DocumentCode :
705769
Title :
MIDAS: Middlebox discovery and selection for on-path flow processing
Author :
Abujoda, Ahmed ; Papadimitriou, Panagiotis
Author_Institution :
Inst. of Commun. Technol., Leibniz Univ. Hannover, Hannover, Germany
fYear :
2015
fDate :
6-10 Jan. 2015
Firstpage :
1
Lastpage :
8
Abstract :
The deployment of micro-datacenters for network function virtualization (NFV) by Internet Service Providers creates opportunities for flow processing along the traffic path. On-path processing requires the discovery of the middleboxes that will be traversed by each flow and the assignment of network functions (NFs) to middleboxes, while preserving the order of the NFs as specified in the service chain. NF location dependencies may require flow processing establishment across multiple NF Providers (NFPs). This entails additional challenges for middlebox discovery and selection, stemming from the NFPs´ restrictions in information disclosure and interoperability. To address these issues, we present MIDAS, an architecture for the coordination of middlebox discovery and selection across multiple NFPs. MIDAS relies on a centralized middlebox controller in each NFP to provide interoperability among NFPs for flow processing setup. MIDAS establishes on-path processing via middlebox signaling, controller chaining, and Multi-Party Computation (MPC) based middlebox selection. We particularly employ MPC to preserve the confidentiality of middlebox utilization across the NFPs. We study the feasibility of MIDAS using a prototype implementation and further present simulation results to assess the efficiency of our middlebox selection approach.
Keywords :
Internet; computer centres; open systems; telecommunication traffic; Internet service providers; MIDAS; MPC based middlebox selection; NF location dependencies; NF providers; NFP; NFV; centralized middlebox controller; controller chaining; information disclosure; information interoperability; microdata center deployment; middlebox discovery and selection; middlebox signaling; multiparty computation based middlebox selection; network function virtualization; on-path flow processing; service chain; Firewalls (computing); Hardware; Irrigation; Lead; Logic gates; Middleboxes;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Communication Systems and Networks (COMSNETS), 2015 7th International Conference on
Conference_Location :
Bangalore
Type :
conf
DOI :
10.1109/COMSNETS.2015.7098686
Filename :
7098686
Link To Document :
بازگشت