Related Experiment Video
Updated: Aug 19, 2025

TBase - an Integrated Electronic Health Record and Research Database for Kidney Transplant Recipients
Published on: April 13, 2021
A data plane security model of SR-BE/TE based on zero-trust architecture
Liang Wang1, Hailong Ma2, Ziyong Li1
1National Digital Switching System Engineering and Technology Research Center, PLA Strategic Support Force Information Engineering University, Zhengzhou, 450003, China.
This study introduces ZbSR, a zero-trust architecture model for Segment Routing-BE/TE (SR-BE/TE) data plane security. It addresses eight security issues, enhancing network protection against untrusted threats with minimal delay overhead.
Area of Science:
- Computer Science
- Network Security
- Cybersecurity
Background:
- The Segment Routing-BE/TE (SR-BE/TE) data plane faces significant security challenges in zero-trust network environments, including untrusted network elements and Public Key Infrastructure/Certificate Authority (PKI/CA) vulnerabilities.
- Existing network audit mechanisms often lack specific support for SR-BE/TE, leaving it susceptible to various attacks.
Purpose of the Study:
- To propose a novel security model for the SR-BE/TE data plane within a zero-trust architecture.
- To address specific security issues and enhance data exchange reliability and network audit capabilities for SR-BE/TE.
Main Methods:
- Refined untrusted threats into eight specific security issues.
- Developed the ZbSR (ZTA-based SR) model, reconstructing the SR control plane into a two-layer 'trust-agent' plane with controller, agent, cryptographic center, and information base components.
- Introduced north-south security verification (identity authentication, trust evaluation, key agreement) for reliable east-west data exchange.
- Proposed a network audit security algorithm based on solid authentication, auditing message fields, behaviors, loops, labels, paths, and SIDs.
Main Results:
- The ZbSR model effectively addresses identified security issues in the SR-BE/TE data plane.
- Security algorithms ensure reliable data exchange between terminal devices and enable effective detection of threats like stream path tampering, SID tampering, DoS attacks, and loop attacks.
- Simulation tests confirmed the model's ability to provide security protection across various threat scenarios.
Conclusions:
- The proposed ZbSR model offers a robust security solution for the SR-BE/TE data plane in zero-trust environments.
- The implemented security algorithms and audit mechanisms significantly enhance network resilience and data integrity.
- The model provides effective security protection with an acceptable average incremental delay overhead of 19.3%.
More Related Videos
11:09RBDT: A Computerized Task System based in Transposition for the Continuous Analysis of Relational Behavior Dynamics in Humans
Published on: July 17, 2021
07:49Automated Deployment of an Internet Protocol Telephony Service on Unmanned Aerial Vehicles Using Network Functions Virtualization
Published on: November 26, 2019
Related Concept Videos
Pilot and Numeric Relaying
Zones of Protection
Protective zones are defined by closed dashed lines, containing one or more components. A key characteristic of these zones is the strategic placement of...
Zero-Force Member
One critical concept in truss design is the idea of zero-force members. It refers to a truss member that experiences no stress under loading conditions.
Fault Types
For line-to-line faults occurring between phases B and C, the...
Per-Unit Sequence Models
Zero-sequence currents, which are identical in magnitude and phase, generate a neutral current, resulting in voltage drops across the neutral impedance and the low-voltage winding. If the...
Boundary Conditions: Lossless Lines
At the receiving end, the boundary condition states that the voltage equals the product of the receiving-end impedance and current. This relationship is expressed as a function of the incident and...