{"title":"Packet Access Control Mechanism Based on Cipher Identification in Software-defined Network","authors":"Xianwei Zhu, Chaowen Chang","doi":"10.1145/3357292.3357303","DOIUrl":null,"url":null,"abstract":"Software defined networking (SDN) decouples the controller plane from the data plane, offering flexible network configure and management. Because of this architecture, the SDN network is vulnerable to threats caused by user identity forgery, such as illegal intrusion and DDoS attacks. In this paper, we propose a control and forwarding mechanism based on cipher identification in SDN. All packets are encapsulated with cipher identification and signed by private keys based on cipher identification. In order to prevent the forged packets, mechanism verifies the signature at the entrance and exit of the network. The cipher identifier is designed as a matching field recognized by the SDN switch, and the network forwarding behavior is defined based on the cipher identifier.","PeriodicalId":115864,"journal":{"name":"Proceedings of the 2nd International Conference on Information Management and Management Sciences","volume":"32 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-08-23","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 2nd International Conference on Information Management and Management Sciences","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3357292.3357303","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2
Abstract
Software defined networking (SDN) decouples the controller plane from the data plane, offering flexible network configure and management. Because of this architecture, the SDN network is vulnerable to threats caused by user identity forgery, such as illegal intrusion and DDoS attacks. In this paper, we propose a control and forwarding mechanism based on cipher identification in SDN. All packets are encapsulated with cipher identification and signed by private keys based on cipher identification. In order to prevent the forged packets, mechanism verifies the signature at the entrance and exit of the network. The cipher identifier is designed as a matching field recognized by the SDN switch, and the network forwarding behavior is defined based on the cipher identifier.