arXiv · 1806.07302
Trust Anchors in Software Defined Networks
Abstract
Advances in software virtualization and network processing lead to increasing network softwarization. Software network elements running on commodity platforms replace or complement hardware components in cloud and mobile network infrastructure. However, such com- modity platforms have a large attack surface and often lack granular control and tight integration of the underlying hardware and software stack. Often, software network elements are either themselves vulnerable to software attacks or can be compromised through the bloated trusted computing base. To address this, we protect the core security assets of network elements - authentication credentials and cryptographic context - by provisioning them to and maintaining them exclusively in isolated execution environments. We complement this with a secure and scalable mechanism to enroll network elements into software defined networks. Our evaluation results show a negligible impact on run-time performance and only a moderate performance impact at the deployment stage.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Nicolae Paladi, Linus Karlsson, Khalid Elbashir. 2018-06-19. Trust Anchors in Software Defined Networks. https://doi.org/10.1007/978-3-319-98989-1_24
Cite the original work for its findings. Save a collection to share your selection of sources.