Related Experiment Video
Updated: Sep 22, 2025

Large Scale Energy Efficient Sensor Network Routing Using a Quantum Processor Unit
Published on: September 8, 2023
A data plane security model of segmented routing based on SDP trust enhancement architecture
Liang Wang1,2, Hailong Ma3,4, Yiming Jiang1,2
1Institute of Information Technology, PLA Strategic Support Force Information Engineering University, Zhengzhou, 450003, China.
This study introduces a new security model for Segment Routing (SR) networks using Software-Defined Perimeter (SDP) to prevent attacks like port scanning and DoS. The proposed SbSR model enhances trust management for SR data plane access devices.
Area of Science:
- Computer Science
- Network Security
- Software-Defined Networking
Background:
- Segment Routing (SR) faces security challenges in its data plane, including data monitoring, denial of service, loop attacks, and label detection.
- Traditional network security measures are insufficient for the dynamic and complex nature of SR networks.
Purpose of the Study:
- To propose a novel security model, SbSR (SDP-based SR), for enhancing the security management of access devices in the SR data plane.
- To address traditional and emerging security threats within SR networks by integrating SR with Software-Defined Perimeter (SDP).
Main Methods:
- Development of an SR security model (SbSR) based on an SDP trust enhancement architecture.
- Design of a two-level SDP AH trust verification mechanism and four trust management mechanisms (initial trust value, evaluation, renewal, inheritance).
- Implementation of a System Cloud Grey Model (1,1) weighted Markov prediction model for real-time trust evaluation using historical device behavior and four key performance indexes.
Main Results:
- The SbSR model effectively addresses security issues such as port scanning, traffic monitoring, topology detection, loop attacks, and DoS attacks in the SR data plane.
- Simulation results demonstrate the model's efficacy across five security functions with an average access delay cost of 2.84 seconds per new network agent.
- The proposed architecture provides multi-faceted protection for the SR network data plane.
Conclusions:
- The integration of SDP with SR provides a robust framework for securing network data planes.
- The developed trust management mechanisms and evaluation model are effective in identifying and mitigating malicious devices.
- The SbSR model offers a viable solution for enhancing the security posture of modern SR networks.
More Related Videos
07:49Automated Deployment of an Internet Protocol Telephony Service on Unmanned Aerial Vehicles Using Network Functions Virtualization
Published on: November 26, 2019
11:41Evaluation of an Exclusive Spur Dike U-Turn Design with Radar-Collected Data and Simulation
Published on: February 1, 2020
Related Concept Videos
Zones of Protection
Protective zones are defined by closed dashed lines, containing one or more components. A key characteristic of these zones is the strategic placement of...
Pilot and Numeric Relaying
IP3/DAG Signaling Pathway
Distribution Reliability and Automation
PD Controller: Design
Designing a continuous-data controller requires selecting and linking components like adders and integrators, which are fundamental in Proportional,...
¹³C NMR: Distortionless Enhancement by Polarization Transfer (DEPT)