Advances in 5G connectivity, edge computing, and cloud-native platforms have driven network environments to new levels of scale and dynamism, challenging conventional security mechanisms for secure communication. For this reason, we introduce the Trusted Network Environment for Devices (TNED). The TNED is an architecture designed to enhance security through centralised management and hardware-based integrity verification. A key component of the TNED is the Centrally Controlled IPsec (CCIPS), an SDN-based framework that streamlines IPsec deployment by adopting an IKE-less model. This approach eliminates peer-to-peer handshakes and reduces tunnel setup complexity by pre-computing and distributing cryptographic material from a central controller. To further protect sensitive keys and configurations, the TNED architecture integrates Trusted Execution Environments (TEEs) and supports Remote Attestation. The implementation leverages two heterogeneous TEE frameworks, Keystone and Enarx, to demonstrate portability and cross-platform trust enforcement.
TNED: Trusted Network Environment for Devices / Ciravegna, F., Bruno, G., Elorza Forcada, M.A., Pastor, A., Lioy, A.. - In: IEEE ACCESS. - ISSN 2169-3536. - (In corso di stampa).
TNED: Trusted Network Environment for Devices
Ciravegna, Flavio;Bruno,Giacomo;Lioy, Antonio
In corso di stampa
Abstract
Advances in 5G connectivity, edge computing, and cloud-native platforms have driven network environments to new levels of scale and dynamism, challenging conventional security mechanisms for secure communication. For this reason, we introduce the Trusted Network Environment for Devices (TNED). The TNED is an architecture designed to enhance security through centralised management and hardware-based integrity verification. A key component of the TNED is the Centrally Controlled IPsec (CCIPS), an SDN-based framework that streamlines IPsec deployment by adopting an IKE-less model. This approach eliminates peer-to-peer handshakes and reduces tunnel setup complexity by pre-computing and distributing cryptographic material from a central controller. To further protect sensitive keys and configurations, the TNED architecture integrates Trusted Execution Environments (TEEs) and supports Remote Attestation. The implementation leverages two heterogeneous TEE frameworks, Keystone and Enarx, to demonstrate portability and cross-platform trust enforcement.| File | Dimensione | Formato | |
|---|---|---|---|
|
FINAL Article.pdf
accesso riservato
Tipologia:
2. Post-print / Author's Accepted Manuscript
Licenza:
Non Pubblico - Accesso privato/ristretto
Dimensione
4.69 MB
Formato
Adobe PDF
|
4.69 MB | Adobe PDF | Visualizza/Apri Richiedi una copia |
Pubblicazioni consigliate
I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.
https://hdl.handle.net/11583/3015878
