Netinfo Security ›› 2016, Vol. 16 ›› Issue (12): 13-18.doi: 10.3969/j.issn.1671-1122.2016.12.003

• Orginal Article • Previous Articles     Next Articles

A Secure Fault Recovery Approach Using OwnShip-Proof Model for Controller Cluster of Software Defined Networks

Zehui WU1,2(), Qiang WEI1,2   

  1. 1. Institute of Cyber Security, PLA Information Engineering University, Zhengzhou Henan 450001, China
    2. State Key Laboratory of Mathematical Engineering and Advanced Computing, Zhengzhou Henan 450001, China
  • Received:2016-11-15 Online:2016-12-20 Published:2020-05-13

Abstract:

Control plane is the core of software defined network, which is responsible for network management and control. Current research focus on the performance, the stability, and the security of controllers, while take no attention on the security of fault recovery progress, by which the attackers could pretend to be a controller and obtain the resources of the network from the backups of control plane. We propose a secure recovery approach based on OwnShip-Proof model to address this threat. Our method employs hash tree to map one backup file with different controllers before backup and recovery procedure, and during the recovery, the controller should provide the solution of the challenge generated through OwnShip-Proof model by the server that stored the backup file. Then the server verify the solution and decide to recovery or not. The testing results show that our approach is able to decrease the memory space used to store the backup file and defense the attackers from the forged recovery attack. Compared with the ordinary method, the performance difference of the two methods would narrow down with the increasing of the size of the backup file.

Key words: SDN, cyber security, fault recovery, controller cluster

CLC Number: