Chinese Journal of Network and Information Security ›› 2021, Vol. 7 ›› Issue (3): 59-71.doi: 10.11959/j.issn.2096-109x.2021035

• TopicⅡ: SDN and cloud computing security • Previous Articles     Next Articles

Verification on policies for network functions in SDN/NFV-based environment

Haoyu CHEN1,2,3, Deqing ZOU1,2,4, Hai JIN1,2,3   

  1. 1 National Engineering Research Center for Big Data Technology and System, School of Computer Science and Technology, Huazhong University of Science and Technology, Wuhan 430074, China
    2 Services Computing Technology and System Lab, School of Computer Science and Technology, Huazhong University of Science and Technology, Wuhan 430074, China
    3 Cluster and Grid Computing Lab, School of Computer Science and Technology, Huazhong University of Science and Technology, Wuhan 430074, China
    4 Hubei Engineering Research Center on Big Data Security, School of Cyber Science and Engineering, Huazhong University of Science and Technology, Wuhan 430074, China
  • Revised:2021-01-21 Online:2021-06-15 Published:2021-06-01
  • Supported by:
    The National Key R&D Program of China(2019YFB2101700);The Science and Technology Program of Guangzhou(201902020016)

Abstract:

Although the newly introduced SDN and NFV technologies bring flexibility and convenience in network management, the dynamic forwarding policies introduced by SDN may cause invalidation in the network function policies, and the policies in different network functions may also cause conflicts due to their own behaviors.In order to verify the policies in SDN/NFV-based cloud network, the verification on policies between the network function and the SDN device, as well as across the network functions were considered.A unified policy expression for analysis was summarized, and policy verification scheme, framework and prototype implementation were proposed to verify the correctness of polices in different scenarios, then experiments were conducted to justify the effectiveness and performance

Key words: policy verification, cloud network, software-defined networking, network function virtualization

CLC Number: 

No Suggested Reading articles found!