BENBI: Scalable and Dynamic Access Control on the Northbound Interface of SDN-Based VANET
Autor: | Jiasi Weng, Weiming Lan, Weiqi Luo, Jian Weng, Yue Zhang |
---|---|
Rok vydání: | 2019 |
Předmět: |
Vehicular ad hoc network
Northbound interface Computer Networks and Communications Computer science business.industry Aerospace Engineering 020302 automobile design & engineering Access control 02 engineering and technology Encryption 0203 mechanical engineering Automotive Engineering Scalability Electrical and Electronic Engineering business Broadcast encryption Computer network |
Zdroj: | IEEE Transactions on Vehicular Technology. 68:822-831 |
ISSN: | 1939-9359 0018-9545 |
DOI: | 10.1109/tvt.2018.2880238 |
Popis: | Recently, emerging SDN-based VANET (i.e., vehicular ad hoc network based on software-defined networking) enables VANET management to be programmable and flexible. It introduces SDN controllers to maintain network-wide resources and SDN applications to program configurations through arbitrarily accessing resources via the northbound interface (NBI). However, this brings with it security issues on the NBI, such as network-wide resource exposure and configuration manipulation. Most of the existing works employed permission systems to restrict resource access; these solutions are generally controller-dependent, which means controller codes need to be modified for giving access permissions to external applications. In this paper, we propose a scalable and dynamic access control scheme on the NBI for SDN-based VANET, named BENBI. In the proposed scheme, we dynamically and flexibly control network resources by employing broadcast encryption, rather than altering source codes of the controller or updating permission lists with various degrees of granularity. Moreover, the resources are encrypted during transmission so that they are only available to authorized applications. Finally, we implement a prototype of BENBI. The experimental results demonstrate that the cost of allocating secret keys is independent of the number of SDN entities being appointed, which indicates the scalability of our scheme. |
Databáze: | OpenAIRE |
Externí odkaz: |