Suppr超能文献

一种新颖的软件定义网络分组安全隧道转发机制。

A novel software-defined network packet security tunnel forwarding mechanism.

机构信息

Zhengzhou Institute of Information Science and Technology, Zhengzhou, 450001, China.

出版信息

Math Biosci Eng. 2019 May 17;16(5):4359-4381. doi: 10.3934/mbe.2019217.

Abstract

The OpenFlow protocol match field capacity is fixed and limited, and packet forwarding in software-defined network lacks valid authentication of data source, integrity verification, and confidentiality protection mechanism. OpenFlow only supports the MPLS label tunnel establishment, and therefore cannot establish a secure tunnel flexibly. In order to solve these problems, we propose P4Sec, a novel software-defined network packet security tunnel forwarding mechanism. As P4 allows the data plane to be reprogrammed to realize the characteristics of packet forwarding, we build a software-defined network security tunnel to prevent data malicious tampering, stealing, forgery and other malicious network behavior, implementing packet routing and forwarding based on gateway identity. Finally, we construct a P4Sec prototype system based on the software switch BMv2, verify the effectiveness of the mechanism through experimental analysis, and evaluate the overhead of the mechanism. The results demonstrate that P4Sec security mechanism ensure the authenticity, integrity, and confidentiality of forwarded data, and realize the secure forwarding requirements of data packets in software-defined network.

摘要

OpenFlow 协议匹配字段的容量是固定且有限的,软件定义网络中的数据包转发缺乏对数据源的有效身份验证、完整性验证和机密性保护机制。OpenFlow 仅支持 MPLS 标签隧道的建立,因此无法灵活地建立安全隧道。为了解决这些问题,我们提出了 P4Sec,一种新颖的软件定义网络数据包安全隧道转发机制。由于 P4 允许数据平面被重新编程以实现数据包转发的特性,我们构建了一个软件定义网络安全隧道,以防止数据的恶意篡改、窃取、伪造等恶意网络行为,基于网关身份实现数据包的路由和转发。最后,我们基于软件交换机 BMv2 构建了一个 P4Sec 原型系统,通过实验分析验证了该机制的有效性,并评估了该机制的开销。结果表明,P4Sec 安全机制确保了转发数据的真实性、完整性和机密性,并实现了软件定义网络中数据包的安全转发要求。

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验