ZT-XPN: An End-to-End Zero-Trust Architecture for Next Generation Programmable Networks

Charalampos Katsis, Elisa Bertino · 2025

Zero-trust architecture (ZTA) mandates strict internal and perimeter defenses, ensuring communication occurs solely on a per-request and need-only basis. Achieving this requires robust access control (AC) policies enforced throughout the network. Software-Defined Networks (SDN) and programmable data planes are crucial in implementing ZTA. SDN's centralized management streamlines access request authorization, while data plane programmability enables the direct execution of various tasks such as error checking and stateful AC. However, significant challenges persist. Administrators must define a comprehensive network-wide security policy that accommodates the communication needs of all endpoints, such as users, IoT and services. Moreover, they must manually design and deploy data plane programs to enforce these policies and separately orchestrate the control plane operations for centralized policy deployment, management, and monitoring. This paper presents ZT-XPN, the first end-to-end framework designed to address these challenges. ZT-XPN consists of three key components: (1) a graph-based policy specification tool that enables the precise and fine-grained definition of complex network-wide policies, allowing for detailed endpoint and protocol-level control; (2) a back-end compiler integrated with ONOS SDN controller that processes these requirements, automatically generating data plane programs and orchestrates the control plane to support those programs and (3) a runtime management system for policy management and runtime monitoring. We evaluate our architecture in an SDN network environment with varying scales, including end systems and BMv2 programmable switches. We also compare the performance of our approach with baseline open-source implementations for packet forwarding and a stateful firewall.

Read the paper · More papers on PaperTik