FlowIdentity: Software-defined network access control

FlowIdentity: Software-defined network access control
复制标题

FlowIdentity:软件定义的网络访问控制

DOI:
--
复制
发表时间:
2015
期刊:
Conference on Network Function Virtualization and Software Defined Network
影响因子:
--
通讯作者:
C. Guy
C. Guy
中科院分区:
--
文献类型:
--
作者:
S. Yakasai;C. Guy

文献摘要

被引文献

相似文献

软件定义网络(SDN)是通过解耦网络设备的控制和转发功能来构建计算机网络的新范例。这不仅为业界和研究人员提供了一个解决一些最持久的网络问题的令人兴奋的机会,而且还提供了一个更容易开发和部署创造性网络应用程序和服务的环境,以解决特定的业务需求。在本文中,我们提出了FlowIdentity -一个虚拟化的网络访问控制功能,使用OpenFlow协议。FlowIdentity在SDN架构中实现了802.1X框架,并结合一种新的基于状态的角色防火墙授权方法。策略定义基于高级端点的角色,可以在集中式802.1X以太网上直接动态更新和实施。我们的解决方案解决了传统的基于端口的访问控制方法所面临的一些持续挑战,提供了一个有效的企业网络访问控制解决方案,并提供了一个平台,鼓励网络运营商,设备供应商和研究人员开发创新的替代方案。
Software-Defined Networking (SDN) is a new paradigm for building computer networks through the decoupling of the control and forwarding functions of network devices. This has provided not only an exciting opportunity for the industry and researchers to solve some of the most persistent networking problems, but also an environment where creative network applications and services are more easily developed and deployed to solve specific business needs. In this paper, we present FlowIdentity - a virtualized network access control function using OpenFlow protocol. FlowIdentity implements 802.1X framework in SDN architecture, combined with a novel authorization method through a stateful role-based firewall. Policy definition is based on high-level endpoints' role which can be dynamically updated and enforced directly on the centralized 802.1X authenticator. Our solution solves some outlined persistent challenges facing the traditional port-based access control method to provide an effective enterprise network access control solution, and also provides a platform that encourages network operators, equipment vendors and researchers to develop innovative alternatives to the current solutions.