SDP-FW: Managing Transient Authorization in Software-Defined Perimeters for Zero Trust Networks
Software-Defined Perimeter (SDP) hides protected services until communicating entities have been authenticated and authorized. In operational SDP gateways, each successful Single Packet Authorization (SPA) request creates transient authorization state that must be enforced and subsequently revoked, potentially imposing substantial rule-management overhead under high-churn access workloads. This paper presents SDP-FW, a dynamic firewall architecture for managing transient authorization in SDP-based Zero Trust networks. SDP-FW uses Time-Based One-Time Password (TOTP)-based dynamic SPA port selection to reduce the persistence of the SPA entry point and a remove-after-connection strategy to promptly remove temporary firewall openings after connection establishment. It further separates authorization-state tracking, implemented with a scalable counting Bloom filter, from kernel-level packet enforcement through Netfilter hooks and connection tracking. We implement an SDP-FW prototype in the Linux kernel and evaluate its security properties, runtime performance, and storage cost. Comparisons with iptables, ipset, nftables, and eBPF further characterize its performance and storage behavior. Experimental results show that SDP-FW maintains efficient insertion, lookup, and removal as the number of transient authorization states increases, while the measured remove-after-connection mechanism substantially shortens the residual exposure window.
Authors
- Junfei Cai (ORCID: https://orcid.org/0000-0002-8062-052X)
- Nuannuan Li (ORCID: https://orcid.org/0000-0002-2363-1572)
- Qi Wang (ORCID: https://orcid.org/0000-0003-3694-5826)
- Jinghong Lan (ORCID: https://orcid.org/0000-0003-0051-5963)
- Yunpeng Li (ORCID: https://orcid.org/0000-0003-2176-5291)
- Yujian Zhang (ORCID: https://orcid.org/0000-0002-9531-9828)
- Cen Chen (ORCID: https://orcid.org/0000-0003-0325-1705)
- Tianyi Wang
Institutions
- State Grid Henan Electric Power Company (China) (CN)
- Southeast University (CN)
Publication Details
- Journal
- Future Internet
- Published
- 2026-09-28
- DOI
- https://doi.org/10.3390/fi18100515
- Primary Topic
- Network Packet Processing and Optimization
- Type
- article
- Field-Weighted Citation Impact
- 0.00