Verifying Network Properties in SRv6 based Service Function Chaining

Ryusei Shiiba, Satoru Kobayashi, Osamu Akashi, K. Fukuda
{"title":"Verifying Network Properties in SRv6 based Service Function Chaining","authors":"Ryusei Shiiba, Satoru Kobayashi, Osamu Akashi, K. Fukuda","doi":"10.1145/3497777.3498546","DOIUrl":null,"url":null,"abstract":"Segment Routing over IPv6 (SRv6) is a simple and scalable protocol for building service function chaining (SFC) on IPv6 data plane. Despite the benefits, managing the data plane of service chains in SRv6 is an error-prone task for network operators, especially in large-scale data center networks. Data plane verification is a promising approach to formally verify the operator requirements. However, the existing approaches do not fully support header modifications with a variable length header in SRv6 and network functions for the service chains. In this paper, we propose a new data plane verification approach for the service chain management. Unlike the existing works, our proposed data plane model for the verification naturally includes header modifications in SRv6 and network functions for the service chains. On the basis of the model, we develop a search-based verification technique for two fundamental network properties: network reachability and isolation of a service chain from the others. To confirm the appropriateness of the approach, we implement a data plane verifier based on the model. Using the verifier, we demonstrate the effectiveness of our approach in two case examples. Through the demonstration, we show that our approach is expressive enough to verify network properties for safely managing the service chains","PeriodicalId":248679,"journal":{"name":"Proceedings of the 16th Asian Internet Engineering Conference","volume":"53 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-12-14","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 16th Asian Internet Engineering Conference","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3497777.3498546","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

Abstract

Segment Routing over IPv6 (SRv6) is a simple and scalable protocol for building service function chaining (SFC) on IPv6 data plane. Despite the benefits, managing the data plane of service chains in SRv6 is an error-prone task for network operators, especially in large-scale data center networks. Data plane verification is a promising approach to formally verify the operator requirements. However, the existing approaches do not fully support header modifications with a variable length header in SRv6 and network functions for the service chains. In this paper, we propose a new data plane verification approach for the service chain management. Unlike the existing works, our proposed data plane model for the verification naturally includes header modifications in SRv6 and network functions for the service chains. On the basis of the model, we develop a search-based verification technique for two fundamental network properties: network reachability and isolation of a service chain from the others. To confirm the appropriateness of the approach, we implement a data plane verifier based on the model. Using the verifier, we demonstrate the effectiveness of our approach in two case examples. Through the demonstration, we show that our approach is expressive enough to verify network properties for safely managing the service chains
验证SRv6业务功能链中的网络属性
SRv6 (Segment Routing over IPv6)是在IPv6数据平面上构建业务功能链(SFC)的一种简单、可扩展的协议。尽管有这些好处,但对于网络运营商来说,在SRv6中管理服务链的数据平面是一项容易出错的任务,特别是在大型数据中心网络中。数据平面验证是一种很有前途的对运营商需求进行正式验证的方法。然而,现有的方法并不完全支持在SRv6和服务链的网络功能中使用可变长度报头修改报头。本文提出了一种新的用于服务链管理的数据平面验证方法。与现有的工作不同,我们提出的用于验证的数据平面模型自然包括SRv6中的报头修改和服务链的网络功能。在此模型的基础上,我们开发了一种基于搜索的验证技术,用于两个基本网络属性:网络可达性和服务链与其他服务链的隔离性。为了确认该方法的适当性,我们基于该模型实现了一个数据平面验证器。使用验证器,我们在两个案例中演示了我们方法的有效性。通过演示,我们表明我们的方法具有足够的表现力,可以验证网络属性以安全管理服务链
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信