动态协作组的可扩展覆盖网络部署

Norihito Fujita, Y. Ishikawa, T. Koide, Akira Tsukamoto
{"title":"动态协作组的可扩展覆盖网络部署","authors":"Norihito Fujita, Y. Ishikawa, T. Koide, Akira Tsukamoto","doi":"10.1109/SAINT.2005.56","DOIUrl":null,"url":null,"abstract":"Scalable deployment and management of overlay networks for collaborative groups with dynamic membership are discussed. In deploying overlay networks for such dynamic groups, unlike in pre-defined static VPN deployment, a mechanism to keep security policies in member nodes updated for membership changes and a mechanism to adaptively reconfigure a topology must be supported. However, previous approaches have scalability problems in supporting these mechanisms. We propose a scalable overlay network deployment scheme to minimize the impact of membership changes. In the scheme, the IPsec policy required for delivering packets to a destination node is resolved on an on-demand basis to eliminate the advertisement-based updates of membership changes. Our approach also provides two modes of overlay topology operation to address dynamic changes in the number of nodes. While the mesh mode eliminates a tunnel initiation/teardown behavior for membership changes, the graph mode creates a graph-structured topology reconfigurable with a constant number of initiated/torn-down tunnels for node joins/leaves. We evaluate a management server load on dynamic membership changes and show the efficient performance of our scheme for increasing the number of nodes. We also show that our topology reconfiguration algorithm provides a smaller number of initiated/torn-down tunnels for changes in the number of nodes than previous approaches.","PeriodicalId":169669,"journal":{"name":"The 2005 Symposium on Applications and the Internet","volume":"110 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2005-01-31","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"5","resultStr":"{\"title\":\"Scalable overlay network deployment for dynamic collaborative groups\",\"authors\":\"Norihito Fujita, Y. Ishikawa, T. Koide, Akira Tsukamoto\",\"doi\":\"10.1109/SAINT.2005.56\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Scalable deployment and management of overlay networks for collaborative groups with dynamic membership are discussed. In deploying overlay networks for such dynamic groups, unlike in pre-defined static VPN deployment, a mechanism to keep security policies in member nodes updated for membership changes and a mechanism to adaptively reconfigure a topology must be supported. However, previous approaches have scalability problems in supporting these mechanisms. We propose a scalable overlay network deployment scheme to minimize the impact of membership changes. In the scheme, the IPsec policy required for delivering packets to a destination node is resolved on an on-demand basis to eliminate the advertisement-based updates of membership changes. Our approach also provides two modes of overlay topology operation to address dynamic changes in the number of nodes. While the mesh mode eliminates a tunnel initiation/teardown behavior for membership changes, the graph mode creates a graph-structured topology reconfigurable with a constant number of initiated/torn-down tunnels for node joins/leaves. We evaluate a management server load on dynamic membership changes and show the efficient performance of our scheme for increasing the number of nodes. We also show that our topology reconfiguration algorithm provides a smaller number of initiated/torn-down tunnels for changes in the number of nodes than previous approaches.\",\"PeriodicalId\":169669,\"journal\":{\"name\":\"The 2005 Symposium on Applications and the Internet\",\"volume\":\"110 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2005-01-31\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"5\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"The 2005 Symposium on Applications and the Internet\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/SAINT.2005.56\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"The 2005 Symposium on Applications and the Internet","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SAINT.2005.56","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 5

摘要

讨论了具有动态成员的协作组覆盖网络的可伸缩部署和管理。在为这样的动态组部署覆盖网络时,与预定义的静态VPN部署不同,必须支持一种机制,使成员节点中的安全策略在成员变更时保持更新,并支持一种机制,以自适应地重新配置拓扑。但是,以前的方法在支持这些机制方面存在可伸缩性问题。我们提出了一种可扩展的覆盖网络部署方案,以尽量减少成员变化的影响。在该方案中,按需解析向目的节点发送报文所需的IPsec策略,从而消除了基于公告的成员变更更新。我们的方法还提供了两种覆盖拓扑操作模式,以解决节点数量的动态变化。虽然网格模式消除了成员关系变化时的隧道启动/拆除行为,但图形模式创建了一个图结构拓扑,可通过恒定数量的节点连接/叶子启动/拆除隧道进行重构。我们评估了动态成员关系变化时管理服务器的负载,并展示了我们的方案在增加节点数量方面的高效性能。我们还表明,与以前的方法相比,我们的拓扑重构算法为节点数量的变化提供了更少的初始化/拆除隧道。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Scalable overlay network deployment for dynamic collaborative groups
Scalable deployment and management of overlay networks for collaborative groups with dynamic membership are discussed. In deploying overlay networks for such dynamic groups, unlike in pre-defined static VPN deployment, a mechanism to keep security policies in member nodes updated for membership changes and a mechanism to adaptively reconfigure a topology must be supported. However, previous approaches have scalability problems in supporting these mechanisms. We propose a scalable overlay network deployment scheme to minimize the impact of membership changes. In the scheme, the IPsec policy required for delivering packets to a destination node is resolved on an on-demand basis to eliminate the advertisement-based updates of membership changes. Our approach also provides two modes of overlay topology operation to address dynamic changes in the number of nodes. While the mesh mode eliminates a tunnel initiation/teardown behavior for membership changes, the graph mode creates a graph-structured topology reconfigurable with a constant number of initiated/torn-down tunnels for node joins/leaves. We evaluate a management server load on dynamic membership changes and show the efficient performance of our scheme for increasing the number of nodes. We also show that our topology reconfiguration algorithm provides a smaller number of initiated/torn-down tunnels for changes in the number of nodes than previous approaches.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信