Decentralised Identity for Secure Connectivity in Software-Defined Networking Environments


연구 분야: Networking



학회: 2025 IEEE 11th International Conference on Network Softwarization (NetSoft)


초록

Telco operators are using Software Defined Networks (SDN) and Network Function Virtualisation (NFV) to virtualise a wide range of network functions and link or chain them together to create, deploy and deliver network connectivity services. In such a distributed software networking environment, operators use Internet Protocol Security (IPsec) with Internet Key Exchange (IKEv2) to provide secure connectivity between container network functions running on different computing nodes in their infrastructure. This paper discusses the adoption of the Self-Sovereign Identity (SSI) model in IKEv2 for authentication purposes to avoid the high costs associated with identity management of IPsec endpoints using Public-Key Infrastructure (PKI) and X. 509 certificates, while preserving all the security features of the protocol. The paper presents a novel design of the IKEv2 message flow with Verifiable Credentials (VCs), its open source implementation as a fork of the strongSwan library, and the successful experimental validation.


Author Profile
Leonardo Perugini

Cybersecurity Research Group LINKS Foundation Torino Italy

Italy
Author Profile
Antonio Pastor

Global CTIO Telefonica Innovacion Digital Madrid Spain

Spain
Author Profile
Andrea Vesco

Cybersecurity Research Group LINKS Foundation Torino Italy

Italy

📄 논문 정보

발행 연도 2025년
인용수 19
출판 국가 Spain, Italy
사이트 IEEE
좋아요 수 0

연관 논문 목록 (375건)