30 research outputs found

    Automatic Intent-Based Secure Service Creation Through a Multilayer SDN Network Orchestration

    Full text link
    Growing traffic demands and increasing security awareness are driving the need for secure services. Current solutions require manual configuration and deployment based on the customer's requirements. In this work, we present an architecture for an automatic intent-based provisioning of a secure service in a multilayer - IP, Ethernet, and optical - network while choosing the appropriate encryption layer using an open-source software-defined networking (SDN) orchestrator. The approach is experimentally evaluated in a testbed with commercial equipment. Results indicate that the processing impact of secure channel creation on a controller is negligible. As the time for setting up services over WDM varies between technologies, it needs to be taken into account in the decision-making process.Comment: Parts of the presented work has received funding from the European Commission within the H2020 Research and Innovation Programme, under grant agreeement n.645127, project ACIN

    ACINO: Second year report on dissemination and communication activities

    Get PDF
    This ACINO deliverable presents the communication and dissemination activities performed by the consortium during the first two years of the project. We have communicated using our website, Twitter account and by various communication actions: The website saw over 3000 unique visitors during the first year and over 4000 during the second year; The consortium Twitter account had 49 followers at the end of the first year and 80 at the end of the second year. We posted 50 tweets during the first year and 40 more during the second year; We also held a press release and an interview in a magazine during the first year, and had three more similar communication actions during the second year. The dissemination activities have been composed of participation in public events where the goals and concepts of ACINO were presented via publications, presentation, workshops, courses and demonstrations. Overall, over forty different dissemination activities have been performed: An article has been published in peer-reviewed, open access Journal of Green Engineering; Eighteen articles have been published in conferences: four during the first year and fourteen during the second. One of them was a post-deadline and six were invited papers; We have co-organised three workshops: the Workshop on Network Function Virtualization and Programmable Networks at EUCNC 2015, the first Workshop on Multi-Layer Network Orchestration (NetOrch) at ICTON 2016 and the stand-alone ONOS/CORD workshop; We have held 16 talks, tutorial, courses and demonstrations; Consortium members have won two prizes for work related to ACINO: a team of developers won the 3rd prize of the ONOS Build Hackathon, and Telef贸nica won the Best SDN-NFV solution award at the LTE and 5G World conference by presenting a solution in which Sedona Systems was involved; We have contributed to six IETF standardisation documents and done some implementation and test of these standards. We have contributed to two open source projects: the NetPhony and ONOS controllers, with the implementation of main features being accepted and merged to the core code of these open source projects. Finally, the project has devised detailed plans for its dissemination activities for the last year of the project. We have: Confirmed plans for the organisation of a workshop, the second edition of the NetOrch workshop, co-located with the ICTON conference; A solid plan for continued dissemination in conferences (already five accepted conference papers, five talk invitations and a list of conferences of interest) and in peer-reviewed journals, with one article accepted for publication in the Journal of Lightwave Technology, two articles under review and plans for four more; Some more planned contribution to open source projects

    Intent-Based In-flight Service Encryption in Multi-Layer Transport Networks

    Full text link
    We demonstrate multi-layer encrypted service provisioning via the ACINO orchestrator. ACINO combines a novel intent interface with an ONOS-based SDN orchestrator to facilitate encrypted services at IP, Ethernet and optical network layers.Comment: Optical Fiber Communication Conferenc

    Integrated IT and SDN Orchestration of multi-domain multi-layer transport networks

    Get PDF
    Telecom operators networks' management and control remains partitioned by technology, equipment supplier and networking layer. In some segments, the network operations are highly costly due to the need of the individual, and even manual, configuration of the network equipment by highly specialized personnel. In multi-vendor networks, expensive and never ending integration processes between Network Management Systems (NMSs) and the rest of systems (OSSs, BSSs) is a common situation, due to lack of adoption of standard interfaces in the management systems of the different equipment suppliers. Moreover, the increasing impact of the new traffic flows introduced by the deployment of massive Data Centers (DCs) is also imposing new challenges that traditional networking is not ready to overcome. The Fifth Generation of Mobile Technology (5G) is also introducing stringent network requirements such as the need of connecting to the network billions of new devices in IoT paradigm, new ultra-low latency applications (i.e., remote surgery) and vehicular communications. All these new services, together with enhanced broadband network access, are supposed to be delivered over the same network infrastructure. In this PhD Thesis, an holistic view of Network and Cloud Computing resources, based on the recent innovations introduced by Software Defined Networking (SDN), is proposed as the solution for designing an end-to-end multi-layer, multi-technology and multi-domain cloud and transport network management architecture, capable to offer end-to-end services from the DC networks to customers access networks and the virtualization of network resources, allowing new ways of slicing the network resources for the forthcoming 5G deployments. The first contribution of this PhD Thesis deals with the design and validation of SDN based network orchestration architectures capable to improve the current solutions for the management and control of multi-layer, multi-domain backbone transport networks. These problems have been assessed and progressively solved by different control and management architectures which has been designed and evaluated in real evaluation environments. One of the major findings of this work has been the need of developed a common information model for transport network's management, capable to describe the resources and services of multilayer networks. In this line, the Control Orchestration Protocol (COP) has been proposed as a first contriution towards an standard management interface based on the main principles driven by SDN. Furthermore, this PhD Thesis introduces a novel architecture capable to coordinate the management of IT computing resources together with inter- and intra-DC networks. The provisioning and migration of virtual machines together with the dynamic reconfiguration of the network has been successfully demonstrated in a feasible timescale. Moreover, a resource optimization engine is introduced in the architecture to introduce optimization algorithms capable to solve allocation problems such the optimal deployment of Virtual Machine Graphs over different DCs locations minimizing the inter-DC network resources allocation. A baseline blocking probability results over different network loads are also presented. The third major contribution is the result of the previous two. With a converged cloud and network infrastructure controlled and operated jointly, the holistic view of the network allows the on-demand provisioning of network slices consisting of dedicated network and cloud resources over a distributed DC infrastructure interconnected by an optical transport network. The last chapters of this thesis discuss the management and orchestration of 5G slices based over the control and management components designed in the previous chapters. The design of one of the first network slicing architectures and the deployment of a 5G network slice in a real Testbed, is one of the major contributions of this PhD Thesis.La gesti贸n y el control de las redes de los operadores de red (Telcos), todav铆a hoy, est谩 segmentado por tecnolog铆a, por proveedor de equipamiento y por capa de red. En algunos segmentos (por ejemplo en IP) la operaci贸n de la red es tremendamente costosa, ya que en muchos casos a煤n se requiere con guraci贸n individual, e incluso manual, de los equipos por parte de personal altamente especializado. En redes con m煤ltiples proveedores, los procesos de integraci贸n entre los sistemas de gesti贸n de red (NMS) y el resto de sistemas (p. ej., OSS/BSS) son habitualmente largos y extremadamente costosos debido a la falta de adopci贸n de interfaces est谩ndar por parte de los diferentes proveedores de red. Adem谩s, el impacto creciente en las redes de transporte de los nuevos flujos de tr谩fico introducidos por el despliegue masivo de Data Centers (DC), introduce nuevos desaf铆os que las arquitecturas de gesti贸n y control de las redes tradicionales no est谩n preparadas para afrontar. La quinta generaci贸n de tecnolog铆a m贸vil (5G) introduce nuevos requisitos de red, como la necesidad de conectar a la red billones de dispositivos nuevos (Internet de las cosas - IoT), aplicaciones de ultra baja latencia (p. ej., cirug铆a a distancia) y las comunicaciones vehiculares. Todos estos servicios, junto con un acceso mejorado a la red de banda ancha, deber谩n ser proporcionados a trav茅s de la misma infraestructura de red. Esta tesis doctoral propone una visi贸n hol铆stica de los recursos de red y cloud, basada en los principios introducidos por Software Defined Networking (SDN), como la soluci贸n para el dise帽o de una arquitectura de gesti贸n extremo a extremo (E2E) para escenarios de red multi-capa y multi-dominio, capaz de ofrecer servicios de E2E, desde las redes intra-DC hasta las redes de acceso, y ofrecer ademas virtualizaci贸n de los recursos de la red, permitiendo nuevas formas de segmentaci贸n en las redes de transporte y la infrastructura de cloud, para los pr贸ximos despliegues de 5G. La primera contribuci贸n de esta tesis consiste en la validaci贸n de arquitecturas de orquestraci贸n de red, basadas en SDN, para la gesti贸n y control de redes de transporte troncales multi-dominio y multi-capa. Estos problemas (gestion de redes multi-capa y multi-dominio), han sido evaluados de manera incremental, mediante el dise帽o y la evaluaci贸n experimental, en entornos de pruebas reales, de diferentes arquitecturas de control y gesti贸n. Uno de los principales hallazgos de este trabajo ha sido la necesidad de un modelo de informaci贸n com煤n para las interfaces de gesti贸n entre entidades de control SDN. En esta l铆nea, el Protocolo de Control Orchestration (COP) ha sido propuesto como interfaz de gesti贸n de red est谩ndar para redes SDN de transporte multi-capa. Adem谩s, en esta tesis presentamos una arquitectura capaz de coordinar la gesti贸n de los recursos IT y red. La provisi贸n y la migraci贸n de m谩quinas virtuales junto con la reconfiguraci贸n din谩mica de la red, han sido demostradas con 茅xito en una escala de tiempo factible. Adem谩s, la arquitectura incorpora una plataforma para la ejecuci贸n de algoritmos de optimizaci贸n de recursos capaces de resolver diferentes problemas de asignaci贸n, como el despliegue 贸ptimo de Grafos de M谩quinas Virtuales (VMG) en diferentes DCs que minimizan la asignaci贸n de recursos de red. Esta tesis propone una soluci贸n para este problema, que ha sido evaluada en terminos de probabilidad de bloqueo para diferentes cargas de red. La tercera contribuci贸n es el resultado de las dos anteriores. La arquitectura integrada de red y cloud presentada permite la creaci贸n bajo demanda de "network slices", que consisten en sub-conjuntos de recursos de red y cloud dedicados para diferentes clientes sobre una infraestructura com煤n. El dise帽o de una de las primeras arquitecturas de "network slicing" y el despliegue de un "slice" de red 5G totalmente operativo en un Testbed real, es una de las principales contribuciones de esta tesis.La gesti贸 i el control de les xarxes dels operadors de telecomunicacions (Telcos), encara avui, est脿 segmentat per tecnologia, per prove茂dors d鈥檈quipament i per capes de xarxa. En alguns segments (Per exemple en IP) l鈥檕peraci贸 de la xarxa 茅s tremendament costosa, ja que en molts casos encara es requereix de configuraci贸 individual, i fins i tot manual, dels equips per part de personal altament especialitzat. En xarxes amb m煤ltiples prove茂dors, els processos d鈥檌ntegraci贸 entre els Sistemes de gesti贸 de xarxa (NMS) i la resta de sistemes (per exemple, Sistemes de suport d鈥檕peracions - OSS i Sistemes de suport de negocis - BSS) s贸n habitualment interminables i extremadament costosos a causa de la falta d鈥檃dopci贸 d鈥檌nterf铆cies est脿ndard per part dels diferents prove茂dors de xarxa. A m茅s, l鈥檌mpacte creixent en les xarxes de transport dels nous fluxos de tr脿nsit introdu茂ts pel desplegament massius de Data Centers (DC), introdueix nous desafiaments que les arquitectures de gesti贸 i control de les xarxes tradicionals que no estan llestes per afrontar. Per acabar de descriure el context, la cinquena generaci贸 de tecnologia m貌bil (5G) tamb茅 presenta nous requisits de xarxa altament exigents, com la necessitat de connectar a la xarxa milers de milions de dispositius nous, dins el context de l鈥橧nternet de les coses (IOT), o les noves aplicacions d鈥檜ltra baixa lat猫ncia (com ara la cirurgia a dist脿ncia) i les comunicacions vehiculars. Se suposa que tots aquests nous serveis, juntament amb l鈥檃cc茅s millorat a la xarxa de banda ampla, es lliuraran a trav茅s de la mateixa infraestructura de xarxa. Aquesta tesi doctoral proposa una visi贸 hol铆stica dels recursos de xarxa i cloud, basada en els principis introdu茂ts per Software Defined Networking (SDN), com la soluci贸 per al disseny de una arquitectura de gesti贸 extrem a extrem per a escenaris de xarxa multi-capa, multi-domini i consistents en m煤ltiples tecnologies de transport. Aquesta arquitectura de gesti贸 i control de xarxes transport i recursos IT, ha de ser capa莽 d鈥檕ferir serveis d鈥檈xtrem a extrem, des de les xarxes intra-DC fins a les xarxes d鈥檃cc茅s dels clients i oferir a m茅s virtualitzaci贸 dels recursos de la xarxa, obrint la porta a noves formes de segmentaci贸 a les xarxes de transport i la infrastructura de cloud, pels propers desplegaments de 5G. La primera contribuci贸 d鈥檃questa tesi doctoral consisteix en la validaci贸 de diferents arquitectures d鈥檕rquestraci贸 de xarxa basades en SDN capaces de millorar les solucions existents per a la gesti贸 i control de xarxes de transport troncals multi-domini i multicapa. Aquests problemes (gesti贸 de xarxes multicapa i multi-domini), han estat avaluats de manera incremental, mitjan莽ant el disseny i l鈥檃valuaci贸 experimental, en entorns de proves reals, de diferents arquitectures de control i gesti贸. Un dels principals troballes d鈥檃quest treball ha estat la necessitat de dissenyar un model d鈥檌nformaci贸 com煤 per a les interf铆cies de gesti贸 de xarxes, capa莽 de descriure els recursos i serveis de la xarxes transport multicapa. En aquesta l铆nia, el Protocol de Control Orchestration (COP, en les seves sigles en angl猫s) ha estat proposat en aquesta Tesi, com una primera contribuci贸 cap a una interf铆cie de gesti贸 de xarxa est脿ndard basada en els principis b脿sics de SDN. A m茅s, en aquesta tesi presentem una arquitectura innovadora capa莽 de coordinar la gesti贸 de els recursos IT juntament amb les xarxes inter i intra-DC. L鈥檃provisionament i la migraci贸 de m脿quines virtuals juntament amb la reconfiguraci贸 din脿mica de la xarxa, ha estat demostrat amb 猫xit en una escala de temps factible. A m茅s, l鈥檃rquitectura incorpora una plataforma per a l鈥檈xecuci贸 d鈥檃lgorismes d鈥檕ptimitzaci贸 de recursos, capa莽os de resoldre diferents problemes d鈥檃ssignaci贸, com el desplegament 貌ptim de Grafs de M脿quines Virtuals (VMG) en diferents ubicacions de DC que minimitzen la assignaci贸 de recursos de xarxa entre DC. Tamb茅 es presenta una soluci贸 b脿sica per a aquest problema, aix铆 com els resultats de probabilitat de bloqueig per a diferents c脿rregues de xarxa. La tercera contribuci贸 principal 茅s el resultat dels dos anteriors. Amb una infraestructura de xarxa i cloud convergent, controlada i operada de manera conjunta, la visi贸 hol铆stica de la xarxa permet l鈥檃provisionament sota demanda de "network slices" que consisteixen en subconjunts de recursos d鈥檟arxa i cloud, dedicats per a diferents clients, sobre una infraestructura de Data Centers distribu茂da i interconnectada per una xarxa de transport 貌ptica. Els 煤ltims cap铆tols d鈥檃questa tesi tracten sobre la gesti贸 i organitzaci贸 de "network slices" per a xarxes 5G en funci贸 dels components de control i administraci贸 dissenyats i desenvolupats en els cap铆tols anteriors. El disseny d鈥檜na de les primeres arquitectures de "network slicing" i el desplegament d鈥檜n "slice" de xarxa 5G totalment operatiu en un Testbed real, 茅s una de les principals contribucions d鈥檃questa tesi.Postprint (published version

    Modular architecture providing convergent and ubiquitous intelligent connectivity for networks beyond 2030

    Get PDF
    The transition of the networks to support forthcoming beyond 5G (B5G) and 6G services introduces a number of important architectural challenges that force an evolution of existing operational frameworks. Current networks have introduced technical paradigms such as network virtualization, programmability and slicing, being a trend known as network softwarization. Forthcoming B5G and 6G services imposing stringent requirements will motivate a new radical change, augmenting those paradigms with the idea of smartness, pursuing an overall optimization on the usage of network and compute resources in a zero-trust environment. This paper presents a modular architecture under the concept of Convergent and UBiquitous Intelligent Connectivity (CUBIC), conceived to facilitate the aforementioned transition. CUBIC intends to investigate and innovate on the usage, combination and development of novel technologies to accompany the migration of existing networks towards Convergent and Ubiquitous Intelligent Connectivity (CUBIC) solutions, leveraging Artificial Intelligence (AI) mechanisms and Machine Learning (ML) tools in a totally secure environment

    Software Defined Applications in Cellular and Optical Networks

    Get PDF
    abstract: Small wireless cells have the potential to overcome bottlenecks in wireless access through the sharing of spectrum resources. A novel access backhaul network architecture based on a Smart Gateway (Sm-GW) between the small cell base stations, e.g., LTE eNBs, and the conventional backhaul gateways, e.g., LTE Servicing/Packet Gateways (S/P-GWs) has been introduced to address the bottleneck. The Sm-GW flexibly schedules uplink transmissions for the eNBs. Based on software defined networking (SDN) a management mechanism that allows multiple operator to flexibly inter-operate via multiple Sm-GWs with a multitude of small cells has been proposed. This dissertation also comprehensively survey the studies that examine the SDN paradigm in optical networks. Along with the PHY functional split improvements, the performance of Distributed Converged Cable Access Platform (DCCAP) in the cable architectures especially for the Remote-PHY and Remote-MACPHY nodes has been evaluated. In the PHY functional split, in addition to the re-use of infrastructure with a common FFT module for multiple technologies, a novel cross functional split interaction to cache the repetitive QAM symbols across time at the remote node to reduce the transmission rate requirement of the fronthaul link has been proposed.Dissertation/ThesisDoctoral Dissertation Electrical Engineering 201
    corecore