Asecure and high-performancemulti-controller architecture for software-defined networking<FootNote> Project supported by the National Natural Science Foundation of China (Nos. 61402357, 61272459, and 61402357), the China Postdoctoral Science Foundation (No. 2015M570835), the Fundamental Research Funds for the Central Universities, China, the Program for New Century Excellent Talents in University, and the CETC 54 Project (No. ITD-U14001/KX142600008) </FootNote>
Huan-zhao WANG , Peng ZHANG , Lei XIONG , Xin LIU , Cheng-chen HU
Front. Inform. Technol. Electron. Eng ›› 2016, Vol. 17 ›› Issue (7) : 634 -646.
Asecure and high-performancemulti-controller architecture for software-defined networking<FootNote> Project supported by the National Natural Science Foundation of China (Nos. 61402357, 61272459, and 61402357), the China Postdoctoral Science Foundation (No. 2015M570835), the Fundamental Research Funds for the Central Universities, China, the Program for New Century Excellent Talents in University, and the CETC 54 Project (No. ITD-U14001/KX142600008) </FootNote>
Controllers play a critical role in software-defined networking (SDN). However, existing singlecontroller SDN architectures are vulnerable to single-point failures, where a controller’s capacity can be saturated by flooded flow requests. In addition, due to the complicated interactions between applications and controllers, the flow setup latency is relatively large. To address the above security and performance issues of current SDN controllers, we propose distributed rule store (DRS), a new multi-controller architecture for SDNs. In DRS, the controller caches the flow rules calculated by applications, and distributes these rules to multiple controller instances. Each controller instance holds only a subset of all rules, and periodically checks the consistency of flow rules with each other. Requests from switches are distributed among multiple controllers, in order to mitigate controller capacity saturation attack. At the same time, when rules at one controller are maliciously modified, they can be detected and recovered in time. We implement DRS based on Floodlight and evaluate it with extensive emulation. The results show that DRS can effectively maintain a consistently distributed rule store, and at the same time can achieve a shorter flow setup time and a higher processing throughput, compared with ONOS and Floodlight.
Software-defined networking (SDN) / Security / Multi-controller / Distributed rule store
| [1] |
|
| [2] |
|
| [3] |
|
| [4] |
Floodlight Project, 2016. Floodlight Controller. Available from |
| [5] |
|
| [6] |
|
| [7] |
|
| [8] |
|
| [9] |
|
| [10] |
|
| [11] |
|
| [12] |
|
| [13] |
|
| [14] |
|
| [15] |
|
| [16] |
NOXRepo, 2016. The POX Controller. Available from |
| [17] |
OpenDaylight Project, 2016. The OpenDaylight Controller. Available from |
| [18] |
|
| [19] |
|
| [20] |
|
| [21] |
|
| [22] |
|
| [23] |
Ryu SDN Framework Community, 2014. The Ryu Controller. Available from |
| [24] |
|
| [25] |
|
| [26] |
|
| [27] |
|
Zhejiang University and Springer-Verlag Berlin Heidelberg
/
| 〈 |
|
〉 |