Packet Access Control Mechanism Based on Cipher Identification in Software-defined Network

Xianwei Zhu, Chaowen Chang
{"title":"Packet Access Control Mechanism Based on Cipher Identification in Software-defined Network","authors":"Xianwei Zhu, Chaowen Chang","doi":"10.1145/3357292.3357303","DOIUrl":null,"url":null,"abstract":"Software defined networking (SDN) decouples the controller plane from the data plane, offering flexible network configure and management. Because of this architecture, the SDN network is vulnerable to threats caused by user identity forgery, such as illegal intrusion and DDoS attacks. In this paper, we propose a control and forwarding mechanism based on cipher identification in SDN. All packets are encapsulated with cipher identification and signed by private keys based on cipher identification. In order to prevent the forged packets, mechanism verifies the signature at the entrance and exit of the network. The cipher identifier is designed as a matching field recognized by the SDN switch, and the network forwarding behavior is defined based on the cipher identifier.","PeriodicalId":115864,"journal":{"name":"Proceedings of the 2nd International Conference on Information Management and Management Sciences","volume":"32 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-08-23","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 2nd International Conference on Information Management and Management Sciences","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3357292.3357303","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

Software defined networking (SDN) decouples the controller plane from the data plane, offering flexible network configure and management. Because of this architecture, the SDN network is vulnerable to threats caused by user identity forgery, such as illegal intrusion and DDoS attacks. In this paper, we propose a control and forwarding mechanism based on cipher identification in SDN. All packets are encapsulated with cipher identification and signed by private keys based on cipher identification. In order to prevent the forged packets, mechanism verifies the signature at the entrance and exit of the network. The cipher identifier is designed as a matching field recognized by the SDN switch, and the network forwarding behavior is defined based on the cipher identifier.
软件定义网络中基于密码识别的分组访问控制机制
软件定义网络(SDN)将控制平面与数据平面解耦,提供灵活的网络配置和管理。由于这种架构,SDN网络容易受到用户身份伪造的威胁,如非法入侵和DDoS攻击。本文提出了一种基于密码识别的SDN控制和转发机制。所有数据包都用密码标识封装,并基于密码标识用私钥签名。为了防止伪造报文,在网络的入口和出口进行签名验证机制。将密码标识符设计为SDN交换机识别的匹配字段,并根据密码标识符定义网络转发行为。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信