Analysis and practical validation of a standard SDN-based framework for IPsec management

被引:11
作者
Lopez-Millan, Gabriel [1 ,4 ]
Marin-Lopez, Rafael [1 ]
Pereniguez-Garcia, Fernando [2 ]
Canovas, Oscar [3 ]
Espin, Jose Antonio Parra [1 ]
机构
[1] Univ Murcia, Dept Informat & Commun Engn, Murcia 30100, Spain
[2] Univ Def Ctr Spanish Air Force Acad, Dept Engn & Appl Technol, Murcia 30720, Spain
[3] Univ Murcia, Dept Comp Engn, Murcia 30100, Spain
[4] Fac Informat, Campus Espinardo S-N, Murcia 30100, Spain
关键词
IPSec; IKE; Management; SDN; Performance;
D O I
10.1016/j.csi.2022.103665
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The Internet Engineering Task Force (IETF), the international standardization organism for the Internet, has recently approved a standard, RFC 9061, which defines an interface and framework with which to manage IPsec SAs autonomously by using the Software Defined Networking (SDN) paradigm. In this framework, a centralized entity, the controller, sends configuration information to IPsec-enabled nodes in the network in order to create IPsec SAs. Two cases are presented: IKE-case, in which the nodes ship an IKE implementation that is configured by the controller or IKE-less, in which the controller sends the IPsec SAs directly to the nodes, among other relevant security information.This paper analyzes both cases in depth, provides a design for the controller's operation based on Mealy state machines and obtains experimental results from a virtualized testbed so as to compare these cases, which are missing parts in the standard.
引用
收藏
页数:13
相关论文
共 43 条
[31]  
RedHat OpenShift, ENCRYPTING TRAFFIC N
[32]  
Schonwalder J, 2011, 6241 RFC, DOI [10.17487/RFC6241, DOI 10.17487/RFC6241]
[33]  
Shafer P., 2011, RFC 6244
[34]  
Sont J, 2017, 2017 USENIX ANNUAL TECHNICAL CONFERENCE (USENIX ATC '17), P473
[35]  
Sousa E., 2018, 2018 IEEE C NETWORK, P1, DOI [10.1109/NFV-SDN.2018.8725675, DOI 10.1109/NFV-SDN.2018.8725675]
[36]   Toward Highly Available and Scalable Software Defined Networks for Service Providers [J].
Suh, Dongeun ;
Jang, Seokwon ;
Han, Sol ;
Pack, Sangheon ;
Kim, Myung-Sup ;
Kim, Taehong ;
Lim, Chang-Gyu .
IEEE COMMUNICATIONS MAGAZINE, 2017, 55 (04) :100-107
[37]  
Tafreshi Vahid Heydari Fami, 2014, ZTE Communications, V12, P41, DOI 10.3969/j.issn.1673-5188.2014.02.007
[38]  
The Open Networking Foundation, 2015, Standard ONF TS-025
[39]  
Tran K.N., 2016, IPSEC DRAFT TRAN IPS
[40]   IPsec and IKE as Functions in SDN Controlled Network [J].
Vajaranta, Markku ;
Kannisto, Joona ;
Harju, Jarmo .
NETWORK AND SYSTEM SECURITY, 2017, 10394 :521-530