An Open Horizontal Model for Group Management and End-to-End Security Management Suitable for Group-based Private Systems
Enrique D. Festijo, Younchan Jung · 2016
This paper proposes an open horizontal model for group management and end-to-end security management suitable for group-based private systems. The overlay network controller (ONC), which is located at the control layer, acts as an SDN controller capable of handling network functions such as group management and end-to-end security management. For group management, we propose a group-based private system that uses unicast method within the overlay network for distributing the signaling messages among the group members and is based on scalable architecture, that is, centralized and network independent. While the group key management is responsible for securing control signaling messages within the group members, the purpose of the end-to-end security management is to protect the end-to-end data traffic within them. To achieve end-to-end security, this paper uses packet key scheme that collaborates with the group key management. The members of the group-based private system are allowed to receive packet key scheme service for their end-to-end data traffic. The packet key scheme is based on the idea that a relatively small key size can be used as long as it provides high level of security and satisfy the latency requirements especially for real-time applications. The proposed scheme is evaluated based on the communication load and computational load requirement on both the ONC and mobile hosts. The security strength of the proposed packet key scheme is also analyzed.