DocumentCode :
3063766
Title :
VSITE: A scalable and secure architecture for seamless L2 enterprise extension in the cloud
Author :
Li, Li Erran ; Woo, Thomas
Author_Institution :
Bell Labs., Alcatel-Lucent, Murray Hill, NJ, USA
fYear :
2010
fDate :
5-5 Oct. 2010
Firstpage :
31
Lastpage :
36
Abstract :
This paper presents an end-to-end architecture, called VSITE, for seamless integration of cloud resources into an enterprise\´s intranet at layer 2. VSITE allows a cloud provider to carve out its resources to serve multiple enterprises simultaneously while maintaining isolation and security. Resources (allocated to an enterprise) in the cloud provider appears "internal" to the enterprise. VSITE achieves this abstraction through the use of VPN technologies, the assignment of different VLANs to different enterprises, and the encoding of enterprise IDs in MAC addresses. Unlike traditional layer 2 VPN technology such as VPLS, VSITE suppresses layer 2 MAC learning related broadcast traffic from reaching the remote sites. VSITE makes use of location IP (represents location area) for scalable migration support. The MAC or IP address of a VM is not visible in data center core. VSITE hypervisor enforces security mechanisms to prevent enterprises from attacking one another. Thus, VSITE is scalable, secure and efficient, and it facilitates common data center operation such as VM migration. Because VSITE extends enterprise network at layer 2, this offers transparency to most existing applications and presents an easy migration path for an enterprise to leverage cloud computing resources.
Keywords :
Internet; business communication; computer centres; computer network security; intranets; virtual enterprises; virtual private networks; IP address; MAC address; VPN technology; VSITE; cloud resource; data center core; end to end architecture; enterprise intranet; scalable and secure architecture; scalable migration support; Cloud computing; Clouds; IP networks; Scalability; Security; Virtual machine monitors; Virtual private networks; cloud computing; multi-tenant data center; seamless L2 network extension;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Secure Network Protocols (NPSec), 2010 6th IEEE Workshop on
Conference_Location :
Kyoto
Print_ISBN :
978-1-4244-8916-9
Type :
conf
DOI :
10.1109/NPSEC.2010.5634451
Filename :
5634451
Link To Document :
بازگشت