AuthFlow: authentication and access control mechanism for software defined networking

被引:0
作者
Diogo Menezes Ferrazani Mattos
Otto Carlos Muniz Bandeira Duarte
机构
[1] Universidade Federal do Rio de Janeiro (COPPE/UFRJ),Grupo de Teleinformática e Automação
[2] Sorbonne Universities,Laboratoire d’Informatique de Paris 6
来源
Annals of Telecommunications | 2016年 / 71卷
关键词
Access control; Authentication; Software-defined networking;
D O I
暂无
中图分类号
学科分类号
摘要
Software-defined networking (SDN) is being widely adopted by enterprise networks, whereas providing security features in these next generation networks is a challenge. In this article, we present the main security threats in software-defined networking and we propose AuthFlow, an authentication and access control mechanism based on host credentials. The main contributions of our proposal are threefold: (i) a host authentication mechanism just above the MAC layer in an OpenFlow network, which guarantees a low overhead and ensures a fine-grained access control; (ii) a credential-based authentication to perform an access control according to the privilege level of each host, through mapping the host credentials to the set of flows that belongs to the host; (iii) a new framework for control applications, enabling software-defined network controllers to use the host identity as a new flow field to define forwarding rules. A prototype of the proposed mechanism was implemented on top of POX controller. The results show that AuthFlow denies the access of hosts either without valid credentials or with revoked authorization. Finally, we show that our scheme allows, for each host, different levels of access to network resources according to its credential.
引用
收藏
页码:607 / 615
页数:8
相关论文
共 45 条
[11]  
Couto RS(undefined)undefined undefined undefined undefined-undefined
[12]  
Carvalho HET(undefined)undefined undefined undefined undefined-undefined
[13]  
Campista MEM(undefined)undefined undefined undefined undefined-undefined
[14]  
Costa LHMK(undefined)undefined undefined undefined undefined-undefined
[15]  
Duarte OCMB(undefined)undefined undefined undefined undefined-undefined
[16]  
Filasiak R(undefined)undefined undefined undefined undefined-undefined
[17]  
Grzenda M(undefined)undefined undefined undefined undefined-undefined
[18]  
Luckner M(undefined)undefined undefined undefined undefined-undefined
[19]  
Zawistowski P(undefined)undefined undefined undefined undefined-undefined
[20]  
Hudson DL(undefined)undefined undefined undefined undefined-undefined