Footprints: Ensuring Trusted Service Function Chaining in the World of SDN and NFV

被引:5
|
作者
Pattaranantakul, Montida [1 ,3 ,4 ]
Song, Qipeng [1 ]
Tian, Yanmei [2 ]
Wang, Licheng [2 ]
Zhang, Zonghua [1 ,3 ]
Meddahi, Ahmed [1 ]
机构
[1] IMT Lille Douai, Inst Mine Telecom, Lille, France
[2] Beijing Univ Posts & Telecommun, Beijing, Peoples R China
[3] CNRS UMR 5157 SAMOVAR Lab, Telecom SudParis, Evry, France
[4] Natl Elect & Comp Technol Ctr, Pathum Thani, Thailand
关键词
NFV; SDN; SFC; Aggregate signature; Pairings;
D O I
10.1007/978-3-030-37231-6_16
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Network Function Virtualization (NFV) and Software Defined Networking (SDN) empower Service Function Chaining (SFC), which integrates an ordered list of Virtualized Network Functions (VNFs) together for implementing a particular service. However, the high-level SFC policy specification cannot guarantee that the VNFs are always chained in an expected manner (or the packet flows of the service are forwarded to the VNFs of concern in a predefined order). An attacker can manage to bypass or evade the security VNFs (e.g., firewall, virus scanner, DPI) and deviate the packets flows from the pre-specified path. It is thus a significant need to have an efficient self-checking mechanism in place, ensuring the SFC to be implemented in a secure and correct way. We develop such a scheme based on an improved crypto primitive, Lite identity-based ordered multisignature, which enforces all the VNFs in the same service chain to sequentially sign the packets received. Then the last hop of the chain will verify the aggregate signature, so as to validate the authenticity of the VNFs, as well as their orders in the chain. We leverage the IETF Network Service Header (NSH) to implement our scheme and run the experiments in a real-world environment to evaluate its performance in terms of computational overhead and latency.
引用
收藏
页码:287 / 301
页数:15
相关论文
共 50 条
  • [1] SDN/NFV VNF Service Chaining
    Anand, Dashmeet
    Narasimhakumar, Hariharakumar
    Kulkarni, Rohit
    Ninale, Sarang
    Perigo, Levi
    Gedia, Dewang
    Gandotra, Rahil
    [J]. INFORMATION TECHNOLOGY IN INDUSTRY, 2020, 8 (01): : 1 - 7
  • [2] Modeling and Performance Analysis for Service Function Chaining in the SDN/NFV Architecture
    Duan, Qiang
    [J]. 2018 4TH IEEE CONFERENCE ON NETWORK SOFTWARIZATION AND WORKSHOPS (NETSOFT), 2018, : 476 - 481
  • [3] Multiple Service Function Chaining Under Load Balance in SDN/NFV Networks
    Liu, Faqiang
    Chen, Xin
    An, Wei
    Peng, Yong
    Cao, Jiuyue
    Zhang, Yan
    [J]. 2017 IEEE 28TH ANNUAL INTERNATIONAL SYMPOSIUM ON PERSONAL, INDOOR, AND MOBILE RADIO COMMUNICATIONS (PIMRC), 2017,
  • [4] Dynamic Service Function Chaining by Resource Usage Learning in SDN/NFV Environment
    Kim, Sang Il
    Kim, Hwa Sung
    [J]. 33RD INTERNATIONAL CONFERENCE ON INFORMATION NETWORKING (ICOIN 2019), 2019, : 485 - 488
  • [5] SDN-based service function chaining mechanism and service prototype implementation in NFV scenario
    Trajkovska, Irena
    Kourtis, Michail-Alexandros
    Sakkas, Christos
    Baudinot, Denis
    Silva, Joao
    Harsh, Piyush
    Xylouris, George
    Bohnert, Thomas Michael
    Koumaras, Harilaos
    [J]. COMPUTER STANDARDS & INTERFACES, 2017, 54 : 247 - 265
  • [6] Enabling Efficient Service Function Chaining by Integrating NFV and SDN : Architecture, Challenges and Opportunities
    Zhang, Jiao, V
    Wang, Zenan
    Ma, Ningning
    Huang, Tao
    Liu, Yunjie
    [J]. IEEE NETWORK, 2018, 32 (06): : 152 - 159
  • [7] SDN-NFV-Cloud Introduction in the Context of Service Chaining
    Akyildiz, Hasan Anil
    Saygun, Ece
    [J]. 2015 23RD SIGNAL PROCESSING AND COMMUNICATIONS APPLICATIONS CONFERENCE (SIU), 2015, : 2605 - 2608
  • [8] Improving dynamic service function chaining classification in NFV/SDN networks through the offloading concept
    Polverini, Marco
    Galan-Jimenez, Jaime
    Lavacca, Francesco G.
    Cianfrani, Antonio
    Eramo, Vincenzo
    [J]. COMPUTER NETWORKS, 2020, 182
  • [9] Providing Resiliency for Service Function Chaining in NFV systems using a SDN-based approach
    Karra, Karthik
    Sivalingam, Krishna M.
    [J]. 2018 TWENTY FOURTH NATIONAL CONFERENCE ON COMMUNICATIONS (NCC), 2018,
  • [10] Network Orchestrator for QoS-enabled Service Function Chaining in reliable NFV/SDN infrastructure
    Gharbaoui, M.
    Fichera, S.
    Castoldi, P.
    Martini, B.
    [J]. 2017 IEEE CONFERENCE ON NETWORK SOFTWARIZATION (IEEE NETSOFT), 2017,