2013, 10 (01) : 32 - 43
  • [3] Scalable Path Computation Flooding Approach for PCE-Based Multi-domain Networks
    Perello, Jordi
    Hernandez-Sola, Guillem
    Agraz, Fernando
    Spadaro, Salvatore
    Comellas, Jaume
    [J]. ETRI JOURNAL, 2010, 32 (04) : 622 - 625
  • [4] Implementation of Segmented Protection and Restoration in PCE-based Multi-domain Heterogeneous Optical Networks
    Liu, Wangyang
    Li, Qingshan
    Lu, Rui
    Wan, Xin
    Hua, Nan
    Zheng, Xiaoping
    Zhou, Bingkun
    Chen, Xiaohui
    Wang, Pi
    [J]. 2012 7TH INTERNATIONAL ICST CONFERENCE ON COMMUNICATIONS AND NETWORKING IN CHINA (CHINACOM), 2012, : 284 - 287
  • [5] PCE-based Network Design for Multi-domain Layer 1 Virtual Private Networks
    Chen, Xiuzhong
    Zhang, Jie
    Cheng, Xiaofei
    Wang, Yan
    Wang, Lei
    Zhang, Xian
    Gu, Wanyi
    Ji, Yuefeng
    [J]. OFC: 2009 CONFERENCE ON OPTICAL FIBER COMMUNICATION, VOLS 1-5, 2009, : 2609 - +
  • [6] Scalable Hybrid Path Computation Procedure for PCE-Based Multi-Domain WSON Networks
    Hernandez-Sola, G.
    Perello, J.
    Agraz, F.
    Spadaro, S.
    Comellas, J.
    Junyent, G.
    [J]. 2011 13TH INTERNATIONAL CONFERENCE ON TRANSPARENT OPTICAL NETWORKS (ICTON), 2011,
  • [7] Enhanced domain disjoint backward recursive TE path computation for PCE-based multi-domain networks
    Guillem Hernández-Sola
    Jordi Perelló
    Fernando Agraz
    Luis Velasco
    Salvatore Spadaro
    Gabriel Junyent
    [J]. Photonic Network Communications, 2011, 21 : 141 - 151
  • [8] Enhanced domain disjoint backward recursive TE path computation for PCE-based multi-domain networks
    Hernandez-Sola, Guillem
    Perello, Jordi
    Agraz, Fernando
    Velasco, Luis
    Spadaro, Salvatore
    Junyent, Gabriel
    [J]. PHOTONIC NETWORK COMMUNICATIONS, 2011, 21 (02) : 141 - 151
  • [9] Domain Sequence Protocol (DSP) for PCE-Based Multi-Domain Traffic Engineering
    Siracusa, Domenico
    Grita, Stefano
    Maier, Guido
    Pattavina, Achille
    Paolucci, Francesco
    Cugini, Filippo
    Castoldi, Piero
    [J]. JOURNAL OF OPTICAL COMMUNICATIONS AND NETWORKING, 2012, 4 (11) : 876 - 884
  • [10] Guaranteeing Confidentiality in Multi-domain Networks: the PCE Anomaly Detector (PAD)
    Gharbaoui, M.
    Paolucci, F.
    Giorgetti, A.
    Castoldi, P.
    Martini, B.
    [J]. 2013 IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM 2013), 2013, : 485 - 491