DocumentCode
3699632
Title
Implementation of C-BAS: Certificate-Based AAA for SDN Experimental Facilities
Author
Umar Toseef;Kostas Pentikousis
Author_Institution
EICT GmbH, Berlin, Germany
fYear
2015
fDate
6/1/2015 12:00:00 AM
Firstpage
36
Lastpage
42
Abstract
Recent work in software-defined networking experimental facilities has been shifting towards large scale deployments through federation of resources that span across continents and make it possible to perform experiments at a global scale. The success of such deployments very much depends on the design and implementation of essential, secure mechanisms for authentication, authorization, and accounting (AAA) that not only ensure the robustness of such facilities against intrusions and unauthorized use but also ease experimentation and system administration in such complex environments. C-BAS is an initiative in this direction that uses a secure and flexible certificate-based AAA architecture for SDN experimental facilities. Advanced certificate-based authentication and authorization makes C-BAS inherently resilient against attacks specific to traditional AAA mechanisms, increases flexibility and autonomy in experimental facility system administration, and facilitates federation. This article introduces the implementation details of C-BAS, explains its features through use cases, and evaluates its computational performance.
Keywords
"Authorization","Authentication","Databases","Software","Computer architecture","Lead"
Publisher
ieee
Conference_Titel
Network Cloud Computing and Applications (NCCA), 2015 IEEE Fourth Symposium on
Print_ISBN
978-1-4673-7741-6
Type
conf
DOI
10.1109/NCCA.2015.16
Filename
7340025
Link To Document