Rapport d’expertise (Rapports)
The KISS principle in Software-Defined Networking: An architecture for Keeping It Simple and Secure
KREUTZ, Diego; VERISSIMO, Paulo; Magalhaes, Catia et al.
2017
 

Documents


Texte intégral
the_sdn_kiss_arXiv_20171027.pdf
Postprint Éditeur (417.19 kB)
Télécharger

Tous les documents dans ORBilu sont protégés par une licence d'utilisation.

Envoyer vers



Détails



Mots-clés :
software-defined networking; SDN; security; system architecture; control plane communications; performance of cryptographic primitives; integrated device verification value (iDVV); perfect forward secrecy
Résumé :
[en] Security is an increasingly fundamental requirement in Software-Defined Networking (SDN). However, the pace of adoption of secure mechanisms has been slow, which we estimate to be a consequence of the performance overhead of traditional solutions and of the complexity of the support infrastructure required. As a first step to addressing these problems, we propose a modular secure SDN control plane communications architecture, KISS, with innovative solutions in the context of key distribution and secure channel support. A comparative analysis of the performance impact of essential security primitives guided our selection of basic primitives for KISS. We further propose iDVV, the integrated device verification value, a deterministic but indistinguishable-from-random secret code generation protocol, allowing the local but synchronized generation/verification of keys at both ends of the channel, even on a per-message basis. iDVV is expected to give an important contribution both to the robustness and simplification of the authentication and secure communication problems in SDN. We show that our solution, while offering the same security properties, outperforms reference alternatives, with performance improvements up to 30% over OpenSSL, and improvement in robustness based on a code footprint one order of magnitude smaller. Finally, we also prove and test randomness of the proposed algorithms.
Centre de recherche :
Interdisciplinary Centre for Security, Reliability and Trust (SnT) > Critical and Extreme Security and Dependability Research Group (CritiX)
Disciplines :
Sciences informatiques
Auteur, co-auteur :
KREUTZ, Diego ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
VERISSIMO, Paulo ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Magalhaes, Catia
Ramos, Fernando M. V.
Langue du document :
Anglais
Titre :
The KISS principle in Software-Defined Networking: An architecture for Keeping It Simple and Secure
Date de publication/diffusion :
2017
Focus Area :
Security, Reliability and Trust
URL complémentaire :
Projet européen :
H2020 - 643964 - SUPERCLOUD - USER-CENTRIC MANAGEMENT OF SECURITY AND DEPENDABILITY IN CLOUDS OF CLOUDS
Projet FnR :
FNR8149128 - Strategic Rtnd Program On Information Infrastructure Security And Dependability, 2014 (01/01/2015-31/12/2021) - Marcus Völp
Intitulé du projet de recherche :
IIS&D - Information Infrastructure Security and Dependability
Organisme subsidiant :
FNR - Fonds National de la Recherche
CE - Commission Européenne
Disponible sur ORBilu :
depuis le 11 février 2018

Statistiques


Nombre de vues
162 (dont 6 Unilu)
Nombre de téléchargements
134 (dont 5 Unilu)

Bibliographie


Publications similaires



Contacter ORBilu