A Proof-of-Concept Demonstration of Isolated and Encrypted Service Function Chains

Contemporary Service Function Chaining (SFC), and the requirements arising from privacy concerns, call for the increasing integration of security features such as encryption and isolation across Network Function Virtualisation (NFV) domains. Therefore, suitable adaptations of automation and encrypti...

Full description

Bibliographic Details
Main Authors: Håkon Gunleifsen, Thomas Kemmerich, Vasileios Gkioulos
Format: Article
Language:English
Published: MDPI AG 2019-08-01
Series:Future Internet
Subjects:
Online Access:https://www.mdpi.com/1999-5903/11/9/183
Description
Summary:Contemporary Service Function Chaining (SFC), and the requirements arising from privacy concerns, call for the increasing integration of security features such as encryption and isolation across Network Function Virtualisation (NFV) domains. Therefore, suitable adaptations of automation and encryption concepts for the development of interconnected data centre infrastructures are essential. Nevertheless, packet isolation constraints related to the current NFV infrastructure and SFC protocols, render current NFV standards insecure. Accordingly, the goal of our work was an experimental demonstration of a new SFC packet forwarding standard that enables contemporary data centres to overcome these constraints. This article presents a comprehensive view of the developed architecture, focusing on the elements that constitute a new forwarding standard of encrypted SFC packets. Through a Proof-of-Concept demonstration, we present our closing experimental results of how the architecture fulfils the requirements defined in our use case.
ISSN:1999-5903