FlowIdentity: Software-defined network access control

S. Yakasai, C. Guy
{"title":"FlowIdentity: Software-defined network access control","authors":"S. Yakasai, C. Guy","doi":"10.1109/NFV-SDN.2015.7387415","DOIUrl":null,"url":null,"abstract":"Software-Defined Networking (SDN) is a new paradigm for building computer networks through the decoupling of the control and forwarding functions of network devices. This has provided not only an exciting opportunity for the industry and researchers to solve some of the most persistent networking problems, but also an environment where creative network applications and services are more easily developed and deployed to solve specific business needs. In this paper, we present FlowIdentity - a virtualized network access control function using OpenFlow protocol. FlowIdentity implements 802.1X framework in SDN architecture, combined with a novel authorization method through a stateful role-based firewall. Policy definition is based on high-level endpoints' role which can be dynamically updated and enforced directly on the centralized 802.1X authenticator. Our solution solves some outlined persistent challenges facing the traditional port-based access control method to provide an effective enterprise network access control solution, and also provides a platform that encourages network operators, equipment vendors and researchers to develop innovative alternatives to the current solutions.","PeriodicalId":315251,"journal":{"name":"2015 IEEE Conference on Network Function Virtualization and Software Defined Network (NFV-SDN)","volume":"90 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2015-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"26","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2015 IEEE Conference on Network Function Virtualization and Software Defined Network (NFV-SDN)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/NFV-SDN.2015.7387415","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 26

Abstract

Software-Defined Networking (SDN) is a new paradigm for building computer networks through the decoupling of the control and forwarding functions of network devices. This has provided not only an exciting opportunity for the industry and researchers to solve some of the most persistent networking problems, but also an environment where creative network applications and services are more easily developed and deployed to solve specific business needs. In this paper, we present FlowIdentity - a virtualized network access control function using OpenFlow protocol. FlowIdentity implements 802.1X framework in SDN architecture, combined with a novel authorization method through a stateful role-based firewall. Policy definition is based on high-level endpoints' role which can be dynamically updated and enforced directly on the centralized 802.1X authenticator. Our solution solves some outlined persistent challenges facing the traditional port-based access control method to provide an effective enterprise network access control solution, and also provides a platform that encourages network operators, equipment vendors and researchers to develop innovative alternatives to the current solutions.
FlowIdentity:软件定义的网络访问控制
软件定义网络(SDN)是一种通过解耦网络设备的控制和转发功能来构建计算机网络的新范式。这不仅为业界和研究人员提供了一个令人兴奋的机会来解决一些最持久的网络问题,而且还提供了一个环境,使创造性的网络应用程序和服务更容易开发和部署,以解决特定的业务需求。本文提出了一种基于OpenFlow协议的虚拟网络访问控制功能FlowIdentity。FlowIdentity在SDN架构中实现802.1X框架,结合一种新的授权方法,通过有状态的基于角色的防火墙。策略定义基于高级端点的角色,可以直接在集中式802.1X身份验证器上动态更新和强制执行。我们的解决方案解决了传统基于端口的访问控制方法所面临的一些持续挑战,提供了有效的企业网络访问控制解决方案,并提供了一个平台,鼓励网络运营商、设备供应商和研究人员开发当前解决方案的创新替代方案。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信