文档介绍:
一种基于 SDN 的安全云接入方法
徐耀峰,郭志刚,寿国础**
(北京邮电大学网络体系构建与融合北京市重点实验室,北京 100876)
5
10
15
20
25
30
35
摘要:随着云计算的逐渐普及,云的接入安全问题成为云商业化发展的一大瓶颈。这篇论文
结合 SDN(Software working)技术,从接入安全保障角度提出一种新型的安全
云接入模型。这个模型中,云服务提供商(CSP)只关心数据的处理和存储,第三服务方根
据云用户的需要提供对应的接入安全保障服务。在 SDN 网络中,第三服务方可以采用基于
服务名称寻址的网络管理策略,这使得服务很容易扩展或恢复。整个模型分为两部分,API
模块和功能模块,API 模块负责功能模块与 SDN 控制器的网络策略交互,功能模块处理接
入安全事项。这一模型具有降低用户开销和管理复杂度、提供专业化的接入安全服务、服务
类型多样化、可以处理海量用户请求和网络策略统一配置等优势。针对云接入安全事项,本
文设计了第三服务方的三种服务,分别是数据完整性检测、统一用户管理以及网络攻击探测。
论文通过设计最优路径算法,实现了这一模型,命名为“安全服务云”。我们验证了模型的基
本功能并测试了时延特性,证明了这种新型接入安全服务模式的可行性。
关键词:云计算;接入安全;SDN;安全服务云
中图分类号:
A Method of Ensuring Access Security in Cloud using SDN
XU Yaofeng, GUO Zhigang, SHOU Guochu
(Beijing Key Labrory work System Architecture and Convengence, Beijing University of
Posts and munications, Beijing 100876)
Abstract: With the increasing popularity of puting, the cloud access security issue has
e a major bottleneck of the mercial development. In this paper, we propose a new
architecture of outsourcing the access security issues to a third party based on SDN. The cloud services
provider (CSP) is only interested in data processing and storage here, and the third party is responsible
for delivering the access security as a service to the cloud users in this model. Policy is specified with
service names not locations, which makes the service can be easily expanded or restored. There are two
parts in this model, one is the function module, which will handle the access security issues, the other is
the API module, which is responsible for the interaction between function module and SDN controller.
The new model can lower overhead and user plexity, improve security features
through providing customized services, deal with massive security request and configure unified
security strategy. Baesd on the framework of access security challenges in puting, the third
party can provide security services such as data integrity, user authorization and attacks de