Improving the Security and Reliability of SDN Controller REST APIs Using JSON Web Token (JWT) with OpenID and auth2.0
Mahmoud F. ELHejazi, Wisam H. A Muragaa · 2024
As Software-Defined Networking (SDN) continues to gain popularity, the need for secure and efficient methods of authenticating users and controlling access to network resources becomes increasingly important. RESTful APIs are commonly used in SDN to enable communication between applications and network devices through the controllers. However, without proper authentication mechanisms, these APIs can be vulnerable to attacks such as injection and unauthorized access. This paper proposes lighter and reliable REST API authentication solution with less open configuration for Software-Defined Networking (SDN) controllers based on JSON Web Token (JWT), OpenID and auth2.0. The proposed solution offers a secure and efficient way to authenticate and authorize users, control access to network resources, and protect against injection attacks. It consists of generating a secret key, defining the JWT payload, generating the JWT, including the JWT in the HTTP Authorization header, verifying the JWT, extracting the payload from the JWT, and implementing token refresh. The solution is implemented using a combination of libraries in Python [requests-json-http.client] and tested on an SDN controller using a cisco DNA sandbox network environment. The results show that the proposed authentication solution is highly efficient and effective, making it suitable for use in high-performance SDN environments. It provides a much-needed solution for securing RESTful APIs in SDN controllers, and we hope that it will encourage further research in this area.