Uppsats
An Experimental Study of Identity-Aware Routing in HIP-Based VPLS Using SDN
Kandidat-uppsats
Linköpings universitet/Institutionen för datavetenskap
Publicerad: 2026
Språk: Engelska
Sammanfattning
In modern networks, devices are mainly identified by their IP-address. This approach presents several limitations, one of which being that IP-address represents both the location and identity of a device. When an entity moves location within the network, its address will change which creates technical challenges and security vulnerabilities. In traditional Host Identity Protocol (HIP) based Virtual Private LAN Service (VPLS) networks, once an Encapsulating Security Payload (ESP) tunnel is established via the HIP Base Exchange, the data flows without further identity signaling. The network relies solely on standard IP routing which prevents the possibility to enforce flexible, security-aware routing policies. To address these issues, we combined VPLS, Host Identity Protocol (HIP) and Software-Defined Networking (SDN). We implemented Host Identity Tags (HITs) as policy keys to control forwarding paths between Provider Edge (PE) pairs. After that, SDN flow rules were added based on the communicating HIT pair. The implemented framework was evaluated using three different routing policies: Shortest Path, Min Hop and Preferred Path. After evaluation, it was concluded that the Shortest Path policy achieved the shortest end-to-end latency. The Min Hop policy utilized the least amount of nodes, reducing exposure to potential security risks associated with longer routing paths. The Preferred Path policy, forcing packets through a chosen switch worked as intended but varied in overall performance metrics but generally fell somewhere between the Min Hop and Shortest Path policies. The results indicate that implementation of identity-aware routing can be implemented within a HIP-based VPLS network using HIT pairs as policy keys for the SDN controller. Additionally, the results show that choice of routing policy create trade-offs between overhead, latency and number of traversed nodes along a path between two sites. Therefore, the proposed approach may be suitable for networks where identity-based control and security are more important than minimizing all performance overhead.
Information
- Författare
- Forsell, Elias, Einarsson, Vincent
- Lärosäte / institution
- Linköpings universitet/Institutionen för datavetenskap
- Publiceringsdatum
- 2026
- Uppsatstyp
- Kandidat-uppsats
- Språk
- Engelska
Utforska vidare
Liknande uppsatser
Uppsatser med liknande ämnen och nyckelord.
Magister-uppsats, Jönköping University/JTH, Avdelningen för datateknik och informatik
Cicek, Nazli Elis, Shafae, Nazgol
Publicerad: 2025
Kandidat-uppsats, Högskolan i Skövde/Institutionen för informationsteknologi
Dargren, Calle
Publicerad: 2026
Kandidat-uppsats, Jönköping University/Tekniska Högskolan
Dam Larsen, Kasper, Tholsby, Sebastian
Publicerad: 2026
Kandidat-uppsats, Mittuniversitetet/Institutionen för data- och elektroteknik (2023-)
Hellzén, Philip
Publicerad: 2026
Kandidat-uppsats, Högskolan i Skövde/Institutionen för informationsteknologi
Herre, Axel, Ranhög, Alex
Publicerad: 2026
Kandidat-uppsats, Blekinge Tekniska Högskola/Institutionen för datavetenskap
Midatha, Vyshnavi Rami, Yerragundu, Sai Dheeraj Reddy
Publicerad: 2026