Virtual Secure Link over Software-Defined Bridged Networks

Ju-Ho Choi · International Journal of Cloud-Computing and Super-Computing · 2019

Ethernet can transfer massive data stream flows as well as real-time flows supported by Time-Sensitive Network (TSN).The MAC layer security, MACsec, is defined at IEEE Std 802.1AE and IEEE Std 802.1X.However, a security association established by MACsec protects the communication among devices within single LAN at bridged networks.Therefore, a packet traversing several LANs must be decrypted and re-encrypted at each bridge.We propose a new virtual secure link over the Software-Defined Bridged Networks (SDBN).In SDBN, end-devices interact with the central MACsec module, running over the Software-Defined Network (SDN) controller, using the standard MACsec procedure.The central MACsec module recognizes a group of devices at the bridged networks regardless of their attached LANs.These devices are treated as they are attached to the same virtual link.The proposed scheme supports end-to-end unicast/multicast secure communication without any modification of the current MACsec standards as well as eliminating the security operation required at bridges in bridged networks.

Read the paper · More papers on PaperTik