首页 | 官方网站   微博 | 高级检索  
     

软件定义网络可信连接设计与实现
引用本文:李兆斌,刘梦甜,魏占祯,王守融.软件定义网络可信连接设计与实现[J].计算机应用研究,2019,36(3).
作者姓名:李兆斌  刘梦甜  魏占祯  王守融
作者单位:北京电子科技学院,北京,100070;北京电子科技学院,北京,100070;北京电子科技学院,北京,100070;北京电子科技学院,北京,100070
基金项目:国家重点研发计划项目(2017YFGX110123);中央高校基本科研业务专项资金项目(2017CL04);北京市自然科学基金资助项目(4152048)
摘    要:软件定义网络(software defined networking,SDN)将控制层和数据转发层分离,由控制层对数据转发层进行统一管理。目前控制层及数据转发层设备间完整性认证机制尚不完善,若平台完整性损坏的设备接入网络,会给整个SDN网络带来严重的安全问题。为确保双方设备在完整可信的前提下建立连接,进而在源头上保障设备安全、网络可信,提出了一种新的SDN可信连接方案。该方案以可信网络远程设备认证技术为基础,利用可信平台模块作为可信支撑,在SDN数据转发设备与控制器的连接过程中添加完整性认证环节。测试分析表明,该方案有效可行,符合实际应用。

关 键 词:软件定义网络  可信连接  完整性认证  网络安全
收稿时间:2017/9/20 0:00:00
修稿时间:2019/1/28 0:00:00

Design and realization of SDN trusted connection
Wei Zhanzhen,Liu Mengtian,Li Zhaobin and Wang Shourong.Design and realization of SDN trusted connection[J].Application Research of Computers,2019,36(3).
Authors:Wei Zhanzhen  Liu Mengtian  Li Zhaobin and Wang Shourong
Affiliation:Beijing Electronic Science Technology Institute,,,
Abstract:Software-Defined Networking separates the control layer and the data layer. Data forwarding is unified management by the control layer in SDN. However, equipment integrity authentication mechanism is not consummate between the control layer and the data layer. If the falsified equipment tries to connect the network, the whole network will face serious security problems. For ensuring that the connection was established after proving the equipment credible and integrated and that network is available, this paper proposed a project of trusted connection based on SDN. Combing the trusted network remote device authentication technology and using the trusted platform module as trusted support, the project added integrity certification to linking process of data forwarding devices and controllers. According to the?experiment, the project is suitable for actual network environment.
Keywords:software defined networking  trusted connection  integrated authentication  network security
本文献已被 万方数据 等数据库收录!
点击此处可从《计算机应用研究》浏览原始摘要信息
点击此处可从《计算机应用研究》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号