Journal on Communications ›› 2021, Vol. 42 ›› Issue (6): 131-144.doi: 10.11959/j.issn.1000-436x.2021079

• Papers • Previous Articles     Next Articles

Software-defined network packet forwarding verification scheme based on attribute-based signatures identification

Chaowen CHANG, Jianshu JIN, Peisheng HAN, Xianwei ZHU   

  1. Information Engineering University, Zhengzhou 450001, China
  • Revised:2021-03-01 Online:2021-06-25 Published:2021-06-01
  • Supported by:
    The National Natural Science Foudation of China(61572517)

Abstract:

Aiming at the lack of effective forwarding verification mechanism for packet in software defined network (SDN), a data packet forwarding verification scheme based on attributed-based signatures identification was proposed.First, the attribute signature identification was generated according to the user's identity attribute, and the data packet was marked by the attribute signature identification.Then, the P4 forwarding device was used to control accurately and sample the data packet.The controller verified the attribute signature of the sampled data packet.The OpenFlow forwarding device processes the abnormal data packets according to the flow table issued by the controller.Finally, a multi-controllers architecture was constructed to avoid the single point failure of the controller.The results of the experiment indicate that the scheme can achieve accurate control and sampling of data packet, effectively detect the forwarding abnormal behaviors such as packet tampering and forgery, and the network delay is within the range of feasible communication delay.

Key words: software-defined network, attribute signature, forwarding verification, P4 forwarding device

CLC Number: 

No Suggested Reading articles found!