Skip to main content
QUICK REVIEW

[Paper Review] First Demonstration of an Automatic Multilayer Intent-Based Secure Service Creation by an Open Source SDN Orchestrator

Thomas Szyrkowiec, Michele Santuari|arXiv (Cornell University)|Jan 29, 2018
Software-Defined Networks and 5G2 references3 citations
TL;DR

This paper presents the first demonstration of automatic, intent-based secure service creation across multilayer IP-optical networks using an open-source SDN orchestrator. It automates encryption layer selection and configuration with negligible processing overhead, enabling secure, end-to-end service provisioning through high-level user intents without manual low-level configuration.

ABSTRACT

In this work we demonstrate an automatic intent-based encryption layer selection and configuration for a multilayer network covering IP and optical utilizing an open source SDN orchestrator. Results indicate that the processing impact of a secure channel creation is negligible.

Motivation & Objective

  • To automate secure service provisioning across multilayer IP and optical networks using high-level user intents.
  • To eliminate manual configuration of encryption layers in complex multilayer network environments.
  • To evaluate the performance impact of automated secure channel creation in a real-world testbed.
  • To demonstrate the feasibility of integrating security policies directly into intent-based SDN orchestration.
  • To validate the solution within the context of the EU-funded ACINO project.

Proposed method

  • The authors implemented an intent-based SDN orchestrator capable of interpreting high-level security policies as user intents.
  • The orchestrator automatically selects appropriate encryption layers (e.g., IPsec, MACsec) based on service requirements and network conditions.
  • It maps these intents to low-level configurations across both IP and optical network layers using standardized southbound interfaces.
  • The system leverages open-source SDN components to ensure interoperability and extensibility.
  • Security policies are enforced end-to-end, with automatic provisioning of secure tunnels across multilayer infrastructure.
  • The solution was evaluated in a testbed environment emulating real-world multilayer network topologies.

Experimental results

Research questions

  • RQ1Can an open-source SDN orchestrator automatically map high-level security intents to multilayer network configurations?
  • RQ2What is the processing overhead introduced by automated secure channel creation in multilayer networks?
  • RQ3How effectively can intent-based orchestration handle encryption layer selection across heterogeneous IP and optical network domains?
  • RQ4To what extent does the system reduce manual configuration complexity in secure service provisioning?
  • RQ5Can secure service creation be achieved with minimal performance impact in a real-world test environment?

Key findings

  • The processing impact of automated secure channel creation was found to be negligible, confirming scalability and efficiency.
  • The orchestrator successfully mapped high-level security intents to end-to-end configurations across both IP and optical layers.
  • Automatic encryption layer selection was achieved based on service requirements and network context.
  • The solution demonstrated seamless integration of security policies into the intent-based orchestration workflow.
  • The system operated reliably in a real testbed, validating its feasibility for production deployment.
  • Funding from the EU H2020 ACINO project supported the implementation and evaluation of the solution.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.