Optical or lambda exchanges have emerged to interconnect networks, providing dynamic switching capabilities on OSI layer 1 and layer 2. So far, the only inter-domain dynamics have occurred on layer 3, the IP layer. This new functionality in the data plane has consequences on the control plane. We explain this by comparing optical exchanges with current Internet exchanges.Descriptions of optical exchanges have appeared in the literature, but discussions about these exchanges have been hampered by a lack of common terminology. This paper defines a common terminology for exchanges. Discussion in the community revealed four different meaning for the term "open exchange". We list them in this paper.We classify the different kind of exchanges based on the interactions between the domains at the control plane. We use these control models to distinguish between different types of interconnection points.
The "VM Turntable" demonstrator at SC05 and SC06 pioneers the integration of Virtual Machines (VMs) with deterministic "lightpath" network services (www.nortel.com/drac) across metro and wide area networks. The integration provides for a new stage of virtualization, one for which computation is no longer localized within a data center but rather can be migrated across geographical distances, with negligible downtime, transparently to running applications and external clients.A noteworthy data point indicates that a live VM can be migrated between Amsterdam, NL and San Diego, USA with just 1 to 2 seconds of application downtime. When compared to intra-LAN local migrations, downtime is only about 5-10 times greater despite 1,000 times higher round-trip-times. These outcomes realize significant value propositions in the areas of data affinity, load balancing, power-aware computing, business continuance, and disaster recovery.
This short communication outlines an experiment where tokens, associated with application oriented IP streams, authorize access to an optical lightpath during iGrid 2005. The experiment showed the practical viability of this mechanism to perform access control and resource management within optical networks. The experiment was conducted in collaboration with the Virtual Machine Turntable (NL-103) experiment, which used the mechanism to obtain access to continental and transatlantic optical network segments that connected Virtual Machine sites.
The availability of information about properties and status of resources is essential for Grid resource brokers. However, while abstractions of computing and storage resources already exist, the notion of Grid network resource is far from being understood today. As a result, the integration of advanced network services is still difficult when a Grid system spans large-scale heterogeneous network infrastructures. In this paper, we propose a single definition of a Grid network resource abstraction for multiple types of network connectivity. This abstraction was successfully implemented and tested in a network resource management prototype supporting a variety of network technologies.
The paper provides an overview of available Web services security vulnerability models and proposes a classification of the potential grid and Web services attacks and vulnerabilities. This is further used to introduce a security model for interacting grid and Web services that illustrates how basic security services should interact to provide an attack-resilient multilayer protection in a typical service-oriented architecture. The analysis and the model can be used as a basis for developing countermeasures against known vulnerabilities and security services design recommendations. The paper refers to the ongoing work on middleware and operational security in the framework of the European grid infrastructure deployment project EGEE and related coordination groups.
New types of exchange points, like Optical Exchanges and GMPLS exchanges have been described in the last few years. Optical and lambda exchanges are now deployed. However, these interconnection points are not defined in systematic way in the literature. We classify interconnection points, mainly by discriminating on the properties of the control planes. Three control models are defined: the autonomous, federated and distributed control model. In addition we define in which cases the adjectives “open” and “automated” can be applied to the control models. This article aims to reach community consensus about a common terminology.
Many Grid applications require high bandwidth end-to-end connections between Grid resources in different domains. Fiber optic networks, owned by different providers, have to cooperate in a coordinated manner in order to provide an end-to-end connection. Currently, multi-domain optical network solutions require paper-based long-term contracts between administrative domains. This paper describes a solution for dynamically creating optical connections between different autonomous domains. This was implemented in the form of a Grid Service following the Open Grid Service Architecture. In our prototype, each switch belongs to a different network domain. Our Grid Service uses a toolkit based on the Generic Authorization, Authentication, and Accounting framework. This toolkit authorizes the use of optical infrastructure elements based on specific policies that are active within each domain. To complete our multi-domain authorization architecture, a Broker Service was also implemented. Our Broker Service interacts with the Grid Service instances to provide Grid application with a simplified way to set up end-to-end connections on demand.
The paper presents proposed Security Architecture for Open Collaborative Environment (OCE) being developed in the framework of the Collaboratory.nl (CNL) project with the intent to build a flexible, customer-driven security infrastructure for open collaborative applications. The architecture is based on extended use of emerging Web Services and Grid security technologies combined with concepts from the generic Authentication Authorization and Accounting (AAA) and Role-based Access Control (RBAC) frameworks. The paper describes another proposed solution the Job-centric security model that uses a Job description as a semantic document created on the basis of the signed order (or business agreement) to provide a job-specific context for invocation of the basic OCE security services. Typical OCE use case of policy based access control is discussed in details.
In e-Science environments, the service for scientific workflows facilitates the management of experiment data and activities, the prototyping of computing systems and the orchestration of the runtime system behaviour. Reusing the successful and stable design of Scientific Workflow Management Systems (SWMS) can not only improve the efficiency for developing advanced high-level application specific functionality, but also reduce cost and risks for utilising an e-Science infrastructure in a new problem domain. However, most of the existing workflow management systems are driven by the domain specific applications; the applicability to different domains is limited. Investigating the internal links between the characteristics of domain specific applications and the requirements on the development of workflow management systems is essential to realise a common e-Science framework for scientists from different domains to share their knowledge and to conduct domain specific scientific research. In this paper, we give an abstract model of SWMSs and survey the state of the art in existing systems, and based on that we discuss the challenges in developing an effective workflow management system. The research is conducted in an ongoing project: Virtual Laboratory for e-
The paper presents experiences with building a flexible, customer-driven security infrastructure for open collaborative applications. The experiences were gained in the framework of the Collaboratory.nl (CNL) project. The work is based on extended use of emerging Web Services and Grid security technologies combined with concepts from the Generic Authentication Authorization and Accounting (AAA) authorisation framework. Basic CNL use cases and functional security requirements are analysed in order to motivate the proposed Job-centric security model. This model describes access control and user- and resource management. The technical details and solutions are described based upon the current CNL implementation. The proposed Job-centric approach uses a Job description as a semantic document created on the basis of the signed order (or business agreement). It contains all of the information required to run the analysis, create and manage the virtual Job-based associations of users and resources. . In addition, this paper shows the usage of XACML as policy/role based access control model to build fine-grained access control and cross-organisation identity management using the Virtual Organization (VO) concept.
Within the scope of the Analytical Network Project at the Master education System- and Network Engineering 1 of the University of Amsterdam, we conducted a research to the performance of the AAA server technology that represents current implementation of the Generic Authorization, Authentication and Accounting (AAA) architecture being developed by Advanced Internet Research Group (AIRG) at the University of Amsterdam 2 . The report represents general analysis of the major components of the AAA server that is built on the J2EE platform using Tomcat Servlet container. Test model includes variable and controlled time delays on server and client sides that allow indirect components' performance testing. Finally, the report represents voluminous test results and provides summary and recommendations based on the analysis of the test data.
Yuri Demchenko合作论文数Fraunhofer Institut SCAI, 53754 Sankt Augustin, GermanyPoznan Supercomputing and Networking Center, Noskowskiego 12/14 , 61-704 Poznan, Poland6
Freek Dijkstra合作论文数SARA3
Franco Travostino合作论文数Open Software Foundation Research Institute|Cambridge Center2