A Dependable and Lightweight UDP-based Transport Layer Security over SDN

碩士 === 國立臺灣大學 === 電機工程學研究所 === 105 === With the improvement of the security awareness, more and more operators focus on their security services. In addition, how to fix the link failure and deal with the inadequate bandwidth are still the crucial issues for both content providers and Internet servic...

Full description

Bibliographic Details
Main Authors: You-Ru Chen, 陳宥如
Other Authors: Chin-Laung Lei
Format: Others
Language:en_US
Published: 2017
Online Access:http://ndltd.ncl.edu.tw/handle/34akr8
id ndltd-TW-105NTU05442089
record_format oai_dc
spelling ndltd-TW-105NTU054420892019-05-15T23:39:45Z http://ndltd.ncl.edu.tw/handle/34akr8 A Dependable and Lightweight UDP-based Transport Layer Security over SDN 軟體定義網路下之輕量可靠傳輸層安全協議架構 You-Ru Chen 陳宥如 碩士 國立臺灣大學 電機工程學研究所 105 With the improvement of the security awareness, more and more operators focus on their security services. In addition, how to fix the link failure and deal with the inadequate bandwidth are still the crucial issues for both content providers and Internet service providers. However, the network bandwidth utilization has profited from Software-Defined Network (SDN). The administrators are easy to manage network flow by customizing flow rules over SDN. Inspired by this, we propose a framework to improve efficiency of Transport Layer Security (TLS) transmission on top of SDN whenever the connection is normal or the link failures occur. SDN is decoupled into control plane and data plane. A centralized controller performs the control plane functionality, and the switches focus on data plane functions exclusively. The controller orchestrates traffic management to optimize bandwidth utilization under various workloads. Owing to the features of SDN, it is more flexible to deal with link failures and bandwidth utilization. Our main contribution in this thesis is to propose a UDP-based TLS module on top of SDN. In order to achieve reliability and sequentiality of UDP transmission, we combine switches with customized engines. For users, they are still transmitting data with TLS, but the overhead of TLS traffic is reduced because of the lightweight characteristic of UDP. Our failover and fast retransmission mechanism also decline the recovery time. We adopt Mininet, Ryu and Scapy to implement our framework at different scenarios. From the experiment results, our proposed framework not only reduces the overhead and time of transmission but also outperforms the classical TLS transmission as well. Chin-Laung Lei 雷欽隆 2017 學位論文 ; thesis 48 en_US
collection NDLTD
language en_US
format Others
sources NDLTD
description 碩士 === 國立臺灣大學 === 電機工程學研究所 === 105 === With the improvement of the security awareness, more and more operators focus on their security services. In addition, how to fix the link failure and deal with the inadequate bandwidth are still the crucial issues for both content providers and Internet service providers. However, the network bandwidth utilization has profited from Software-Defined Network (SDN). The administrators are easy to manage network flow by customizing flow rules over SDN. Inspired by this, we propose a framework to improve efficiency of Transport Layer Security (TLS) transmission on top of SDN whenever the connection is normal or the link failures occur. SDN is decoupled into control plane and data plane. A centralized controller performs the control plane functionality, and the switches focus on data plane functions exclusively. The controller orchestrates traffic management to optimize bandwidth utilization under various workloads. Owing to the features of SDN, it is more flexible to deal with link failures and bandwidth utilization. Our main contribution in this thesis is to propose a UDP-based TLS module on top of SDN. In order to achieve reliability and sequentiality of UDP transmission, we combine switches with customized engines. For users, they are still transmitting data with TLS, but the overhead of TLS traffic is reduced because of the lightweight characteristic of UDP. Our failover and fast retransmission mechanism also decline the recovery time. We adopt Mininet, Ryu and Scapy to implement our framework at different scenarios. From the experiment results, our proposed framework not only reduces the overhead and time of transmission but also outperforms the classical TLS transmission as well.
author2 Chin-Laung Lei
author_facet Chin-Laung Lei
You-Ru Chen
陳宥如
author You-Ru Chen
陳宥如
spellingShingle You-Ru Chen
陳宥如
A Dependable and Lightweight UDP-based Transport Layer Security over SDN
author_sort You-Ru Chen
title A Dependable and Lightweight UDP-based Transport Layer Security over SDN
title_short A Dependable and Lightweight UDP-based Transport Layer Security over SDN
title_full A Dependable and Lightweight UDP-based Transport Layer Security over SDN
title_fullStr A Dependable and Lightweight UDP-based Transport Layer Security over SDN
title_full_unstemmed A Dependable and Lightweight UDP-based Transport Layer Security over SDN
title_sort dependable and lightweight udp-based transport layer security over sdn
publishDate 2017
url http://ndltd.ncl.edu.tw/handle/34akr8
work_keys_str_mv AT youruchen adependableandlightweightudpbasedtransportlayersecurityoversdn
AT chényòurú adependableandlightweightudpbasedtransportlayersecurityoversdn
AT youruchen ruǎntǐdìngyìwǎnglùxiàzhīqīngliàngkěkàochuánshūcéngānquánxiéyìjiàgòu
AT chényòurú ruǎntǐdìngyìwǎnglùxiàzhīqīngliàngkěkàochuánshūcéngānquánxiéyìjiàgòu
AT youruchen dependableandlightweightudpbasedtransportlayersecurityoversdn
AT chényòurú dependableandlightweightudpbasedtransportlayersecurityoversdn
_version_ 1719152323253501952