SDN-oriented trusted dynamic routing construction method and system
By building a trusted control plane and trusted path in the SDN architecture and combining it with incremental update routing table rules, the vulnerability of the SDN controller is resolved, and network security and performance are improved, especially in virtualized environments.
Patent Information
- Application Number
- CN202410441714.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-12
- Publication Date
- 2025-10-21
AI Technical Summary
SDN controllers are vulnerable to attacks, leading to network security risks, including tampering of traffic control, security policies, and routing. The communication links between controllers and switches are also vulnerable to man-in-the-middle attacks and data tampering.
Trusted computing technology is used to build a trusted control plane, and trusted platform modules and trusted execution environments are used to protect the integrity of the control plane. A trusted path between the data plane and the control plane is built through remote attestation technology to ensure the integrity of routing table information. At the same time, routing table rules are updated incrementally to reduce performance loss.
Effectively defend against attacks on SDN controllers and switch communication links, protect the integrity of routing table information, reduce performance loss, and ensure secure isolation and resource isolation of network function virtualization.
Smart Images

Figure CN120825440A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of network technology, and in particular relates to a trusted dynamic routing construction method and system for SDN. Background Art
[0002] Software-defined networking (SDN) is an innovative network architecture that separates network control from data forwarding, centralizing network management and control functions within a centralized controller. In traditional networks, network devices (such as switches and routers) typically have built-in control capabilities. In SDN, however, these network devices are considered data planes, with specific data forwarding tasks directed and managed by a controller. The controller uses communication protocols (such as OpenFlow) with network devices to achieve flexible control and management of the network. The advantage of this architecture is that it provides a higher level of network programming and management capabilities, making network configuration, monitoring, and optimization more convenient and flexible.
[0003] SDN architecture can be divided into infrastructure layer, control layer and application layer, such as Figure 1 As shown in the figure, the infrastructure layer primarily consists of forwarding devices, such as data center switches, that implement forwarding functions. The control layer consists of SDN control software, which communicates with forwarding devices using standardized protocols to control the infrastructure layer. Common application layer platforms include cloud platforms based on the OpenStack architecture. Alternatively, users can build their own cloud management platforms based on OpenStack. SDN uses northbound and southbound application programming interfaces (APIs) for communication between layers. Northbound APIs handle communication between the application layer and the control layer, while southbound APIs handle communication between the infrastructure layer and the control layer. In the SDN architecture, the SDN control plane plays a core role. It receives and processes control instructions from network administrators or upper-layer applications and generates corresponding forwarding rules based on these instructions. These forwarding rules describe the path and processing of packets within the network and can include multiple factors such as source address, destination address, and quality of service requirements. The control plane also monitors network status and traffic flow, dynamically adjusting and optimizing based on real-time network conditions. The data plane, which actually performs packet forwarding, consists of SmartNICs or DPUs. SmartNICs and DPUs offer programmable network interface cards (NICs), enabling high-performance packet forwarding based on forwarding rules generated by the control plane. These devices utilize high-speed data processing and forwarding technologies, capable of handling large volumes of data packets and rapidly forwarding them according to pre-set rules. The introduction of SmartNICs and DPUs makes data center network forwarding more efficient and customizable, meeting the needs of diverse application scenarios.
[0004] Traditional network interface cards (NICs) primarily send and receive data packets from a computer to the network, providing basic network connectivity. SmartNICs, on the other hand, build upon traditional NICs by integrating more processing power and intelligent features, providing more advanced support for network applications and management. First, SmartNICs offer more powerful processing capabilities. Traditional NICs are typically limited to simple network packet processing tasks, such as sending and receiving packets. SmartNICs, with their built-in processors and memory, are capable of performing more complex packet processing tasks, such as parsing, filtering, reassembly, and forwarding. This built-in processing power reduces the burden on the host and improves network performance and responsiveness. Second, SmartNICs support a wider range of network protocols and features. Traditional NICs typically only support basic network protocols, such as Ethernet and IP. SmartNICs, on the other hand, support more advanced network protocols and features, such as virtual local area networks (VLANs), load balancing, security encryption, traffic monitoring, and QoS (Quality of Service). These features enable SmartNICs to better meet diverse application scenarios and network requirements, providing more flexible and customizable network services. SmartNICs also offer more powerful management and monitoring capabilities. Traditional network adapters (NICs) typically require management and configuration through the host's operating system. SmartNICs, however, have built-in management interfaces and software, enabling configuration, monitoring, and troubleshooting independent of the host. Administrators can communicate with SmartNICs through the management interfaces to obtain network status, statistics, and event logs. This independent management capability simplifies network management, improving management efficiency and troubleshooting capabilities. SmartNICs also integrate and collaborate with other network devices and systems. By supporting open interfaces and standards, SmartNICs can communicate and collaborate with network switches, routers, firewalls, servers, and other devices. For example, SmartNICs can perform traffic control and load balancing with switches, negotiate and enforce security policies with firewalls, and efficiently transmit and process data with servers. This collaborative operation improves the performance and reliability of the entire network.
[0005] The Data Processing Unit (DPU) is an emerging hardware accelerator designed to provide high-performance and efficient data processing capabilities. A third processor option, alongside traditional central processing units (CPUs) and graphics processing units (GPUs), DPUs are specifically designed to accelerate data-intensive and compute-intensive applications. DPUs feature a unique processor architecture designed to maximize data processing throughput and efficiency. They play a vital role in data centers and network forwarding, providing more efficient and faster data processing capabilities through their high performance and dedicated hardware accelerators. Data centers typically carry large-scale computing, storage, and networking tasks, which often place extremely high demands on data processing capabilities. Through their highly parallel architecture and dedicated hardware accelerators, DPUs accelerate various computing tasks in data centers, providing faster data processing and response times. For example, in the field of artificial intelligence, DPUs can accelerate the training and inference of deep learning models through their specialized tensor processors, significantly improving the computational efficiency and performance of these models. Furthermore, DPUs can save energy and reduce operating costs for data centers through their efficient memory systems and energy-efficiency optimizations. The DPU also plays a vital role in network forwarding. Network forwarding, the process of sending data packets from one network node to another, is crucial to network performance and efficiency. The DPU, with its high-performance data processing capabilities and dedicated hardware accelerators, enables faster and more efficient network forwarding. It can parse and process various network protocols, including Ethernet, IP, TCP / UDP, and implement various network functions such as load balancing, security encryption, traffic monitoring, and QoS (Quality of Service). These capabilities enable the DPU to provide more flexible and customizable network services and improve network throughput, latency, and reliability. Furthermore, the DPU, with its dedicated cryptographic engine and security protocol processor, implements security functions such as encryption, decryption, and authentication of network data. It can execute various cryptographic algorithms to protect the confidentiality and integrity of network data. Furthermore, the DPU can monitor and analyze network traffic in real time to promptly detect and prevent potential network attacks and malicious activity.
[0006] The SDN controller is a key component in the SDN architecture, responsible for centrally managing and controlling the entire network. However, the centralized management of the SDN controller also introduces security risks and challenges. If the controller is attacked and compromised, the entire network will be severely impacted, including traffic control, security policies, and routing. This centralized risk makes the SDN controller a prime target for hackers, as a successful attack can cause widespread damage to the entire network. Specifically, the SDN controller must process and store a large amount of sensitive network information, such as topology information, security policies, and user credentials. Insecure coding practices and a lack of security awareness can lead to vulnerabilities and errors in the SDN controller software, which can be exploited by hackers to conduct remote attacks or perform malicious operations. If the controller itself is vulnerable to vulnerabilities or attacks, sensitive information can be stolen or tampered with, leading to serious security issues. If the controller is maliciously tampered with, hackers can also use it to perform malicious operations, such as modifying flow table rules, forging traffic, or initiating denial-of-service attacks. Furthermore, the SDN controller needs to communicate with the various switches in the network to transmit control commands and configuration information. However, these communication links can be vulnerable to threats such as man-in-the-middle attacks, data tampering, or information leakage. If the communication between the controller and the switch is attacked, hackers may interfere with or control network traffic, disrupting the normal operation of the network. Therefore, ensuring the security of the communication between the controller and the switch is crucial. Summary of the Invention
[0007] In response to the above problems, the present invention provides a method and system for constructing a trusted dynamic routing for SDN.
[0008] The technical solution adopted in the present invention is as follows:
[0009] A method for constructing a trusted dynamic routing for SDN includes the following steps:
[0010] Utilize trusted computing technology to build a trusted control plane to measure and protect the integrity of the control plane;
[0011] Build a trusted path between the data plane and the control plane based on remote attestation technology to ensure the integrity of routing table information;
[0012] By incrementally updating routing table rules, the performance loss introduced by remote attestation and encryption / decryption processes is reduced.
[0013] Furthermore, the use of trusted computing technology to build a trusted control plane includes:
[0014] Introducing trusted computing hardware modules into the SDN controller to form an SDN trusted controller;
[0015] Metrics code is embedded in the key components and code of the control plane. The metrics code is responsible for generating and recording metrics for the control plane. The integrity of the control plane is verified by comparing the metrics with pre-calculated expected values. If the metrics do not match the expected values, it indicates that the control plane may have been tampered with or attacked. Administrators monitor changes in metrics and take timely measures to address potential security threats.
[0016] Furthermore, the hardware module of the trusted computing is a trusted platform module TPM or a trusted execution environment TEE.
[0017] Furthermore, the construction of a trusted path between the data plane and the control plane based on remote attestation technology includes:
[0018] The routing table rules generated by the control plane are encrypted and encapsulated in secure messages, and then transmitted to the data plane through a trusted path. The trusted path is composed of trusted devices and communication channels between the control plane and the data plane. Remote attestation technology is used on the trusted path to verify the integrity and authenticity of the messages.
[0019] Furthermore, the use of remote attestation technology to verify the integrity and authenticity of the message includes:
[0020] The control plane generates a proof that proves the correctness of the routing table rules and sends the proof to the data plane along with the encrypted message;
[0021] After receiving the message, the data plane decrypts the message using the pre-shared key and uses the verified proof to verify the correctness of the routing table rules to ensure that the routing table information has not been tampered with or modified during transmission.
[0022] Furthermore, the updating of routing table rules in an incremental manner includes:
[0023] By recording the changes in each update and generating corresponding proofs, these changes and proofs are then sent to the data plane;
[0024] The data plane is only locally updated based on these changes without having to re-acquire and apply the complete routing table rules.
[0025] Furthermore, the above method implements network function virtualization and places the virtual network function VNF under the protection of a trusted platform or a trusted execution environment, ensuring security isolation and resource isolation of the virtualized environment.
[0026] A trusted dynamic routing construction system for SDN, comprising:
[0027] A trusted control plane construction unit, used to build a trusted control plane using trusted computing technology, and used to measure and protect the integrity of the control plane;
[0028] Trusted path construction unit, used to build a trusted path between the data plane and the control plane based on remote attestation technology to ensure the integrity of routing table information;
[0029] The incremental update unit is used to update the routing table rules in an incremental manner to reduce the performance loss introduced by the remote attestation and encryption and decryption processes.
[0030] The key points of the present invention are:
[0031] 1. A trusted control plane is built using trusted computing technology to measure and protect the integrity of the control plane.
[0032] 2. A trusted path between the data plane and the control plane is built based on remote attestation technology to ensure the integrity of routing table information.
[0033] 3. Update routing table rules incrementally to reduce the performance loss introduced by remote attestation and encryption and decryption processes.
[0034] 4. Used to protect network function virtualization, placing VNF (virtual network function) under the protection of a trusted platform or trusted execution environment to ensure security isolation and resource isolation of the virtualized environment.
[0035] The beneficial effects of the present invention are as follows:
[0036] 1. The present invention can protect the SDN controller from being attacked and destroyed, and prevent the modification of flow table rules, forged traffic or the initiation of denial of service attacks.
[0037] 2. The present invention can protect the communication link between the SDN controller and each switch in the network, and defend against man-in-the-middle attacks, data tampering or information leakage, etc.
[0038] 3. The present invention can protect network function virtualization (VNF) and defend it from attacks by malicious system software (Hypervisor). BRIEF DESCRIPTION OF THE DRAWINGS
[0039] Figure 1 This is a schematic diagram of the SDN architecture in the prior art.
[0040] Figure 2 It is a schematic diagram of the SDN architecture of the present invention. DETAILED DESCRIPTION
[0041] The present invention is further described in detail below through specific embodiments and drawings.
[0042] The present invention is aimed at data center scenarios and aims to provide a high-performance network routing system to meet the growing data traffic and network requirements. Figure 2 As shown, the data center uses an SDN (Software Defined Network)-based routing system. This system includes control and data plane components. The control plane communicates with the data plane's Smart NICs via the virtual machine's Virtio mechanism. To further improve performance, the design introduces Smart NICs or DPUs (Data Processing Units). These devices have programmable network interface cards (NICs) and can perform high-performance packet forwarding based on forwarding rules generated by the control plane.
[0043] In a virtualized environment, virtual machine communication is a crucial aspect. This invention utilizes the Virtio mechanism to enable communication between virtual machines and SmartNICs. Virtio is a virtualization driver framework that provides efficient data transmission and communication mechanisms, enabling virtual machines to interact directly with SmartNICs. Through the Virtio mechanism, virtual machines can exchange data with SmartNICs with low latency and high throughput, thereby improving the performance and efficiency of the entire data center.
[0044] The programmability of SmartNICs and DPUs provides data center administrators with tremendous flexibility and customization. Administrators can customize forwarding rules based on actual needs to implement specific network routing and processing methods. For example, forwarding rules can be customized based on traffic type, quality of service requirements, or security policies, enabling flexible traffic control and optimization. SmartNICs and DPUs can also dynamically adjust forwarding rules based on network traffic changes to accommodate varying loads and traffic patterns. This flexibility enables data centers to better adapt to changing network requirements and provide higher performance and more reliable services.
[0045] In addition to providing high-performance packet forwarding capabilities, SmartNICs and DPUs can collaborate with other network devices to enable higher-level network functions and services. They can be integrated with devices such as firewalls and load balancers to jointly implement network security and load balancing. By collaborating with SmartNICs and DPUs, data centers can build a highly flexible, scalable, and manageable network architecture that delivers high-performance and high-availability services.
[0046] Furthermore, SmartNICs and DPUs can interact with the controller to perform network monitoring and troubleshooting. They provide real-time network status information to the controller, helping administrators optimize network performance and troubleshoot problems. Leveraging the intelligent capabilities of SmartNICs and DPUs, data centers can better monitor and manage network health, identifying and resolving potential issues promptly.
[0047] Data center administrators can select appropriate hardware and software solutions based on actual needs. By configuring and managing these components, they can achieve a high-performance, customizable, and manageable network architecture. The application of these technologies enables data centers to better cope with growing data traffic and complex application requirements, providing stable and reliable network services.
[0048] To further address the vulnerability of SDN controllers to attacks, this paper proposes a trusted dynamic routing construction method for SDN. This method utilizes trusted computing technology to build a trusted control plane, which measures and protects its integrity. Furthermore, a trusted path between the data plane and the control plane is established based on remote attestation technology to ensure the integrity of routing table information. Furthermore, the system incrementally updates routing table rules to mitigate the performance penalties introduced by remote attestation and encryption / decryption processes.
[0049] 1. Build a trusted control plane
[0050] In this invention, to solve the problem that the SDN control plane is vulnerable to malicious attacks, trusted computing technology is used to build a trusted control plane. Trusted computing is a security technology that ensures the integrity and confidentiality of the computing process through the combination of hardware and software. In the SDN controller, the present invention introduces a hardware module of trusted computing, such as a trusted platform module (TPM) or a trusted execution environment (TEE), to form an SDN trusted controller, such as Figure 2 As shown in Figure 2, the TEE provides a protected execution environment that contains the key components and code of the control plane. By placing important parts of the control plane in the TEE, the integrity and security of these parts are ensured. The TEE also provides encryption and authentication features to further protect the control plane from unauthorized access and tampering.
[0051] In terms of integrity protection of the control plane, the present invention uses measurement technology to verify the integrity of the control plane. Measurement is a technology used to measure and verify the integrity of code and data, which can detect any tampering or modification of the control plane. The present invention embeds measurement codes in the key components and codes of the control plane. These codes generate and record the measurement values of the control plane by calculating the hash value of the control plane code (such as using hash algorithms such as SHA-3 and SM3). The measurement value of the control plane can be compared with the pre-calculated expected value to verify its integrity. If the measurement value does not match the expected value, it means that the control plane may have been tampered with or attacked. Administrators can monitor changes in measurement values and take timely measures to deal with potential security threats.
[0052] 2. Build a trusted path between the data plane and the control plane
[0053] In addition to protecting the integrity of the control plane, this invention also establishes a trusted path between the data plane and the control plane to ensure the integrity of routing table information. In SDN, the control plane is responsible for generating and distributing routing table rules, while the data plane is responsible for forwarding data packets according to these rules. To ensure that the routing table rules generated by the control plane are not modified or tampered with during transmission, this invention introduces remote attestation technology. Remote attestation is a technology used to verify the integrity and credibility of data, ensuring the security of data during transmission.
[0054] In this invention, the routing table rules generated by the control plane are encrypted and encapsulated in a secure message, which is then transmitted to the data plane via a trusted path. The trusted path consists of trusted devices and communication channels between the control and data planes. Within this trusted path, the invention uses remote attestation technology to verify the integrity and authenticity of messages. The control plane generates a certificate proving the correctness of the routing table rules and sends the certificate along with the encrypted message to the data plane. Upon receiving the message, the data plane can decrypt the message using a pre-shared key and verify the correctness of the routing table rules using the verified certificate. This ensures that routing table information is not tampered with or modified during transmission.
[0055] 3. Incremental update of routing table rules
[0056] To reduce the performance loss introduced by remote attestation and encryption / decryption processes, the present invention employs an incremental update strategy for routing table rules. Traditionally, each update requires regenerating and transmitting the entire routing table rules, which incurs significant computational and communication overhead. Incremental updates, however, only transmit the changed portions, reducing data volume and transmission time. In practice, the present invention records the changes in each update and generates corresponding attestations, which are then sent to the data plane. The data plane only needs to perform local updates based on these changes, eliminating the need to reacquire and apply the complete routing table rules. This significantly reduces communication and computational overhead, improving system performance and efficiency.
[0057] 4. Implement network function virtualization
[0058] This invention also integrates with Network Function Virtualization (NFV). NFV is an emerging network architecture paradigm that decouples network functions from dedicated hardware devices and instead runs them as software on general-purpose servers, enabling flexible deployment and dynamic management of network functions. The introduction of NFV aims to improve network flexibility, scalability, and cost-effectiveness, and provide faster and more flexible service delivery for network operators and enterprises.
[0059] The core concept of NFV is to transform traditional dedicated hardware devices (such as routers, firewalls, and load balancers) into virtualized network functions (VNFs) that run as software on general-purpose servers. By virtualizing network functions, multiple VNFs can be deployed on the same physical server, reducing the number of hardware devices and costs. NFV also supports the elastic scaling of network functions, increasing or decreasing the number of VNF instances based on demand, thereby optimizing the use of network resources.
[0060] However, NFV also faces some challenges and security risks. First, resource sharing in a virtualized environment can lead to security risks. Different VNFs share the resources of the same physical server. If one VNF is attacked or has a vulnerability, it may affect the security and performance of other VNFs. Furthermore, the management and orchestration of virtual network functions in a virtualized environment is a complex issue, requiring ensuring the collaboration and interoperability between VNFs, as well as implementing automated management and configuration of VNFs. Therefore, this technical solution can also place VNFs under the protection of a trusted platform or trusted execution environment to ensure security and resource isolation in the virtualized environment.
[0061] Another embodiment of the present invention provides a trusted dynamic routing construction system for SDN, which includes:
[0062] A trusted control plane construction unit, used to build a trusted control plane using trusted computing technology, and used to measure and protect the integrity of the control plane;
[0063] Trusted path construction unit, used to build a trusted path between the data plane and the control plane based on remote attestation technology to ensure the integrity of routing table information;
[0064] The incremental update unit is used to update the routing table rules in an incremental manner to reduce the performance loss introduced by the remote attestation and encryption and decryption processes.
[0065] The specific implementation process of each module refers to the above description of the method of the present invention.
[0066] Another embodiment of the present invention provides a computer device (computer, server, smart phone, etc.), which includes a memory and a processor, wherein the memory stores a computer program, the computer program is configured to be executed by the processor, and the computer program includes instructions for executing each step in the method of the present invention.
[0067] Another embodiment of the present invention provides a computer-readable storage medium (such as ROM / RAM, magnetic disk, optical disk), wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a computer, the steps of the method of the present invention are implemented.
[0068] The specific embodiments of the present invention disclosed above are intended to facilitate understanding and implementation of the present invention. Those skilled in the art will appreciate that various substitutions, changes, and modifications are possible without departing from the spirit and scope of the present invention. The present invention should not be limited to the embodiments disclosed in this specification; the scope of protection of the present invention shall be determined by the scope defined in the claims.
Claims
1. A trusted dynamic routing construction method for SDN, characterized in that: The following steps are involved: Utilize trusted computing technology to build a trusted control plane to measure and protect the integrity of the control plane; Build a trusted path between the data plane and the control plane based on remote attestation technology to ensure the integrity of routing table information; By incrementally updating routing table rules, the performance loss introduced by remote attestation and encryption / decryption processes is reduced.
2. The method according to claim 1, characterized in that The use of trusted computing technology to build a trusted control plane includes: Introducing trusted computing hardware modules into the SDN controller to form an SDN trusted controller; Metrics code is embedded in the key components and code of the control plane. The metrics code is responsible for generating and recording metrics for the control plane. The integrity of the control plane is verified by comparing the metrics with pre-calculated expected values. If the metrics do not match the expected values, it indicates that the control plane may have been tampered with or attacked. Administrators monitor changes in metrics and take timely measures to address potential security threats.
3. The method according to claim 2, characterized in that The hardware module of the trusted computing is a trusted platform module TPM or a trusted execution environment TEE.
4. The method according to claim 1, wherein The construction of a trusted path between the data plane and the control plane based on remote attestation technology includes: The routing table rules generated by the control plane are encrypted and encapsulated in secure messages, and then transmitted to the data plane through a trusted path. The trusted path is composed of trusted devices and communication channels between the control plane and the data plane. Remote attestation technology is used on the trusted path to verify the integrity and authenticity of the messages.
5. The method according to claim 4, characterized in that The use of remote attestation technology to verify the integrity and authenticity of the message includes: The control plane generates a proof that proves the correctness of the routing table rules and sends the proof to the data plane along with the encrypted message; After receiving the message, the data plane decrypts the message using the pre-shared key and uses the verified proof to verify the correctness of the routing table rules to ensure that the routing table information has not been tampered with or modified during transmission.
6. The method according to claim 1, characterized in that The incremental updating of routing table rules includes: By recording the changes in each update and generating corresponding proofs, these changes and proofs are then sent to the data plane; The data plane is only locally updated based on these changes without having to re-acquire and apply the complete routing table rules.
7. The method according to claim 1, characterized in that Implement network function virtualization and place virtual network functions (VNFs) under the protection of a trusted platform or trusted execution environment to ensure security isolation and resource isolation of the virtualized environment.
8. A trusted dynamic routing construction system for SDN, characterized by: include: A trusted control plane construction unit, used to build a trusted control plane using trusted computing technology, and used to measure and protect the integrity of the control plane; Trusted path construction unit, used to build a trusted path between the data plane and the control plane based on remote attestation technology to ensure the integrity of routing table information; The incremental update unit is used to update the routing table rules in an incremental manner to reduce the performance loss introduced by the remote attestation and encryption and decryption processes.
9. A computer device, characterized in that: The method comprises a memory and a processor, wherein the memory stores a computer program, the computer program is configured to be executed by the processor, and the computer program comprises instructions for executing the method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a computer, the method according to any one of claims 1 to 7 is implemented.