Devolving IEEE 802.1X authentication capability to data plane in software-defined networking (SDN) architecture

被引:6
作者
Benzekki, Kamal [1 ]
El Fergougui, Abdeslam [1 ]
El Alaoui, Abdelbaki El Belrhiti [1 ]
机构
[1] Moulay Ismail Univ, Fac Sci, Dept Math & Comp Sci, Lab Comp Networks & Syst, Meknes, Morocco
基金
欧盟地平线“2020”;
关键词
software-defined networking; IEEE 802.1X port-based authentication; network access; scalability;
D O I
10.1002/sec.1613
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software-defined networking (SDN) is a relatively new approach in network management that proposes to separate the network control (Control plane) and the forwarding process (Data plane) to optimize the network infrastructure and improve network performance, controllability, manageability and flexibility. However, like every technology, SDN has brought its own new challenges in terms of security and scalability which are very important aspects that should be considered to design and build a resilient architecture in order to meet carrier grade network requirements. In this paper, we propose a secure SDN architecture with IEEE 802.1X port-based authentication where we also consider the controller's scalability issue by devolving the access control capability to the data plane. In this way, we reduce the high demand and the workload on the SDN controller. Our proposed model presents a novel SDN network architecture and logical network segmentation which provides an optimal and secure network access with low latency. We have implemented and tested our architecture to show its performance (authentication delays). Copyright (C) 2016 John Wiley & Sons, Ltd.
引用
收藏
页码:4369 / 4377
页数:9
相关论文
共 22 条
[1]  
[Anonymous], 8021X IEEE
[2]  
[Anonymous], 2010, P 2010 INT NETW MAN
[3]  
[Anonymous], 3 EUR WORKSH SOFTW D
[4]  
[Anonymous], 2010, OSDI
[5]  
[Anonymous], ARXIV14086760
[6]  
Benton K., 2013, P 2 ACM SIGCOMM WORK, P151, DOI [DOI 10.1145/2491185.2491222, 10.1145/2491185.2491222]
[7]  
Cai Z, 2011, THESIS
[8]   DevoFlow: Scaling Flow Management for High-Performance Networks [J].
Curtis, Andrew R. ;
Mogul, Jeffrey C. ;
Tourrilhes, Jean ;
Yalagandula, Praveen ;
Sharma, Puneet ;
Banerjee, Sujata .
ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2011, 41 (04) :254-265
[9]   ElastiCon: An Elastic Distributed SDN Controller [J].
Dixit, Advait ;
Hao, Fang ;
Mukherjee, Sarit ;
Lakshman, T. V. ;
Kompella, Ramana Rao .
TENTH 2014 ACM/IEEE SYMPOSIUM ON ARCHITECTURES FOR NETWORKING AND COMMUNICATIONS SYSTEMS (ANCS'14), 2014, :17-27
[10]   Towards an Elastic Distributed SDN Controller [J].
Dixit, Advait ;
Hao, Fang ;
Mukherjee, Sarit ;
Lakshman, T. V. ;
Kompella, Ramana .
ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2013, 43 (04)