Multipath transmission can effectively integrate path resources and provide high-quality QoS performance for services. However, traditional scheduling algorithms are unable to flexibly identify suitable transmission paths based on service demands due to the absence of support for fine-grained sensing technology. To solve this problem, this paper proposes a vector offset based multipath scheduling algorithm (VOMS) to optimize the adaptability of service demands and path resources. First, the proposed algorithm collects path resources information in real time based on In-band network telemetry (INT) and constructs a multipath resources and service demands joint matrix. Then, VOMS uses the vector offset method to calculate Euclidean distance to rank path scores based on service demands. Finally, scheduling strategies are established according to service demands, prioritizing the selection of single path transmission to meet service requirements. If the bandwidth of a single path is insufficient, VOMS allocates traffic based on sorted paths from highest to lowest until the total filled bandwidth meets the service demand. Experimental results show that compared with the traditional round robin scheduling algorithm (RR) and the bandwidth-based weighted round robin scheduling algorithm (WRR), VOMS can ensure high QoS performance for the service and significantly reduce the packet out-of-order rate.
Integrated Sensing and Communication (ISAC) introduces greater challenges to network transmission in terms of delay, bandwidth, and reliability. Achieving stable and efficient congestion control is a critical issue in emerging ISAC scenarios. However, many traditional congestion control algorithms primarily focus on transmission efficiency but perform poorly in ensuring fairness between different data flows. To address this limitation, this paper proposes a queuing-aware fair congestion control (Q-FCC) solution for ISAC. In particular, Q-FCC incorporates a queue status monitoring module which can provide real-time feedback on the queuing delays at targeted network switches. Additionally, this paper analyzes the traditional BBR algorithm and identifies an inherent flaw: longer RTT flows have a higher bandwidth gain coefficient compared to shorter RTT flows, leading to unfairness. Based on this insight, Q-FCC introduces bandwidth gain factor. Q-FCC uses the queue status monitoring module to categorize data flows into three types and interacts with bursty flow endpoints via ACK packets to assist them in calculating the bandwidth gain factor, which enables the control of the transmission rate. Finally, the algorithm was implemented in the Linux kernel. The results of the semi-physical simulation show that Q-FCC outperforms the traditional BBR and CUBIC algorithms in terms of bandwidth fairness and transmission stability, respectively.
With the development of Software Defined Networking (SDN), the most investigated firewall type is software firewall, running as application on control plane. The main process in firewalls is matching network traffic with stored security policies, that is, packet classification. Although extensive research has been conducted in this area, existing packet classification algorithms still face problems of low classification performance and large storage space. To minimize the impact of the packet classification on the entire network, we propose an efficient firewall using Learned Cuckoo filter (LCF) based packet classification algorithm. This algorithm adopts a hierarchical search strategy. The single-field matching results is obtain first. Then the machine learning model is used as a pre-filter in front of the cuckoo filter, which effectively eliminates unnecessary rule search in the next stage and achieves a memory reduction, as well as an improvement on performance. We implemented a proposed firewall prototype. Extensive simulations verify the superiority of the introduced design in terms of false positive rate, memory consumption and memory access.
Deploying popular contents during the off-peak time via node cooperative caching has been proved to be an important measure to alleviate the link burden of wired multi-hop network. However, due to the unknown and time-varying content popularity in practice, it is imminent to optimize the content placement to effectively utilize the limited caching storage. In this paper, to address these issues, we investigate a multi-agent reinforcement learning (DRL) mechanism to intelligently deploy contents in dynamic environments. The optimization of content caching is modeled as a cooperative Markov decision process (MDP) to minimize the content transmission cost in the network. Then, a multi-agent deep deterministic policy gradient-based collaborative caching algorithm (MADDPG-CC) is proposed to solve this optimization problem with the goal of maximizing long-term caching reward. Extensive simulations have demonstrated the superior performance of the proposed algorithm in reducing the content transmission cost compared to existing caching algorithms, as well as its compatibility with variable and dynamic network environments.
未来的网络通信需求动态多样,网络层功能也应适时而变,因此对网络可演进性的研究具有重要意义.多标识网络作为一种兼容性极强的网络架构,网络层功能十分丰富,但仍缺少网络演进性设计.本文为多标识网络设计了一种通过标识扩展来支持网络体系不断演进的方案,包括对标识空间进行形式化定义,设计标识回退候选标识的优先级排序算法以及设计支持标识扩展的路由转发协议;并且在ndnSIM网络仿真环境和多标识网络测试床中实现了上述方案,评估了标识扩展方案的可行性和性能.实验结果表明相比于标识扩展机制给网络架构带来的益处,其性能损失在可接受的范围内.
In distributed storage systems, the replication mechanisms are usually used to ensure system reliability and data availability. Random replication is widely used in cloud storage systems to prevent data loss. Copyset Replication (CR) as a replication strategy, makes a nearly optimal trade-off between the number of scattered nodes and the probability of data loss. Compared with random replication, CR greatly reduces the probability of data loss caused by node failure. However, CR's random selection strategy makes it difficult to select the optimal copyset based on data characteristics such as calculation and storage. In response to this problem of CR, the Optimal Copyset Replication (OCR) proposed in this paper can select the optimal copyset according to the specified data characteristics and its corresponding node conditions. Finally, combined with Cyberspace Mimicry Defense (CMD), we implemented OCR in a distributed object storage system and conducted related experiments. When the calculation type data reaches 300,000, the experimental results prove that compared with CR randomly selecting copyset, OCR reduces the data processing time by nearly 10% through selecting the optimal copyset. By setting relevant parameters, OCR can also ensure that the data distribution of each node is relatively uniform, and avoid data skew.
With the era of the internet of things (IoT), the protocol stack conversion scheme based on the application-layer’s gateway has problems such as poor performance and end to end security that can’t be guaranteed.A lightweight and trusted IoT IP communication protocol was proposed, which was the main research direction of Protocol and Interface Group in Network 5.0 Industry and Technology Innovation Alliance, the deployment costs of protocol conversion gateways was decreased, the computing and storage overhead of IoT devices was reduced, and end to end communication security was ensured.
IP protocol is the core of TCP/IP network layer. However, since IP address and its Domain Name are allocated and managed by a single agency, there are risks of centralization. The semantic overload of IP address also reduces its scalability and mobility, which further hinders the security. This paper proposes a co-governing Multi-Identifier Network (MIN) architecture that constructs a network layer with parallel coexistence of multiple identifiers, including identity, content, geographic information, and IP address. On the management plane, we develop an efficient management system using consortium blockchain with voting consensus, so the network can simultaneously manage and support by hundreds or thousands of nodes with high throughput. On the data plane, we propose an algorithm merging hash table and prefix tree (HTP) for FIB, which avoids the false-negative error and can inter-translate different identifiers with tens of billions of entries. Further, we propose a scheme to transport IP packets using CCN as a tunnel for supporting progressive deployment. We deployed the prototype of MIN to the largest operators' network in Mainland China, Hongkong and Macao, and demonstrated that the network can register identifier under co-governing consensus algorithm, support VoD service very well.
The Internet has become the essential infrastructure of modern society, while the centralized domain name system (DNS) is unable to provide high-quality services and secure government.Facing this challenge, we propose a reconfigurable multi-identifier network architecture and develop the prototype of the multi-identifier system.We optimize the network security using consortium blockchain, improve the forwarding speed using HPT for FIB, and enhance the scalability through tunnel algorithm.Experiments and testing of this prototype on the network of the two largest telecommunication service providers in China demonstrate that the system is robust enough to support real-world traffic.It can also be applied to sovereign network and other private networks with multiple identifiers, which may become a Chinese solution of the network security to the world.
The Internet has become the most important infrastructure of modern society, while the existing IP network is unable to provide high-quality service. The unilateralism IP network is unable to satisfy the Co-managing and Co-governing demands to Cyberspace for most Nations in the world as well. Facing this challenge, we propose a novel Decentralized Multilateral Co-Governing Post-IP Internet architecture. To verify its effectiveness, we develop the prototype on the operator's networks including China Mainland, Hong Kong, and Macao. The experiments and testing results show that this architecture is feasible for co-existing of Content-Centric Networking and IP network, and it might become a Chinese Solution to the world.
软件定义广域网(SD-WAN)是将软件定义网络(SDN)技术应用于广域网(WAN)连接的服务。重点阐述了SD-WAN应用的关键技术,包括SD-WAN服务中4种典型技术架构、SD-WAN的整体功能模块以及边缘设备中所采用的关键技术。与传统的WAN架构相比,SD-WAN技术以一种多接入、安全、策略驱动业务、弹性路由、多虚拟隧道、敏捷上云的方法重新定义了开放式的WAN架构。
向基于IPv6的下一代互联网演进是互联网发展的必经阶段,而且IPv4网络和IPv6网络将长期共存.本文以IETF已经开发出的过渡技术工具集为基础,结合运营商网络架构和业务迁移策略,阐述网络向IPv6平滑演进升级的不同过渡技术方案.
In this paper, in order to make a systematic and comprehensive evaluation for the soft defined network(SDN)/network function virtualization(NFV), the three-level test methodology, including interface-level test method, device-level test method and platform-level test method is proposed. This test methodology abstracts test aspects for different level and firstly formulates consistent metrics, and will provide an important reference for the test research evaluation in the future.
对全球IPv6发展的整体情况进行了分析和研究,重点对比美国、中国IPv6发展现状,分析了导致中美IPv6发展存在较大差异的主要原因,并对我国后续发展提出了建议.
云计算技术实现了数据中心内部IT资源的虚拟化管理,用户可以动态、按需、实时地申请IT资源.那么,底层承载网络如何应对这种新变化,为用户实时、按需地创建相互隔离的网络连接并满足特定QoS需求的承载服务,已成为云化数据中心解决方案关注的焦点.本文分析了数据中心网络云化后的新需求,讨论了云化数据中心网络解决方案及其关键技术,最后就如何选择云化数据中心网络解决方案给出了建议.
In this paper, the current hot issues of soft defined network(SDN)/network function virtualization (NFV) industrial development are analyzed, including standardization and interoperability of open interface, performance of general-purpose hardware and SDN control er, cooperation with existing operation system, security and integration deployment. And the progress status of standardizations and open source projects in the SDN/NFV field are also concluded. It is believed that the deployment of SDN/NFV should be a gradual process, and the traditional network and SDN/NFV network wil coexist for a long time. The architecture, interface and protocol standards should be unified as soon as possible, so as to promote the integration of different functional components of different manufacturers. In this way, network as a service (NaaS) can be realized.
当前,SDN产业蓬勃发展,特别是支持OpenFlow协议的SDN交换设备得到了业界主流设备制造商的大力支持.然而,随着商用化应用的不断深入,SDN产业遇到了一些问题,如市场竞争紊乱、设备良莠不齐等.要推动SDN产业进一步向规范化和标准化的方向发展,就必须从测试工作入手,借鉴传统设备的测试经验,对SDN设备的测试方法和测试工具进行全面研究,找出符合SDN设备特点的测试技术.
目前,SDN技术已成为ICT领域的热点技术之一.本文从SDN技术标准进展、产业发展现状以及SDN对产业发展的影响等3个方面系统阐述了SDN发展的整体概况,分析了不同标准组织的标准化研究重点以及设备厂商不同的解决方案路径.
在网络向IPv6演进的过渡阶段,如何将业务流量从IPv4网络向IPv6网络迁移是需要考虑的首要问题。本文分析了终端应用向IPv6网络迁移的3种场景,探讨了基于主机的流量迁移方案以及网站的流量迁移方案。
This paper introduces three kinds of technologies about network evolution from IPv4 to IPv6,namely Dual-Stack,Tunnel and Translation,as well as current research hot spot including IPv6 Rapid Deployment on IPv4 infrastructures,CarrierGrade network address translation and IVI translation technology.Moreover it briefly analyzes typical application models of three kinds of transition technologies.