Uppsats

An Experimental Study of Identity-Aware Routing in HIP-Based VPLS Using SDN

Kandidat-uppsats

Linköpings universitet/Institutionen för datavetenskap

Publicerad: 2026

Språk: Engelska

Sammanfattning

In modern networks, devices are mainly identified by their IP-address. This approach presents several limitations, one of which being that IP-address represents both the location and identity of a device. When an entity moves location within the network, its address will change which creates technical challenges and security vulnerabilities. In traditional Host Identity Protocol (HIP) based Virtual Private LAN Service (VPLS) networks, once an Encapsulating Security Payload (ESP) tunnel is established via the HIP Base Exchange, the data flows without further identity signaling. The network relies solely on standard IP routing which prevents the possibility to enforce flexible, security-aware routing policies. To address these issues, we combined VPLS, Host Identity Protocol (HIP) and Software-Defined Networking (SDN). We implemented Host Identity Tags (HITs) as policy keys to control forwarding paths between Provider Edge (PE) pairs. After that, SDN flow rules were added based on the communicating HIT pair. The implemented framework was evaluated using three different routing policies: Shortest Path, Min Hop and Preferred Path. After evaluation, it was concluded that the Shortest Path policy achieved the shortest end-to-end latency. The Min Hop policy utilized the least amount of nodes, reducing exposure to potential security risks associated with longer routing paths. The Preferred Path policy, forcing packets through a chosen switch worked as intended but varied in overall performance metrics but generally fell somewhere between the Min Hop and Shortest Path policies. The results indicate that implementation of identity-aware routing can be implemented within a HIP-based VPLS network using HIT pairs as policy keys for the SDN controller. Additionally, the results show that choice of routing policy create trade-offs between overhead, latency and number of traversed nodes along a path between two sites. Therefore, the proposed approach may be suitable for networks where identity-based control and security are more important than minimizing all performance overhead.

Information

Lärosäte / institution
Linköpings universitet/Institutionen för datavetenskap
Publiceringsdatum
2026
Uppsatstyp
Kandidat-uppsats
Språk
Engelska

Utforska vidare

Liknande uppsatser

Uppsatser med liknande ämnen och nyckelord.