Advances in 5G connectivity, edge computing, and cloud-native platforms have driven network environments to new levels of scale and dynamism, challenging conventional security mechanisms for secure communication. For this reason, we introduce the Trusted Network Environment for Devices (TNED). The TNED is an architecture designed to enhance security through centralised management and hardware-based integrity verification. A key component of the TNED is the Centrally Controlled IPsec (CCIPS), an SDN-based framework that streamlines IPsec deployment by adopting an IKE-less model. This approach eliminates peer-to-peer handshakes and reduces tunnel setup complexity by pre-computing and distributing cryptographic material from a central controller. To further protect sensitive keys and configurations, the TNED architecture integrates Trusted Execution Environments (TEEs) and supports Remote Attestation. The implementation leverages two heterogeneous TEE frameworks, Keystone and Enarx, to demonstrate portability and cross-platform trust enforcement.

TNED: Trusted Network Environment for Devices / Ciravegna, F., Bruno, G., Elorza Forcada, M.A., Pastor, A., Lioy, A.. - In: IEEE ACCESS. - ISSN 2169-3536. - (In corso di stampa).

TNED: Trusted Network Environment for Devices

Ciravegna, Flavio;Bruno,Giacomo;Lioy, Antonio
In corso di stampa

Abstract

Advances in 5G connectivity, edge computing, and cloud-native platforms have driven network environments to new levels of scale and dynamism, challenging conventional security mechanisms for secure communication. For this reason, we introduce the Trusted Network Environment for Devices (TNED). The TNED is an architecture designed to enhance security through centralised management and hardware-based integrity verification. A key component of the TNED is the Centrally Controlled IPsec (CCIPS), an SDN-based framework that streamlines IPsec deployment by adopting an IKE-less model. This approach eliminates peer-to-peer handshakes and reduces tunnel setup complexity by pre-computing and distributing cryptographic material from a central controller. To further protect sensitive keys and configurations, the TNED architecture integrates Trusted Execution Environments (TEEs) and supports Remote Attestation. The implementation leverages two heterogeneous TEE frameworks, Keystone and Enarx, to demonstrate portability and cross-platform trust enforcement.
In corso di stampa
File in questo prodotto:
File Dimensione Formato  
FINAL Article.pdf

accesso riservato

Tipologia: 2. Post-print / Author's Accepted Manuscript
Licenza: Non Pubblico - Accesso privato/ristretto
Dimensione 4.69 MB
Formato Adobe PDF
4.69 MB Adobe PDF   Visualizza/Apri   Richiedi una copia
Pubblicazioni consigliate

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11583/3015878