Skip to main navigation Skip to search Skip to main content

Towards flexible, scalable and autonomic virtual tenant slices

  • Mohamed Fekih Ahmed

Student thesis: Master's thesisMaster in Engineering: Engineering

Abstract

Multi-tenant flexible, scalable and autonomic virtual networks isolation has long been a goal of the network research and industrial community. With Software-Defined Networking (SDN) and Overlay Virtualization technologies (OVT), multiple and independent virtual networks each with potentially different and heterogeneous addressing, forwarding and tunneling mechanisms can coexist above the same underlay infrastructure. For today’s cloud platforms, providing tenants requirements for scalability, elasticity, and transparency is far from straightforward. SDN addresses isolation and manageability through network slices, but suffers from scalability limitations. SDN programmers typically enforce strict, inflexible, and complex traffic isolation resorting to low-level encapsulations mechanisms which help and facilitate network programmer reasoning about their complex slices behavior. Overlay protocols have successfully overcome scalability issues of isolation mechanisms, but remain limited to single slice. However, the opportunity cost of the successful implementation of transparent and flexible slices is to find an alternative isolation design to satisfy multiple and different tenant’ requirements such as slice scalability and enabling the deployment of arbitrary virtual network services and boundaries. In this thesis, we propose Open Network Management and Security (OpenNMS), a novel software-defined architecture overcoming SDN and OVT limitations. OpenNMS lifts several network virtualization roadblocks by combining these two separate approaches into an unified design. It enables to reap the benefits of network slice while preserving scalability. Our design leverages the benefits of SDN to provide Layer 2 isolation coupled with network overlay protocols. It offers multi-tenants isolation with simple and flexible Virtual Tenant Slices (VTSs) abstractions. This yields a network virtualization architecture that is both flexible, scalable and secure on one side, and self-manageable on the other. At the core of these challenges, we extend our research to outline the SDN control plane scalability bottleneck and demonstrate the benefits of OpenNMS to limit the load on the controller for supporting larger number of tenants. OpenNMS exploits the high flexibility of software-defined switches and controllers to break the scalability bottleneck and scale the network to several thousands of isolated tenants networks on top of shared network infrastructures. It requires only a small amount of line as extended application to OpenFlow controller without any modifications on SDN dataplane which makes it suitable for legacy systems. Furthermore, this work takes a step towards reducing the complex network management operations. We designed OpenNMS as an autonomic communication based architecture, to provide self-configured and self-awareness VTSs network for cloud tenants. The result is recursive, layered isolation architecture, with control and management planes both at tenant and overall network levels. Moreover, we describe novel capabilities added for the isolation model: Split, Merge and Migrate (SMM) that can be well suited for cloud requirements. We implemented our approach on a real cloud testbed, and demonstrated our isolation model’s flexibility and scalability, while achieving order of magnitude improvements over previous isolation approaches investigated in this work. The experiment results showed that the proposed design offers negligible overhead and guarantees the network performance while achieving the desired isolation goals.
Date28 Jan 2015
Original languageAmerican English
Awarding Institution
  • École de technologie supérieure
SupervisorChamseddine Talhi (Supervisor) & Mohamed Cheriet (Co-supervisor)

Cite this

'