通信学报 ›› 2021, Vol. 42 ›› Issue (6): 131-144.doi: 10.11959/j.issn.1000-436x.2021079

• 学术论文 • 上一篇    下一篇

基于属性签名标识的SDN数据包转发验证方案

常朝稳, 金建树, 韩培胜, 祝现威   

  1. 信息工程大学,河南 郑州 450001
  • 修回日期:2021-03-01 出版日期:2021-06-25 发布日期:2021-06-01
  • 作者简介:常朝稳(1966− ),男,河南滑县人,博士,信息工程大学教授、博士生导师,主要研究方向为移动信息安全、物联网安全
    金建树(1992− ),男,辽宁锦州人,信息工程大学硕士生,主要研究方向为 SDN安全、网络安全
    韩培胜(1978− ),男,河北黄骅人,博士,信息工程大学教授,主要研究方向为网络安全、可信计算
    祝现威(1991− ),男,河南虞城人,信息工程大学博士生,主要研究方向为 SDN安全、网络安全、云计算安全
  • 基金资助:
    国家自然科学基金资助项目(61572517)

Software-defined network packet forwarding verification scheme based on attribute-based signatures identification

Chaowen CHANG, Jianshu JIN, Peisheng HAN, Xianwei ZHU   

  1. Information Engineering University, Zhengzhou 450001, China
  • Revised:2021-03-01 Online:2021-06-25 Published:2021-06-01
  • Supported by:
    The National Natural Science Foudation of China(61572517)

摘要:

针对软件定义网络(SDN)中数据包缺乏有效转发验证机制的问题,提出了一种基于属性签名标识的数据包转发验证方案。首先,根据用户的身份属性生成属性签名标识,并为数据包打上属性签名标识。然后,使用P4转发设备对数据包进行精确控制与采样,控制器对采样数据包进行属性签名验证,OpenFlow转发设备根据控制器下发的流表对转发异常的数据包进行处理。最后,构建了多控制器架构,避免了控制器单点失效故障。实验结果表明,所提方案实现了对数据包的精确控制与采样,能有效检测数据包篡改、伪造等异常行为,其网络时延处于可行通信时延范围内。

关键词: 软件定义网络, 属性签名, 转发验证, P4转发设备

Abstract:

Aiming at the lack of effective forwarding verification mechanism for packet in software defined network (SDN), a data packet forwarding verification scheme based on attributed-based signatures identification was proposed.First, the attribute signature identification was generated according to the user's identity attribute, and the data packet was marked by the attribute signature identification.Then, the P4 forwarding device was used to control accurately and sample the data packet.The controller verified the attribute signature of the sampled data packet.The OpenFlow forwarding device processes the abnormal data packets according to the flow table issued by the controller.Finally, a multi-controllers architecture was constructed to avoid the single point failure of the controller.The results of the experiment indicate that the scheme can achieve accurate control and sampling of data packet, effectively detect the forwarding abnormal behaviors such as packet tampering and forgery, and the network delay is within the range of feasible communication delay.

Key words: software-defined network, attribute signature, forwarding verification, P4 forwarding device

中图分类号: 

No Suggested Reading articles found!