SDP-FW: Managing Transient Authorization in Software-Defined Perimeters for Zero Trust Networks

Software-Defined Perimeter (SDP) hides protected services until communicating entities have been authenticated and authorized. In operational SDP gateways, each successful Single Packet Authorization (SPA) request creates transient authorization state that must be enforced and subsequently revoked, potentially imposing substantial rule-management overhead under high-churn access workloads. This paper presents SDP-FW, a dynamic firewall architecture for managing transient authorization in SDP-based Zero Trust networks. SDP-FW uses Time-Based One-Time Password (TOTP)-based dynamic SPA port selection to reduce the persistence of the SPA entry point and a remove-after-connection strategy to promptly remove temporary firewall openings after connection establishment. It further separates authorization-state tracking, implemented with a scalable counting Bloom filter, from kernel-level packet enforcement through Netfilter hooks and connection tracking. We implement an SDP-FW prototype in the Linux kernel and evaluate its security properties, runtime performance, and storage cost. Comparisons with iptables, ipset, nftables, and eBPF further characterize its performance and storage behavior. Experimental results show that SDP-FW maintains efficient insertion, lookup, and removal as the number of transient authorization states increases, while the measured remove-after-connection mechanism substantially shortens the residual exposure window.

Authors

Institutions

Publication Details

Journal
Future Internet
Published
2026-09-28
DOI
https://doi.org/10.3390/fi18100515
Primary Topic
Network Packet Processing and Optimization
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

SDP-FW: Managing Transient Authorization in Software-Defined Perimeters for Zero Trust Networks

Junfei Cai, Nuannuan Li, Qi Wang, Jinghong Lan et al.
Future Internet
Network Packet Processing and Optimization
article

SDP-FW: Managing Transient Authorization in Software-Defined Perimeters for Zero Trust Networks

Junfei Cai, Nuannuan Li, Qi Wang, Jinghong Lan, Yunpeng Li, Yujian Zhang, Cen Chen, Tianyi Wang
article en

Abstract

Software-Defined Perimeter (SDP) hides protected services until communicating entities have been authenticated and authorized. In operational SDP gateways, each successful Single Packet Authorization (SPA) request creates transient authorization state that must be enforced and subsequently revoked, potentially imposing substantial rule-management overhead under high-churn access workloads. This paper presents SDP-FW, a dynamic firewall architecture for managing transient authorization in SDP-based Zero Trust networks. SDP-FW uses Time-Based One-Time Password (TOTP)-based dynamic SPA port selection to reduce the persistence of the SPA entry point and a remove-after-connection strategy to promptly remove temporary firewall openings after connection establishment. It further separates authorization-state tracking, implemented with a scalable counting Bloom filter, from kernel-level packet enforcement through Netfilter hooks and connection tracking. We implement an SDP-FW prototype in the Linux kernel and evaluate its security properties, runtime performance, and storage cost. Comparisons with iptables, ipset, nftables, and eBPF further characterize its performance and storage behavior. Experimental results show that SDP-FW maintains efficient insertion, lookup, and removal as the number of transient authorization states increases, while the measured remove-after-connection mechanism substantially shortens the residual exposure window.

Future InternetVol. 18(10)
State Grid Henan Electric Power Company (China) (CN), Southeast University (CN)
Peace, Justice and strong institutions
Openalex Percentile: Top 6%
Network Packet Processing and Optimization
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

SDP-FW: Managing Transient Authorization in Software-Defined Perimeters for Zero Trust Networks — Junfei Cai, Nuannuan Li, et al. · Future Internet (2026) | TGRS Research Map | TGRS