Publication:
Analysis and practical validation of a standard SDN-based framework for IPsec management

dc.contributor.authorMarín-López, Rafael
dc.contributor.authorCánovas, Óscar
dc.contributor.authorParra-Espín, José Antonio
dc.contributor.authorLópez Millán, Gabriel
dc.contributor.authorPereñíguez García, Fernando
dc.contributor.departmentIngeniería y Tecnología de Computadores
dc.date.accessioned2024-01-28T09:26:18Z
dc.date.available2024-01-28T09:26:18Z
dc.date.issued2023-01
dc.description©2023. This manuscript version is made available under the CC-BY-NC-ND 4.0 license http://creativecommons.org/licenses/by-nc-nd/4.0/ This document is the Accepted, version of a Published Work that appeared in final form in Computer Standards & Interfaces. To access the final edited and published work see https://doi.org/10.1016/j.csi.2022.103665es
dc.description.abstractThe Internet Engineering Task Force (IETF), the international standardization organism for the Internet, has recently approved a standard, RFC 9061, which defines an interface and framework with which to manage IPsec SAs autonomously by using the Software Defined Networking (SDN) paradigm. In this framework, a centralized entity, the controller, sends configuration information to IPsec-enabled nodes in the network in order to create IPsec SAs. Two cases are presented: IKE-case, in which the nodes ship an IKE implementation that is configured by the controller or IKE-less, in which the controller sends the IPsec SAs directly to the nodes, among other relevant security information. This paper analyzes both cases in depth, provides a design for the controller’s operation based on Mealy state machines and obtains experimental results from a virtualized testbed so as to compare these cases, which are missing parts in the standard.es
dc.formatapplication/pdfes
dc.format.extent21es
dc.identifier.citationComputer Standards & Interfaces, Volume 83, January 2023
dc.identifier.doihttps://doi.org/10.1016/j.csi.2022.103665
dc.identifier.issn1872-7018
dc.identifier.issn0920-5489
dc.identifier.urihttp://hdl.handle.net/10201/137869
dc.languageenges
dc.publisherElsevieres
dc.relationSin financiación externa a la Universidades
dc.relation.ispartofUniversity of Murcia’s project 33713-”Gestión automática de canales de comunicación seguros mediante el paradigma de redes definidas por software ”es
dc.relation.publisherversionhttps://www.sciencedirect.com/science/article/pii/S0920548922000393es
dc.rightsinfo:eu-repo/semantics/openAccesses
dc.rightsAttribution-NonCommercial-NoDerivatives 4.0 Internacional*
dc.rights.urihttp://creativecommons.org/licenses/by-nc-nd/4.0/*
dc.subjectIPSeces
dc.subjectIKE Managementes
dc.subjectSDNes
dc.subjectPerformancees
dc.titleAnalysis and practical validation of a standard SDN-based framework for IPsec managementes
dc.typeinfo:eu-repo/semantics/articlees
dspace.entity.typePublicationes
relation.isAuthorOfPublication95fd6dd8-97d5-4335-a962-f693b20779ba
relation.isAuthorOfPublication11194db1-33ae-4229-8840-6821d0de651e
relation.isAuthorOfPublication.latestForDiscovery95fd6dd8-97d5-4335-a962-f693b20779ba
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
1-s2.0-S0920548922000393-main.pdf
Size:
2.91 MB
Format:
Adobe Portable Document Format
Description:
License bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
2.26 KB
Format:
Item-specific license agreed upon to submission
Description:
Collections