• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

一种新颖的软件定义网络分组安全隧道转发机制。

A novel software-defined network packet security tunnel forwarding mechanism.

机构信息

Zhengzhou Institute of Information Science and Technology, Zhengzhou, 450001, China.

出版信息

Math Biosci Eng. 2019 May 17;16(5):4359-4381. doi: 10.3934/mbe.2019217.

DOI:10.3934/mbe.2019217
PMID:31499666
Abstract

The OpenFlow protocol match field capacity is fixed and limited, and packet forwarding in software-defined network lacks valid authentication of data source, integrity verification, and confidentiality protection mechanism. OpenFlow only supports the MPLS label tunnel establishment, and therefore cannot establish a secure tunnel flexibly. In order to solve these problems, we propose P4Sec, a novel software-defined network packet security tunnel forwarding mechanism. As P4 allows the data plane to be reprogrammed to realize the characteristics of packet forwarding, we build a software-defined network security tunnel to prevent data malicious tampering, stealing, forgery and other malicious network behavior, implementing packet routing and forwarding based on gateway identity. Finally, we construct a P4Sec prototype system based on the software switch BMv2, verify the effectiveness of the mechanism through experimental analysis, and evaluate the overhead of the mechanism. The results demonstrate that P4Sec security mechanism ensure the authenticity, integrity, and confidentiality of forwarded data, and realize the secure forwarding requirements of data packets in software-defined network.

摘要

OpenFlow 协议匹配字段的容量是固定且有限的,软件定义网络中的数据包转发缺乏对数据源的有效身份验证、完整性验证和机密性保护机制。OpenFlow 仅支持 MPLS 标签隧道的建立,因此无法灵活地建立安全隧道。为了解决这些问题,我们提出了 P4Sec,一种新颖的软件定义网络数据包安全隧道转发机制。由于 P4 允许数据平面被重新编程以实现数据包转发的特性,我们构建了一个软件定义网络安全隧道,以防止数据的恶意篡改、窃取、伪造等恶意网络行为,基于网关身份实现数据包的路由和转发。最后,我们基于软件交换机 BMv2 构建了一个 P4Sec 原型系统,通过实验分析验证了该机制的有效性,并评估了该机制的开销。结果表明,P4Sec 安全机制确保了转发数据的真实性、完整性和机密性,并实现了软件定义网络中数据包的安全转发要求。

相似文献

1
A novel software-defined network packet security tunnel forwarding mechanism.一种新颖的软件定义网络分组安全隧道转发机制。
Math Biosci Eng. 2019 May 17;16(5):4359-4381. doi: 10.3934/mbe.2019217.
2
Attribute identification based IoT fog data security control and forwarding.基于属性识别的物联网雾数据安全控制与转发
PeerJ Comput Sci. 2023 Dec 20;9:e1747. doi: 10.7717/peerj-cs.1747. eCollection 2023.
3
A data plane security model of segmented routing based on SDP trust enhancement architecture.一种基于SDP信任增强架构的分段路由数据平面安全模型。
Sci Rep. 2022 May 24;12(1):8762. doi: 10.1038/s41598-022-12858-2.
4
Secure multi-path routing for Internet of Things based on trust evaluation.基于信任评估的物联网安全多路径路由
Math Biosci Eng. 2024 Feb 4;21(2):3335-3363. doi: 10.3934/mbe.2024148.
5
FuGeF: A Resource Bound Secure Forwarding Protocol for Wireless Sensor Networks.FuGeF:一种用于无线传感器网络的资源受限安全转发协议
Sensors (Basel). 2016 Jun 22;16(6):943. doi: 10.3390/s16060943.
6
DoSGuard: Mitigating Denial-of-Service Attacks in Software-Defined Networks.DoSGuard:缓解软件定义网络中的拒绝服务攻击
Sensors (Basel). 2022 Jan 29;22(3):1061. doi: 10.3390/s22031061.
7
Detection of malicious consumer interest packet with dynamic threshold values.使用动态阈值检测恶意消费者兴趣包。
PeerJ Comput Sci. 2021 Mar 17;7:e435. doi: 10.7717/peerj-cs.435. eCollection 2021.
8
TrustBlock: An adaptive trust evaluation of SDN network nodes based on double-layer blockchain.TrustBlock:基于双层区块链的 SDN 网络节点自适应信任评估。
PLoS One. 2020 Mar 10;15(3):e0228844. doi: 10.1371/journal.pone.0228844. eCollection 2020.
9
Mechanism to prevent the abuse of IPv6 fragmentation in OpenFlow networks.防止 OpenFlow 网络中 IPv6 分片滥用的机制。
PLoS One. 2020 May 11;15(5):e0232574. doi: 10.1371/journal.pone.0232574. eCollection 2020.
10
PHACK: An Efficient Scheme for Selective Forwarding Attack Detection in WSNs.PHACK:一种用于无线传感器网络中选择性转发攻击检测的高效方案。
Sensors (Basel). 2015 Dec 9;15(12):30942-63. doi: 10.3390/s151229835.