Netinfo Security ›› 2018, Vol. 18 ›› Issue (4): 23-31.doi: 10.3969/j.issn.1671-1122.2018.04.004

• Orginal Article • Previous Articles     Next Articles

Research on SDN Terminal Access Control Based on OpenFlow

Zhanzhen WEI, Shourong WANG(), Zhaobin LI, Weilong LI   

  1. Beijing Electronic Science Technology Institute, Beijing 100070, China
  • Received:2018-01-27 Online:2018-04-15 Published:2020-05-11

Abstract:

In order to solve the security access problem of SDN terminal based on OpenFlow, an in-depth study of terminal secure access solutions in existing SDN networks is conducted, this paper proposes an network terminal access control system for SDN based on OpenFlow. The system drew on the traditional access control technology combined with the new SDN network based on OpenFlow. It mainly realized the functions of user identity authentication, terminal security status evaluation, authorized services for the user and different QoS control for authorized users in SDN networked environment and analyzed the security of the design system in detail. The network simulation is carried out in Mininet with the second developed RYU controller, and the experiments of access control function test and communication delay performance are carried out. The results showed that this mechanism had a flexible network access control security policy to detect and solved the security threats posed by unsafe terminal access in SDN, which not only realized the user identity authentication but also ensured the security of access terminal and achieved different security status of the terminal’s access authorization. Moreover, the performance test results shows that the OpenFlow-based SDN network terminal access control system can meet the actual needs in terms of authentication delay, platform evaluation delay and communication delay.

Key words: SDN, OpenFlow, terminal access control, authentication, service authorization

CLC Number: