2018
DOI: 10.3390/fi10060046
|View full text |Cite
|
Sign up to set email alerts
|

A Tiered Control Plane Model for Service Function Chaining Isolation

Abstract: This article presents an architecture for encryption automation in interconnected Network Function Virtualization (NFV) domains. Current NFV implementations are designed for deployment within trusted domains, where overlay networks with static trusted links are utilized for enabling network security. Nevertheless, within a Service Function Chain (SFC), Virtual Network Function (VNF) flows cannot be isolated and end-to-end encrypted because each VNF requires direct access to the overall SFC data-flow. This rest… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
2
1

Citation Types

0
17
0

Year Published

2019
2019
2023
2023

Publication Types

Select...
4
2

Relationship

2
4

Authors

Journals

citations
Cited by 6 publications
(17 citation statements)
references
References 12 publications
0
17
0
Order By: Relevance
“…The second paper [2] explores the issue of creating isolated and dynamically secured overlay networks and overcoming the limitations of current NFV implementations that are designed for deployment within trusted domains, where overlay networks with static trusted links are utilized to enable network security. This is achieved by introducing a novel tiered architecture for the automated establishment of encrypted tunnels in NFV in a multi-domain environment.…”
Section: Contributionsmentioning
confidence: 99%
“…The second paper [2] explores the issue of creating isolated and dynamically secured overlay networks and overcoming the limitations of current NFV implementations that are designed for deployment within trusted domains, where overlay networks with static trusted links are utilized to enable network security. This is achieved by introducing a novel tiered architecture for the automated establishment of encrypted tunnels in NFV in a multi-domain environment.…”
Section: Contributionsmentioning
confidence: 99%
“…However, most of the underlying network protocols, such as Geneve [14] in NSX-T, are not capable of combining SR with micro-segmentation and flow-based encryption. Hence, we have in our previous work [3] suggested a new SFC header, based on an NSH extension that adds more granularity to the security aspect of an SFC. Correspondingly, we have in this paper developed a RESTconf based control plane for distributing the forwarding decisions of this new packet header.…”
Section: Related Workmentioning
confidence: 99%
“…In this paper, we combine this SD-SA encryption architecture [7] with our new SFC header [3] and a new flow distribution control plane. The security features of the architecture are verified by demonstrating how the requirements such as isolation and encryption comply with a use case scenario.…”
Section: Related Workmentioning
confidence: 99%
See 2 more Smart Citations