• 제목/요약/키워드: network virtualization

검색결과 245건 처리시간 0.027초

Virtual Network Embedding through Security Risk Awareness and Optimization

  • Gong, Shuiqing;Chen, Jing;Huang, Conghui;Zhu, Qingchao;Zhao, Siyi
    • KSII Transactions on Internet and Information Systems (TIIS)
    • /
    • 제10권7호
    • /
    • pp.2892-2913
    • /
    • 2016
  • Network virtualization promises to play a dominant role in shaping the future Internet by overcoming the Internet ossification problem. However, due to the injecting of additional virtualization layers into the network architecture, several new security risks are introduced by the network virtualization. Although traditional protection mechanisms can help in virtualized environment, they are not guaranteed to be successful and may incur high security overheads. By performing the virtual network (VN) embedding in a security-aware way, the risks exposed to both the virtual and substrate networks can be minimized, and the additional techniques adopted to enhance the security of the networks can be reduced. Unfortunately, existing embedding algorithms largely ignore the widespread security risks, making their applicability in a realistic environment rather doubtful. In this paper, we attempt to address the security risks by integrating the security factors into the VN embedding. We first abstract the security requirements and the protection mechanisms as numerical concept of security demands and security levels, and the corresponding security constraints are introduced into the VN embedding. Based on the abstraction, we develop three security-risky modes to model various levels of risky conditions in the virtualized environment, aiming at enabling a more flexible VN embedding. Then, we present a mixed integer linear programming formulation for the VN embedding problem in different security-risky modes. Moreover, we design three heuristic embedding algorithms to solve this problem, which are all based on the same proposed node-ranking approach to quantify the embedding potential of each substrate node and adopt the k-shortest path algorithm to map virtual links. Simulation results demonstrate the effectiveness and efficiency of our algorithms.

Cell Virtualization with Network Partition for Initial User Association in Software Defined Small-cell Networks

  • Sun, Guolin;Lu, Li;Ayepah-Mensah, Daniel;Fang, Xiufen;Jiang, Wei
    • KSII Transactions on Internet and Information Systems (TIIS)
    • /
    • 제12권10호
    • /
    • pp.4703-4723
    • /
    • 2018
  • In recent years, dense small cell network has been deployed to address the challenge that has resulted from the unprecendented growth of mobile data traffic and users. It has proven to be a cost efficeient solution to offload traffic from macro-cells. Software defined heterogeneous wireless network can decouple the control plane from the data plane. The control signal goes through the macro-cell while the data traffic can be offloaded by small cells. In this paper, we propose a framework for cell virtualization and user association in order to satisfy versatile requirements of multiple tenants. In the proposed framework, we propose an interference graph partioning based virtual-cell association and customized physical-cell association for multi-homed users in a software defined small cell network. The proposed user association scheme includes 3 steps: initialization, virtual-cell association and physical-cell association. Simulation results show that the proposed virtual-cell association outperforms the other schemes. For physical-cell association, the results on resource utilization and user fairness are examined for mobile users and infrastructure providers.

IOMMU Para-Virtualization for Efficient and Secure DMA in Virtual Machines

  • Tang, Hongwei;Li, Qiang;Feng, Shengzhong;Zhao, Xiaofang;Jin, Yan
    • KSII Transactions on Internet and Information Systems (TIIS)
    • /
    • 제10권12호
    • /
    • pp.5375-5400
    • /
    • 2016
  • IOMMU is a hardware unit that is indispensable for DMA. Besides address translation and remapping, it also provides I/O virtual address space isolation among devices and memory access control on DMA transactions. However, currently commodity virtualization platforms lack of IOMMU virtualization, so that the virtual machines are vulnerable to DMA security threats. Previous works focus only on DMA security problem of directly assigned devices. Moreover, these solutions either introduce significant overhead or require modifications on the guest OS to optimize performance, and none can achieve high I/O efficiency and good compatibility with the guest OS simultaneously, which are both necessary for production environments. However, for simulated virtual devices the DMA security problem also exists, and previous works cannot solve this problem. The reason behind that is IOMMU circuits on the host do not work for this kind of devices as DMA operations of which are simulated by memory copy of CPU. Motivated by the above observations, we propose an IOMMU para-virtualization solution called PVIOMMU, which provides general functionalities especially DMA security guarantees for both directly assigned devices and simulated devices. The prototype of PVIOMMU is implemented in Qemu/KVM based on the virtio framework and can be dynamically loaded into guest kernel as a module, As a result, modifying and rebuilding guest kernel are not required. In addition, the device model of Qemu is revised to implement DMA access control by separating the device simulator from the address space of the guest virtual machine. Experimental evaluations on three kinds of network devices including Intel I210 (1Gbps), simulated E1000 (1Gbps) and IB ConnectX-3 (40Gbps) show that, PVIOMMU introduces little overhead on DMA transactions, and in general the network I/O performance is close to that in the native KVM implementation without IOMMU virtualization.

방송 인프라의 클라우드 및 가상화 동향 (Trends of Cloud and Virtualization in Broadcast Infra)

  • 김순철;오혜주;임현정;현은희;최동준
    • 전자통신동향분석
    • /
    • 제34권3호
    • /
    • pp.23-33
    • /
    • 2019
  • Broadcast is evolving into media service aimed at user customization, personalization, and participation with high-quality broadcasting contents (4K/8K/AR/VR). A broadcast infrastructure is needed to engage with the competition for providing large-scaled media traffic process, platform performance for adaptive transcoding to diverse receivers, and intelligent service. Cloud service and virtualization in broadcast are becoming more valuable as the broadcasting environment changes and new high-level broadcasting services emerge. This document describes the examples of cloud and virtualization in the broadcast industry, and prospects the network virtualization of broadcast transmission infrastructure, especially terrestrial and cable networks.

위성/이동 통신 시스템에서의 가상화 기술 동향 (Virtualization Technology Trends in Satellite/Mobile Communication Systems)

  • 이승규;이준환;이문식
    • 전자통신동향분석
    • /
    • 제39권1호
    • /
    • pp.36-47
    • /
    • 2024
  • Virtualization technology supports the execution of software unrelated to the hardware environment through the decoupling of software and hardware. Additionally, it enables network slicing, allowing one physical device to be divided and used by a function or service by supporting sharing with isolation. Virtualization enables flexible platform use, allowing a variety of services to be launched without changes or additions to the hardware platform. We describe virtualization technology trends in satellite/mobile communication systems. Basic concepts and technical definitions are included, and the current status of research and development by domestic and foreign organizations, including the Electronics and Telecommunications Research Institute, is analyzed. Finally, future prospects and implications are discussed.

Towards Scalable and Cost-efficient Software-Defined 5G Core Network

  • 박종한;최창순;정상수;나민수;조성호
    • 정보와 통신
    • /
    • 제33권6호
    • /
    • pp.18-26
    • /
    • 2016
  • Network and network functions virtualization (NFV) promise a number of attractive benefits and thus have driven mobile network operators to transform their previously static networks to more dynamic and software-defined networks. In this article, we share a mobile network operator's view based on implementation and deployment experiences in the wild during the past few years towards a software-defined 5G core network. More specifically, we present a practical point of view from mobile network operators and elaborate on why some of the virtualization benefits such as total cost of ownership (TCO) reduction are not easily realized as initially intended. Then, we describe 5G visions, services, and their requirements commonly agreed across mobile operators globally. Given the requirements, we then introduce desirable characteristics of 5G mobile core network and its key enabling technologies.

입출력 가상화 기반 가상 데스크탑 서비스를 이용한 물리적 네트워크 망분리 시스템 설계 및 구현 (Design and Implementation of a Physical Network Separation System using Virtual Desktop Service based on I/O Virtualization)

  • 김선욱;김성운;김학영;정성권;이숙영
    • 정보과학회 컴퓨팅의 실제 논문지
    • /
    • 제21권7호
    • /
    • pp.506-511
    • /
    • 2015
  • 입출력 가상화는 하나의 물리적 입출력 장치를 하나 이상의 가상 데스크탑들이 공유해서 사용 할 수 있도록 하는 기술로서 일반적으로 가상화 소프트웨어가 소프트웨어적으로 에뮬레이션하여 제공하는 가상 I/O 장치들을 가상 데스크탑에서 사용한다. 소프트웨어 에뮬레이션 기반 I/O 장치들을 사용하는 가상 데스크탑들은 성능이 떨어지고 고사양의 응용 프로그램을 지원할 수 없는 문제점을 가지고 있다. 본 논문에서는 이러한 서비스의 품질 및 성능 저하를 극복하기 위해 PCI기반 하드웨어 직접 할당기술을 이용한 망분리 가상 데스크탑 시스템을 제안한다. 제안하는 시스템은 하나의 물리적 데스크탑 컴퓨터에 서버 가상화 기술을 이용하여 사용자에게 인터넷 등의 외부망과 인트라넷 등의 업무망 접속을 위한 독립적인 데스크탑을 제공한다. 이를 통해 물리적 망분리를 위한 별도의 데스크탑 설치 및 논리적 망분리를 위한 네트워크 패킷의 검사에 따른 성능의 저하 없이 가상 데스크탑 서비스를 이용한 물리적 네트워크 망분리 시스템을 제공한다.

M-CORD 기반의 네트워크 슬라이스 선택 기능 (Network Slice Selection Function on M-CORD)

  • 디아즈 리베라 하비에르;칸 탈하 애흐마드;메흐무드 아시프;송왕철
    • KNOM Review
    • /
    • 제21권2호
    • /
    • pp.35-45
    • /
    • 2018
  • 네트워크 슬라이싱 기능이 모바일 네트워킹에 적용되면서 네트워크 슬라이스를 선택할 수 있는 메커니즘이 필수적이다. 5G 아키텍처에 대한 3GPP 표준 기술 사양에 따라 슬라이스 선택 프로세스를 활용하기 위해 Network Slice Selection Function (NSSF)가 포함되어 있다. 이 네트워크 기능의 실제 구현은 네트워크 인스턴스의 동적 변경 사항을 처리해야하므로 가상 네트워크 기능 (VNF)의 오케스트레이션을 지원하는 플랫폼이 필요하다. 제안 된 솔루션은 Central Office Rearchitected as a Data Center (CORD) 플랫폼에서 모바일 네트워크용으로 특화된 M-CORD를 사용하고 있다. 이는 서비스 오케스트레이터인 XoS를 통합하는 플랫폼 및 Software Defined Networking (SDN), Network Function Virtualization (NFV) 및 클라우드를 관리하는 OpenStack에 기반하고 있다. 이 플랫폼을 통해, 본 논문에서 제시된 NSSF 구현은 백엔드 서비스와 네트워크 기능 인스턴스 간의 동기화를 통해서 동적으로 슬라이스 정보를 얻을 수 있는 적절한 생태계를 제공하고 있다.

서버통합 및 가상화를 위한 효율적인 소프트웨어 라이선싱 관리전략에 관한 연구 : N-데이터센터를 중심으로 (Efficient Software Licensing Management Strategy for Server Consolidation and Virtualization Using the N-Datacenter Case)

  • 최영진;나종회;최광돈
    • 한국IT서비스학회지
    • /
    • 제10권4호
    • /
    • pp.281-293
    • /
    • 2011
  • Server consolidation and virtualization have become an integral part of IT planning to reduce TCO cost and ensure the high availability for customer, enlarge the flexibility to computing resource in today' enterprise data centers. In spite of having the variety advantages of server consolidation and virtualization, they cause many problems such as the software licensing issues, virtual server sprawl, network complexity issues, hardware start-up costs, and failover costs. In particular, software licensing problem brings about the serious results in operating of data center and also presents a significant challenge to virtualization because many vendors have realized that licensing policies applicable to physical systems are not compatible with virtual machines. So, the IT planers must be considering this problem before they conducts the server consolidation and virtualization. In this paper, we proposed the efficiency strategy of SW licensing for server consolidation and virtualization analyzing the N-Datacenter case in Korea. As a result, we suggest the two strategies as technical and management/contract aspect. First, as the technical aspect, we propose i) the adaptation of suitable licensing for virtualization, ii) differentiation of license according to the characteristics of server, iii) the core distribution of licenses to minimizing. Second, as the management/contract aspect, we suggest following three things. i) The existing license agreement is changed to the right licensing for virtualization. ii) The license agreement is contracts the active focused. iii) When a new contract should be added to virtualization provisions.

SDDC BAS의 아키텍처에 관한 연구 (Architecture Study for SDDC BAS)

  • 김정욱
    • 한국산학기술학회논문지
    • /
    • 제16권1호
    • /
    • pp.646-651
    • /
    • 2015
  • 본 논문에서는 일반적인 건물자동제어 시스템의 아키텍처를 네트워크 구성과 관제점, 상호운영성, 성능 측면에서 분석하고, 점대점 고속 유선 방식으로 연결된 가상화 기반의 새로운 건물자동제어 시스템을 제시하였다. 클라우드 컴퓨팅 기반의 건물자동제어 시스템은 사용자 기반의 환경제어를 가능하게 하며 건물자동제어 시스템의 성능 향상을 통하여 건물에너지관리를 효율적으로 수행할 수 있다. 또한, 가상화 방식은 부하관리사업자의 건물 군관리를 효율적으로 수행할 수 있도록 한다.