{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,30]],"date-time":"2026-03-30T22:18:30Z","timestamp":1774909110990,"version":"3.50.1"},"reference-count":43,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2022,1,20]],"date-time":"2022-01-20T00:00:00Z","timestamp":1642636800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2022,1,20]],"date-time":"2022-01-20T00:00:00Z","timestamp":1642636800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/100014440","name":"Ministerio de Ciencia, Innovaci\u00f3n y Universidades","doi-asserted-by":"publisher","award":["FPU18\/00304"],"award-info":[{"award-number":["FPU18\/00304"]}],"id":[{"id":"10.13039\/100014440","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004687","name":"Universidad de Murcia","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100004687","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Netw Syst Manage"],"published-print":{"date-parts":[[2022,4]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>The Transport Layer Security (TLS) protocol is widely used for protecting end-to-end communications between network peers (applications or nodes). However, the administrators usually have to configure parameters (e.g., cryptography algorithms or authentication credentials) to establish TLS connections manually. However, this way of managing security connections becomes infeasible when the number of network peers is high. This paper proposes a TLS management framework that configures and manages TLS connections in a dynamic and autonomous manner. The solution is based on well-known standardized protocols and models that allow providing the necessary configuration parameters to establish a TLS connection between two network nodes. Nowadays, this is required in several application scenarios such as virtual private networks, virtualized network functions, or service function chains. Our framework is based on standard elements of the Software Defined Networking paradigm, widely adopted to provide flexibility to network management, such as for the scenarios aforementioned. The proposed framework has been implemented in a proof of concept to validate the suitability of the proposed solution to manage the dynamic configuration of TLS connections. The experimental results confirm that the implementation of this framework enables an operable and flexible procedure to manage TLS connections between network nodes in different scenarios.<\/jats:p>","DOI":"10.1007\/s10922-021-09640-6","type":"journal-article","created":{"date-parts":[[2022,1,20]],"date-time":"2022-01-20T18:03:08Z","timestamp":1642701788000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["A Framework for Dynamic Configuration of TLS Connections Based on Standards"],"prefix":"10.1007","volume":"30","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4827-6682","authenticated-orcid":false,"given":"Javier","family":"Pastor-Galindo","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Gabriel","family":"L\u00f3pez-Mill\u00e1n","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rafael","family":"Mar\u00edn-L\u00f3pez","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fernando","family":"Pere\u00f1\u00edguez-Garc\u00eda","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"\u00d3scar","family":"C\u00e1novas","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2022,1,20]]},"reference":[{"issue":"1","key":"9640_CR1","doi-asserted-by":"publisher","first-page":"9","DOI":"10.1007\/s10922-020-09575-4","volume":"29","author":"S Ahmad","year":"2020","unstructured":"Ahmad, S., Mir, A.H.: Scalability, consistency, reliability and security in SDN controllers: a survey of diverse SDN controllers. J. Netw. Syst. Manag. 29(1), 9 (2020). https:\/\/doi.org\/10.1007\/s10922-020-09575-4","journal-title":"J. Netw. Syst. Manag."},{"key":"9640_CR2","unstructured":"Amazon Web Services Cloud. Deploying an opportunistic IPsec mesh on the AWS Cloud. https:\/\/aws.amazon.com\/about-aws\/whats-new\/2019\/05\/new-quick-start-deploys-opportunistic-ipsec-mesh-on-aws\/?nc1=h_ls. Accessed 2 Dec 2020."},{"key":"9640_CR3","unstructured":"AWS App Mesh. Transport layer Security (TLS). https:\/\/aws.amazon.com\/about-aws\/whats-new\/2019\/05\/new-quick-start-deploys-opportunistic-ipsec-mesh-on-aws\/?nc1=h_ls. Accessed 2 Dec 2020."},{"key":"9640_CR4","doi-asserted-by":"crossref","unstructured":"Badra, M.: NETCONF over transport layer security (TLS). RFC 5539 (2009). 10.17487\/RFC5539. https:\/\/rfc-editor.org\/rfc\/rfc5539.txt","DOI":"10.17487\/rfc5539"},{"issue":"4","key":"9640_CR5","doi-asserted-by":"publisher","first-page":"1575","DOI":"10.1007\/s10922-020-09551-y","volume":"28","author":"P Bellavista","year":"2020","unstructured":"Bellavista, P., Dolci, A., Giannelli, C., Padalino Montenero, D.D.: SDN-based traffic management middleware for spontaneous WMNs. J. Netw. Syst. Manag. 28(4), 1575\u20131609 (2020). https:\/\/doi.org\/10.1007\/s10922-020-09551-y","journal-title":"J. Netw. Syst. Manag."},{"key":"9640_CR6","doi-asserted-by":"publisher","unstructured":"Bj\u00f6rklund, M.: YANG\u2014a data modeling language for the network configuration protocol (NETCONF). RFC 6020 (2010). https:\/\/doi.org\/10.17487\/RFC6020.","DOI":"10.17487\/RFC6020"},{"key":"9640_CR9","doi-asserted-by":"publisher","unstructured":"Cullen, M.: Using the NETCONF protocol over Secure Shell (SSH). RFC 6242 (2011). https:\/\/doi.org\/10.17487\/RFC6242.","DOI":"10.17487\/RFC6242"},{"issue":"4","key":"9640_CR8","doi-asserted-by":"publisher","first-page":"784","DOI":"10.1007\/s10922-017-9423-2","volume":"25","author":"WL da Costa Cordeiro","year":"2017","unstructured":"da Costa Cordeiro, W.L., Marques, J.A., Gaspary, L.P.: Data plane programmability beyond openflow: opportunities and challenges for network and service operations and management. J. Netw. Syst. Manag. 25(4), 784\u2013818 (2017). https:\/\/doi.org\/10.1007\/s10922-017-9423-2","journal-title":"J. Netw. Syst. Manag."},{"key":"9640_CR10","doi-asserted-by":"publisher","unstructured":"Enns, R., Bj\u00f6rklund, M., Bierman, A., Sch\u00f6nw\u00e4lder, J.: Network configuration protocol (NETCONF). RFC 6241 (2011). https:\/\/doi.org\/10.17487\/RFC6241.","DOI":"10.17487\/RFC6241"},{"key":"9640_CR11","doi-asserted-by":"publisher","unstructured":"Fedor, M., Schoffstall, M.L., Davin, J.R., Case, D.J.D.: Simple network management protocol (SNMP). RFC 1157 (1990). https:\/\/doi.org\/10.17487\/RFC1157.","DOI":"10.17487\/RFC1157"},{"key":"9640_CR12","unstructured":"Google Anthos Service Mesh. https:\/\/cloud.google.com\/anthos\/service-mesh5. Accessed 2 Dec 2020."},{"key":"9640_CR13","unstructured":"Google Transparency Report. https:\/\/transparencyreport.google.com\/https\/overview. Accessed 5 Dec 2020."},{"issue":"4","key":"9640_CR14","doi-asserted-by":"publisher","first-page":"320","DOI":"10.1109\/MNET.001.1900554","volume":"34","author":"H Hantouti","year":"2020","unstructured":"Hantouti, H., Benamar, N., Taleb, T.: Service function chaining in 5G beyond networks: challenges and open research issues. IEEE Netw. 34(4), 320\u2013327 (2020). https:\/\/doi.org\/10.1109\/MNET.001.1900554","journal-title":"IEEE Netw."},{"key":"9640_CR15","doi-asserted-by":"publisher","DOI":"10.1016\/j.cosrev.2021.100366","author":"L Helali","year":"2021","unstructured":"Helali, L., Omri, M.N.: A survey of data center consolidation in cloud computing systems. Comput. Sci. Rev. (2021). https:\/\/doi.org\/10.1016\/j.cosrev.2021.100366","journal-title":"Comput. Sci. Rev."},{"key":"9640_CR16","unstructured":"IBM Cloud Private. Encrypting cluster data network traffic with IPsec. https:\/\/www.ibm.com\/support\/knowledgecenter\/en\/SSBS6K_3.1.0\/installing\/ipsec_mesh.html. Accessed 2 Dec 2020."},{"key":"9640_CR17","unstructured":"Interface to Network Security Functions (I2NSF) Working Group. https:\/\/datatracker.ietf.org\/wg\/i2nsf\/about\/. Accessed 9 Dec 2020."},{"key":"9640_CR18","unstructured":"Istio 1.8. Security architecture. https:\/\/istio.io\/latest\/docs\/concepts\/security\/. Accessed 2 Dec 2020."},{"key":"9640_CR19","unstructured":"(ITU-T), I.T.U.: Framework of software-defined networking (itu-t y.3300) (2014)"},{"key":"9640_CR20","doi-asserted-by":"crossref","unstructured":"Kreutz, D., Ramos, F.M., Verissimo, P.: Towards secure and dependable software-defined networks. In: Proceedings of the Second ACM SIGCOMM Workshop on Hot Topics in Software Defined Networking, HotSDN \u201913, p. 55-60. Association for Computing Machinery, New York, NY, USA (2013). https:\/\/doi.org\/10.1145\/2491185.2491199","DOI":"10.1145\/2491185.2491199"},{"issue":"1","key":"9640_CR21","doi-asserted-by":"publisher","first-page":"14","DOI":"10.1109\/JPROC.2014.2371999","volume":"103","author":"D Kreutz","year":"2015","unstructured":"Kreutz, D., Ramos, F.M.V., Ver\u00edssimo, P.E., Rothenberg, C.E., Azodolmolky, S., Uhlig, S.: Software-defined networking: a comprehensive survey. Proc. IEEE 103(1), 14\u201376 (2015). https:\/\/doi.org\/10.1109\/JPROC.2014.2371999","journal-title":"Proc. IEEE"},{"key":"9640_CR22","unstructured":"Linkerd 2.x. Securing your service. https:\/\/linkerd.io\/2\/tasks\/securing-your-service\/. Accessed 2 Dec 2020."},{"key":"9640_CR23","doi-asserted-by":"publisher","unstructured":"Lopez-Millan, G., Marin-Lopez, R., Pereniguez-Garcia, F.: Towards a standard SDN-based IPsec management framework. Comput. Stand. Interfaces 66,(2019). https:\/\/doi.org\/10.1016\/j.csi.2019.103357","DOI":"10.1016\/j.csi.2019.103357"},{"key":"9640_CR24","doi-asserted-by":"publisher","unstructured":"Marin-Lopez, R., Lopez-Millan, G., Pereniguez-Garcia, F.: A YANG data model for IPsec flow protection based on software-defined networking (SDN). RFC 9061 (2021). https:\/\/doi.org\/10.17487\/RFC9061","DOI":"10.17487\/RFC9061"},{"key":"9640_CR25","doi-asserted-by":"publisher","unstructured":"Michel, O., Keller, E.: Sdn in wide-area networks: a survey. In: 2017 Fourth International Conference on Software Defined Systems (SDS), pp. 37\u201342 (2017). https:\/\/doi.org\/10.1109\/SDS.2017.7939138","DOI":"10.1109\/SDS.2017.7939138"},{"key":"9640_CR7","unstructured":"Network Services Orchestrator VPN Solution Overview. https:\/\/www.cisco.com\/c\/en\/us\/products\/collateral\/cloud-systems-management\/network-services-orchestrator\/solution-overview-c22-734917.html. Accessed 2 Dec 2020."},{"key":"9640_CR26","unstructured":"Open networking foundation: OF-CONFIG version 1, 2 (2014)"},{"key":"9640_CR27","unstructured":"Open networking foundation: openflow switch specification version 1.5.1 (2015)"},{"key":"9640_CR29","unstructured":"OpenSSL. Cryptography and SSL\/TLS Toolkit. https:\/\/www.openssl.org\/. Accessed 3 Dec 2020."},{"key":"9640_CR30","unstructured":"OpenVPN. https:\/\/openvpn.net\/. Accessed 3 Dec 2020."},{"key":"9640_CR31","doi-asserted-by":"crossref","unstructured":"Pashkov, V., Shalimov, A., Smeliansky, R.: Controller failover for SDN enterprise networks. In: 2014 International Science and Technology Conference (Modern Networking Technologies) (MoNeTeC), pp. 1\u20136 (2014).","DOI":"10.1109\/MoNeTeC.2014.6995594"},{"key":"9640_CR32","doi-asserted-by":"crossref","unstructured":"Ranjbar, A., Komu, M., Salmela, P., Aura, T.: An SDN-based approach to enhance the end-to-end security: SSL\/TLS case study. In: NOMS 2016 - 2016 IEEE\/IFIP Network Operations and Management Symposium, pp. 281\u2013288 (2016).","DOI":"10.1109\/NOMS.2016.7502823"},{"key":"9640_CR33","unstructured":"RedHat OpenShift. Encrypting traffic between nodes with IPsec. https:\/\/docs.openshift.com\/container-platform\/3.11\/admin_guide\/ipsec.html. Accessed 2 Dec 2020."},{"key":"9640_CR28","unstructured":"RedHat OpenShift Service Mesh. https:\/\/docs.openshift.com\/container-platform\/4.6\/service_mesh\/v2x\/ossm-security.html. Accessed 2 Dec 2020."},{"key":"9640_CR34","doi-asserted-by":"crossref","unstructured":"Rescorla, E.: The transport layer security (TLS) protocol version 1.3. RFC 8446 (2018). 10.17487\/RFC8446.","DOI":"10.17487\/RFC8446"},{"issue":"2","key":"9640_CR35","doi-asserted-by":"publisher","first-page":"321","DOI":"10.1007\/s10922-016-9393-9","volume":"25","author":"S Singh","year":"2017","unstructured":"Singh, S., Jha, R.: A survey on software defined networking: architecture for next generation network. J. Netw. Syst. Manag. 25(2), 321\u2013374 (2017). https:\/\/doi.org\/10.1007\/s10922-016-9393-9","journal-title":"J. Netw. Syst. Manag."},{"key":"9640_CR36","doi-asserted-by":"publisher","unstructured":"Sousa, E., Cunha, V.A., de Carvalho, M.B., Corujo, D., Barraca, J.P., Gomes, D., Schaeffer-Filho, A.E., dos Santos, C.R.P., Granville, L.Z., Aguiar, R.L.: Orchestrating an SFC-enabled SSL\/TLS traffic processing architecture using MANO. In: 2018 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN), pp. 1\u20137 (2018). https:\/\/doi.org\/10.1109\/NFV-SDN.2018.8725675","DOI":"10.1109\/NFV-SDN.2018.8725675"},{"key":"9640_CR37","doi-asserted-by":"publisher","unstructured":"Suartana, I.M., Anggraini, M.A.N., Pramudita, A.Z.: High availability in software-defined networking using cluster controller: a simulation approach. In: 2020 Third International Conference on Vocational Education and Electrical Engineering (ICVEE), pp. 1\u20135 (2020). https:\/\/doi.org\/10.1109\/ICVEE50212.2020.9243173","DOI":"10.1109\/ICVEE50212.2020.9243173"},{"key":"9640_CR38","doi-asserted-by":"publisher","unstructured":"Vajaranta, M., Kannisto, J., Harju, J.: Implementation experiences and design challenges for resilient SDN based secure WAN overlays. In: 2016 11th Asia Joint Conference on Information Security (AsiaJCIS), pp. 17\u201323 (2016). https:\/\/doi.org\/10.1109\/AsiaJCIS.2016.25","DOI":"10.1109\/AsiaJCIS.2016.25"},{"key":"9640_CR39","doi-asserted-by":"crossref","unstructured":"Vajaranta, M., Kannisto, J., Harju, J.: IPsec and IKE as functions in SDN controlled network. In: Yan, Z., Molva, R., Mazurczyk, W., Kantola, R. (eds.) Network and system security, pp. 521\u2013530. Springer, Cham (2017)","DOI":"10.1007\/978-3-319-64701-2_39"},{"key":"9640_CR40","unstructured":"(W3C), W.W.W.C.: Extensible markup language (XML). www.w3.org\/TR\/xml\/ (2013)"},{"key":"9640_CR41","unstructured":"Watsen, K.: YANG groupings for TLS clients and TLS servers. Internet-draft draft-ietf-netconf-tls-client-server-22, Internet Engineering Task Force (2020). https:\/\/datatracker.ietf.org\/doc\/html\/draft-ietf-netconf-tls-client-server-22 (Work in Progress)."},{"key":"9640_CR42","unstructured":"YANG Catalog. https:\/\/yangcatalog.org\/. Accessed 5 Apr 2021."},{"key":"9640_CR43","doi-asserted-by":"publisher","unstructured":"Yin, H., Xie, H., Tsou, T., Lopez, D.R., Aranda, P.A., Sidi, R.: Interface to network security functions (I2NSF): problem statement and use cases. RFC 8192 (2017). https:\/\/doi.org\/10.17487\/RFC8192.","DOI":"10.17487\/RFC8192"}],"container-title":["Journal of Network and Systems Management"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10922-021-09640-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10922-021-09640-6\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10922-021-09640-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,3,2]],"date-time":"2022-03-02T15:08:21Z","timestamp":1646233701000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10922-021-09640-6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,1,20]]},"references-count":43,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2022,4]]}},"alternative-id":["9640"],"URL":"https:\/\/doi.org\/10.1007\/s10922-021-09640-6","relation":{},"ISSN":["1064-7570","1573-7705"],"issn-type":[{"value":"1064-7570","type":"print"},{"value":"1573-7705","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,1,20]]},"assertion":[{"value":"7 May 2021","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"20 September 2021","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"12 November 2021","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"20 January 2022","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no known competing financial interests or personal relationships that could have appeared to influence the work reported in this paper.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}],"article-number":"24"}}