Norihito Fujita, Y. Ishikawa, T. Koide, Akira Tsukamoto
{"title":"Scalable overlay network deployment for dynamic collaborative groups","authors":"Norihito Fujita, Y. Ishikawa, T. Koide, Akira Tsukamoto","doi":"10.1109/SAINT.2005.56","DOIUrl":null,"url":null,"abstract":"Scalable deployment and management of overlay networks for collaborative groups with dynamic membership are discussed. In deploying overlay networks for such dynamic groups, unlike in pre-defined static VPN deployment, a mechanism to keep security policies in member nodes updated for membership changes and a mechanism to adaptively reconfigure a topology must be supported. However, previous approaches have scalability problems in supporting these mechanisms. We propose a scalable overlay network deployment scheme to minimize the impact of membership changes. In the scheme, the IPsec policy required for delivering packets to a destination node is resolved on an on-demand basis to eliminate the advertisement-based updates of membership changes. Our approach also provides two modes of overlay topology operation to address dynamic changes in the number of nodes. While the mesh mode eliminates a tunnel initiation/teardown behavior for membership changes, the graph mode creates a graph-structured topology reconfigurable with a constant number of initiated/torn-down tunnels for node joins/leaves. We evaluate a management server load on dynamic membership changes and show the efficient performance of our scheme for increasing the number of nodes. We also show that our topology reconfiguration algorithm provides a smaller number of initiated/torn-down tunnels for changes in the number of nodes than previous approaches.","PeriodicalId":169669,"journal":{"name":"The 2005 Symposium on Applications and the Internet","volume":"110 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2005-01-31","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"5","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"The 2005 Symposium on Applications and the Internet","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SAINT.2005.56","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 5
Abstract
Scalable deployment and management of overlay networks for collaborative groups with dynamic membership are discussed. In deploying overlay networks for such dynamic groups, unlike in pre-defined static VPN deployment, a mechanism to keep security policies in member nodes updated for membership changes and a mechanism to adaptively reconfigure a topology must be supported. However, previous approaches have scalability problems in supporting these mechanisms. We propose a scalable overlay network deployment scheme to minimize the impact of membership changes. In the scheme, the IPsec policy required for delivering packets to a destination node is resolved on an on-demand basis to eliminate the advertisement-based updates of membership changes. Our approach also provides two modes of overlay topology operation to address dynamic changes in the number of nodes. While the mesh mode eliminates a tunnel initiation/teardown behavior for membership changes, the graph mode creates a graph-structured topology reconfigurable with a constant number of initiated/torn-down tunnels for node joins/leaves. We evaluate a management server load on dynamic membership changes and show the efficient performance of our scheme for increasing the number of nodes. We also show that our topology reconfiguration algorithm provides a smaller number of initiated/torn-down tunnels for changes in the number of nodes than previous approaches.