BDSecChain: a Byzantine-resilient blockchain-assisted security algorithm for multi-controller SDN environments
摘要
In this paper, we propose BDSecChain, a blockchain-assisted conceptual security framework designed to secure communication within a multi-controller software-defined networking environment. Unlike existing work that solely uses the proof-of-work (PoW) or proof-of-stake (PoS) consensus mechanism for security, the BDSecChain conceptually integrates practical Byzantine fault-tolerance consensus (PBFT), zero-knowledge proofs (ZKPs), and a dual-chain architecture for enhanced security. Our proposed Byzantine Controller Detection and Isolation algorithm (BCDI) identifies the malicious controllers via decentralised voting and the zero-knowledge proof flow validation protocol algorithm. BDSecChain framework verifies the cryptographic proofs without revealing their content to other SDN controllers. Furthermore, our architecture uses permissioned blockchains like C-Chain and D-Chain to ensure scalability and transparency, and we have also provided a comparative analysis against related state-of-the-art approaches. Our comprehensive theoretical security analysis suggests BDSecChain can thwart switch hijacking, flow rule injection, and replay threats, confirming the method’s suitability for next-generation SDN deployment.