Expert report (Reports)
The KISS principle in Software-Defined Networking: An architecture for Keeping It Simple and Secure
Kreutz, Diego; Verissimo, Paulo; Magalhaes, Catia et al.
2017
 

Files


Full Text
the_sdn_kiss_arXiv_20171027.pdf
Publisher postprint (417.19 kB)
Download

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
software-defined networking; SDN; security; system architecture; control plane communications; performance of cryptographic primitives; integrated device verification value (iDVV); perfect forward secrecy
Abstract :
[en] Security is an increasingly fundamental requirement in Software-Defined Networking (SDN). However, the pace of adoption of secure mechanisms has been slow, which we estimate to be a consequence of the performance overhead of traditional solutions and of the complexity of the support infrastructure required. As a first step to addressing these problems, we propose a modular secure SDN control plane communications architecture, KISS, with innovative solutions in the context of key distribution and secure channel support. A comparative analysis of the performance impact of essential security primitives guided our selection of basic primitives for KISS. We further propose iDVV, the integrated device verification value, a deterministic but indistinguishable-from-random secret code generation protocol, allowing the local but synchronized generation/verification of keys at both ends of the channel, even on a per-message basis. iDVV is expected to give an important contribution both to the robustness and simplification of the authentication and secure communication problems in SDN. We show that our solution, while offering the same security properties, outperforms reference alternatives, with performance improvements up to 30% over OpenSSL, and improvement in robustness based on a code footprint one order of magnitude smaller. Finally, we also prove and test randomness of the proposed algorithms.
Research center :
Interdisciplinary Centre for Security, Reliability and Trust (SnT) > Critical and Extreme Security and Dependability Research Group (CritiX)
Disciplines :
Computer science
Author, co-author :
Kreutz, Diego ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Verissimo, Paulo ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Magalhaes, Catia
Ramos, Fernando M. V.
Language :
English
Title :
The KISS principle in Software-Defined Networking: An architecture for Keeping It Simple and Secure
Publication date :
2017
Focus Area :
Security, Reliability and Trust
European Projects :
H2020 - 643964 - SUPERCLOUD - USER-CENTRIC MANAGEMENT OF SECURITY AND DEPENDABILITY IN CLOUDS OF CLOUDS
FnR Project :
FNR8149128 - Strategic Rtnd Program On Information Infrastructure Security And Dependability, 2014 (01/01/2015-31/12/2021) - Marcus Völp
Name of the research project :
IIS&D - Information Infrastructure Security and Dependability
Funders :
FNR - Fonds National de la Recherche [LU]
CE - Commission Européenne [BE]
Available on ORBilu :
since 11 February 2018

Statistics


Number of views
111 (6 by Unilu)
Number of downloads
71 (5 by Unilu)

Bibliography


Similar publications



Contact ORBilu