信息网络安全 ›› 2014, Vol. 14 ›› Issue (9): 6-6.doi: 10.3969/j.issn.1671-1122.2014.09.002

• Orginal Article • Previous Articles     Next Articles

Solution for Rule Conflict under Distributed SDN Controller System

WANG Xin1, 2, 3, GAO Neng1, 2, MA Cun-qing1, 2, XUE Cong1, 2, 3   

  1. 1. Institute of Information Engineering, Chinese Academy of Sciences, Beijing 100093, China;
    2.State Key Laboratory of Information Security, Beijing 100093, China;
    3. University of Chinese Academy of Sciences, Beijing 100049, China
  • Received:2014-08-06 Online:2014-09-01

Abstract: The distributed SDN controller system has become the research focus, but the distributed architecture also introduces new security challenges, one of which is how to efficiently detect and reconcile the potential conflicting flow rules imposed by dynamic applications. By researching the conflict solution strategy FortNox with SDN single controller, in this paper we propose one kind of conflict resolution mechanism for the distributed SDN controller system. The scheme extends FortNox into distributed system, and adds controller rule conflict resolution mechanism based on end-to-end path and adds the bootstrap process of new controller so as to determine the conflict of flow rules in the distributed system. Our simulations show that it can not only check flow rule conflict in real time under distributed system, but is also effective to stop adversarial application inserting flow rules to bypass the security flow rules.

Key words: SDN, rule conflict, distributed SDN controller system