Blockchain and Intent-Based Networking: A Novel Approach to Secure and Accurate Network Policy Implementation

Javier Jose Diaz Rivera, Muhammad Afaq, Wang Cheol Song*

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

4 Scopus citations

Abstract

In response to the swift evolution of network technologies, traditional security measures centered on perimeter defenses have become inadequate for the needs of present-day distributed systems. Contemporary paradigms, such as Zero Trust Networking (ZTN) and Software Defined Perimeters (SDP), enhance network security by implementing a “never trust, always verify” model. Establishing trust is a crucial part of security policies that govern access to network resources. Automated policy management, continuous monitoring, and data analytics are required to ensure these policies’ reliability. Intent-Based Networking (IBN) can meet these requirements by translating high-level security policies into network configurations, thus bolstering network management and policy enforcement. Integrating IBN with blockchain technology creates a single source of truth (SSoT) for intent translation, providing an immutable, transaction-based ledger to verify each interaction. Our proposed design employs the open-source Hyperledger Besu for a permissioned blockchain implementation, alongside a secure network overlay from NetFoundry (OpenZiti). An IBN system is integrated as a management layer for secure policy creation. These policies, in the form of intents, are stored in the blockchain. Additionally, an event listener mechanism is designed to automatically translate the intents from the blockchain into network overlay configurations. Furthermore, a synchronizer ensures that the state of the network overlay remains aligned with the policy configurations defined by the intents in the blockchain. The overall research aims to achieve a Zero Touch and Trust (ZT&T) network system.

Original languageEnglish
Title of host publicationAPNOMS 2023 - 24th Asia-Pacific Network Operations and Management Symposium
Subtitle of host publicationIntelligent Management for Enabling the Digital Transformation
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages77-82
Number of pages6
ISBN (Electronic)9788995004395
StatePublished - 2023
Externally publishedYes
Event24th Asia-Pacific Network Operations and Management Symposium, APNOMS 2023 - Sejong, Korea, Republic of
Duration: 6 Sep 20238 Sep 2023

Publication series

NameAPNOMS 2023 - 24th Asia-Pacific Network Operations and Management Symposium: Intelligent Management for Enabling the Digital Transformation

Conference

Conference24th Asia-Pacific Network Operations and Management Symposium, APNOMS 2023
Country/TerritoryKorea, Republic of
CitySejong
Period6/09/238/09/23

Bibliographical note

Publisher Copyright:
Copyright 2023 KICS.

Keywords

  • Blockchain
  • IBN
  • Security Policies
  • Software Defined Perimeter
  • Zero Trust Network

ASJC Scopus subject areas

  • Artificial Intelligence
  • Computer Networks and Communications
  • Information Systems
  • Information Systems and Management
  • Safety, Risk, Reliability and Quality

Fingerprint

Dive into the research topics of 'Blockchain and Intent-Based Networking: A Novel Approach to Secure and Accurate Network Policy Implementation'. Together they form a unique fingerprint.

Cite this