DocumentCode
710602
Title
Towards an access control scheme for accessing flows in SDN
Author
Klaedtke, Felix ; Karame, Ghassan O. ; Bifulco, Roberto ; Heng Cui
Author_Institution
NEC Labs. Eur., Heidelberg, Germany
fYear
2015
fDate
13-17 April 2015
Firstpage
1
Lastpage
6
Abstract
Sharing network resources with user groups, divisions, or even other companies in software defined networking promises better network utilization. Resource sharing is effectively realized by empowering these tenants at the control plane with permissions for administrating network components. However, since the network resources at the data plane are shared and different tenants can have competing objectives, mechanisms are needed to protect the network resources from unauthorized access. In this paper, we propose mechanisms that focus on protecting the network flows, which are determined by the entries installed in the flow tables of the shared switches. To this end, we present an access control scheme, based on the OpenFlow model, for accessing the switches´ flow tables and their entries. Our scheme accounts for various security requirements in multi-tenant networks, including requirements on sharing flow table entries for handling network flows, and the resolution of conflicts originating from the reconfiguration of network components.
Keywords
authorisation; software defined networking; OpenFlow model; SDN; access control scheme; data plane; multitenant networks; network components; network flows; network resources; network utilization; resource sharing; security requirements; shared switches; software defined networking; switches flow tables; unauthorized access; user groups; Access control; Aerospace electronics; Control systems; Frequency selective surfaces; IP networks; Monitoring; Ports (Computers); Access control; Network flows; OpenFlow; Reference monitor; Software defined networking;
fLanguage
English
Publisher
ieee
Conference_Titel
Network Softwarization (NetSoft), 2015 1st IEEE Conference on
Conference_Location
London
Type
conf
DOI
10.1109/NETSOFT.2015.7116185
Filename
7116185
Link To Document