Author:
Wang Liang,Ma Hailong,Li Ziyong,Pei Jinchuan,Hu Tao,Zhang Jin
Abstract
AbstractFacing the untrusted threats of network elements and PKI/CA faced by SR-BE/TE (Segment Routing-BE/TE) data plane in the zero-trust network environment, firstly, this paper refines it into eight specific security issues. Secondly, an SR-BE/TE data plane security model ZbSR (ZTA-based SR) based on zero-trust architecture is proposed, which reconstructs the original SR control plane into a "trust-agent" two-layer plane based on 4 components of the controller, agent, cryptographic center and information base. On one hand, we distinguish between the two segment list generation modes and proposes corresponding data exchange security algorithms, by introducing north–south security verification based on identity authentication, trust evaluation, and key agreement before the terminal device establishes an east–west access connection, so reliable data exchange between terminal devices can be realized. On the other hand, for the network audit lacking SR-BE/TE, a network audit security algorithm based on solid authentication is proposed. By auditing the fields, behaviors, loops, labels, paths, and SIDs of messages, threats such as stream path tampering, SID tampering, DoS attacks, and loop attacks can be effectively detected. Finally, through the simulation test, the proposed model can provide security protection for the SR data plane with a 19.3% average incremental delay overhead for various threat scenarios.
Publisher
Springer Science and Business Media LLC
Reference44 articles.
1. Ventre, P. L. et al. Segment routing: A comprehensive survey of research activities, standardization efforts and implementation results. J. IEEE Commun. Surv. Tutor. 99, 1–1 (2020).
2. Clarence, F., Kris, M. & Ketan, T. Segment routing-part I (2017).
3. Pier, V. et al. Segment routing: A comprehensive survey of research activities, standardization efforts, and implementation results. J. IEEE Commun. Surv. Tutor. 23(1), 182–221 (2021).
4. Segment Routing over IPv6 (SRv6) Network Programming. RFC 8986:1-40 (2021).
5. Geng, H. Intra-domain routing protection scheme in segment routing architecture. J. Comput. Eng. Appl. 55(08), 80–85 (2019).
Cited by
2 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献