【24h】

SDN-based Trusted Path Control

机译:基于SDN的受信任路径控制

获取原文
获取原文并翻译 | 示例

摘要

Security of sensitive data in the network is a key issue in a world where such sensitive data can easily be transferred between different servers and locations (e.g., in networked clouds). In this context, there is a particular need to control the path followed by the data when they move across the cloud (e.g., to avoid crossing -even encrypted- un-trusted nodes or areas). In this paper we proposed therefore a new approach which aims to leverage the programmability offered by the SDN technology in order to enforce a trusted path for the transfer of sensitive data in the network. Given a policy related to the sensitive data (e.g., the data should not cross a given area), our approach allows sending this policy to an extended SDN controller (called Trusted Path Controller) which automatically enforces this policy in the SDN network. Two architectures have been investigated: the Out-of-Band architecture (the policy being sent to the Trusted Path Controller via a Web Service interface) and the In-Band architecture (the policy being sent to the Trusted Path Controller via a dedicated “signaling packet”). These two architectures have been implemented in a SDN controller. Experimentations and evaluations have also been performed on a test-bed of SDN switches which allow showing the feasibility of this approach as well as its performances.
机译:在这样的敏感数据很容易在不同服务器和位置之间(例如,在联网的云中)之间传输的世界中,网络中敏感数据的安全性是一个关键问题。在这种情况下,特别需要控制数据在云中移动时所遵循的路径(例如,避免跨越甚至是加密的不可信节点或区域)。因此,在本文中,我们提出了一种旨在利用SDN技术提供的可编程性的新方法,以便为网络中的敏感数据的传输实施可信赖的路径。给定与敏感数据相关的策略(例如,数据不应跨越给定区域),我们的方法允许将该策略发送到扩展的SDN控制器(称为可信任路径控制器),后者会在SDN网络中自动执行此策略。已研究了两种体系结构:带外体系结构(通过Web服务接口将策略发送到受信路径控制器)和带内体系结构(通过专用的“信令”将策略发送给受信路径控制器)包”)。这两种架构已在SDN控制器中实现。还已经在SDN交换机的测试平台上进行了实验和评估,可以显示这种方法的可行性及其性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号