Preserving Confidentiality in PCE-based Multi-domain Networks

被引:14
|
作者
Paolucci, Francesco [1 ]
Gharbaoui, Molka [1 ]
Giorgetti, Alessio [1 ]
Cugini, Filippo [2 ]
Martini, Barbara [2 ]
Valcarenghi, Luca [1 ]
Castoldi, Piero [1 ]
机构
[1] Scuola Super Sant Anna, I-56124 Pisa, Italy
[2] CNIT, I-56124 Pisa, Italy
关键词
Authorization policy; Confidentiality; Generalized multiprotocol label switching; Multi-domain; Path computation element; PCE protocol; Security; PATH-COMPUTATION;
D O I
10.1364/JOCN.3.000465
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The path computation element (PCE) architecture has been proposed to effectively enable multi-domain traffic engineering (TE) in generalized multiprotocol label switching (GMPLS) networks while providing an adequate level of confidentiality among domains. However, a malicious utilization of the procedures defined within the PCE architecture might affect the confidentiality of network domain information in a multi-domain multi-carrier network scenario. This paper discusses the critical issues of the PCE architecture in terms of confidentiality. A two-step authorization scheme, named the behavior-based PCE authorization policy (BPAP), is proposed. The BPAP includes a novel add-on PCE component and a central authorization policy server to protect against confidentiality breaking. The scheme is based on the PCE protocol (PCEP) client behavior analysis and includes attack pattern detection procedures and possible partial information filtering of the reply message. The applicability of the BPAP scheme is validated in wavelength switched optical networks (WSONs) through simulations focusing on the exchange of a restricted set of available resources. Finally, a BPAP implementation is experimentally evaluated, showing the efficiency of the two-step scheme in terms of scalability, capability to limit the discovery of critical information, and reactivity to confidential attacks.
引用
收藏
页码:465 / 474
页数:10
相关论文
共 50 条
  • [31] PCE-based Inter-Domain Lightpath Provisioning
    Pontes, Alisson
    Drummond, Andre C.
    da Fonseca, Nelson L. S.
    Jukan, Admela
    [J]. 2012 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2012,
  • [32] A Hierarchical Path Computation Element (PCE)-Based Routing Algorithm in Multi-Domain WDM Networks
    Shang, Shengfeng
    Zheng, Xiaoping
    Zhang, Heng
    Hua, Nan
    Zhang, Hanyi
    [J]. NETWORK ARCHITECTURES, MANAGEMENT, AND APPLICATIONS VIII, 2011, 7989
  • [33] Effective Statistical Detection of Smart Confidentiality Attacks in Multi-Domain Networks
    Gharbaoui, Molka
    Paolucci, Francesco
    Giorgetti, Alessio
    Martini, Barbara
    Castoldi, Piero
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2013, 10 (04): : 383 - 397
  • [34] Connection Provisioning for PCE-Based GMPLS Optical Networks
    Reddy, Murla Bhumi
    Thangaraj, Jaisingh
    Priye, Vishnu
    [J]. WIRELESS PERSONAL COMMUNICATIONS, 2018, 103 (04) : 2775 - 2790
  • [35] Field and lab trials of PCE-based OSNR-aware dynamic restoration in multi-domain GMPLS-enabled translucent WSON
    Liu, Lei
    Casellas, Ramon
    Tsuritani, Takehiro
    Morita, Itsuro
    Okamoto, Shuichi
    Martinez, Ricardo
    Munoz, Rauel
    [J]. OPTICS EXPRESS, 2011, 19 (27): : 26568 - 26577
  • [36] Connection Provisioning for PCE-Based GMPLS Optical Networks
    Murla Bhumi Reddy
    Jaisingh Thangaraj
    Vishnu Priye
    [J]. Wireless Personal Communications, 2018, 103 : 2775 - 2790
  • [37] AN ENHANCED APPROACH OF INTER-DOMAIN PATH COMPUTATION IN HIERARCHICAL PCE-BASED GMPLS MULTI-REGION NETWORKS
    Gu, Yuan
    Zhang, Jie
    Zhao, Yongli
    Mao, Yixia
    Meng, Shengwei
    Wu, Di
    Gu, Wanyi
    [J]. 2011 4TH IEEE INTERNATIONAL CONFERENCE ON BROADBAND NETWORK AND MULTIMEDIA TECHNOLOGY (4TH IEEE IC-BNMT2011), 2011, : 84 - 90
  • [38] PCE-Based Centralized Control Plane for Filterless Networks
    Mantelet, Guillaume
    Tremblay, Christine
    Plant, David V.
    Littlewood, Paul
    Belanger, Michel P.
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2013, 51 (05) : 128 - 135
  • [39] A Novel PCE-based Architecture of Multi-region and Multi-layer GMPLS/ASON Networks
    Zhang Jie
    Zhao Yongli
    Cao Xuping
    Han Dahai
    Chen Xiuzhong
    Gu Wanyi
    Ji Yuefeng
    [J]. CHINA COMMUNICATIONS, 2009, 6 (03) : 64 - 71