Published April 1, 2025 | Version v1
Publication Open

Decentralised Identity for Secure Connectivity in Software-defined Networking Environments

  • 1. ROR icon LINKS Foundation
  • 2. Telefónica Innovación Digital

Description

Telco operators are using Software Defined Networks (SDN) and Network Function Virtualisation (NFV) to virtualise a wide range of network functions and link or chain them together to create, deploy and deliver network connectivity services. 
In such a distributed software networking environment, operators use Internet Protocol Security (IPsec) with Internet Key Exchange (IKEv2) to provide secure connectivity between container network functions running on different computing nodes in their infrastructure. This paper discusses the adoption of the Self-Sovereign Identity (SSI) model in IKEv2 for authentication purposes to avoid the high costs associated with identity management of IPsec endpoints using Public-Key Infrastructure (PKI) and X.509 certificates, while preserving all the security features of the protocol. The paper presents a novel design of the IKEv2 message flow with Verifiable Credentials (VCs), its open source implementation as a fork of the strongSwan library, and the successful experimental validation.

Files

SSI_IKEv2_zenodo.pdf

Files (809.5 kB)

Name Size Download all
md5:d7a006bd7e5028a1b4e3f85cf4b6dae9
809.5 kB Preview Download

Additional details

Funding

European Commission
QUBIP - Quantum-oriented Update to Browsers and Infrastructures for the PQ Transition 101119746

Dates

Available
2025-04-01