Current approaches to automate the design and configuration of transport services face several challenges. Firstly, there is a lack of open interfaces between the Operational Support Systems (OSS) and the network layer. The commercially available interfaces to Network Management Systems (NMSs) or directly to the devices are typically proprietary and with limited programmability. Secondly, for the case of IP/MPLS networks, the definition of how a service is built is particular to each operator. To solve this situation, this work presents an approach based on a hybrid SDN in which the definition of a VPN service is made with a modeling language and is not limited to a particular operator design nor a particular set of vendor devices. The IP/MPLS network topology and the VPN services are programmable via standard APIs with RESTCONF/YANG from an SDN Controller. This facilitates the operator on the one hand designing a new VPN service and its full automation. This work demonstrates, for the first time, that such automation is possible with proposed draft standards from IETF and validates its implementation, comparing the time consumed in the controller to process to different workflows from the same model.
One possible deployment strategy for BGP origin validation based on the Resource Public Key Infrastructure (RPKI) is the construction of islands of trust. This document describes the authors' experience deploying and maintaining a BGP origin validation island of trust in Ecuador.
This document specifies the process that Certification Authorities (CAs) and Relying Parties (RPs) participating in the Resource Public Key Infrastructure (RPKI) will need to follow to transition to a new (and probably cryptographically stronger) algorithm set.The process is expected to be completed over a timescale of several years.Consequently, no emergency transition is specified.The transition procedure defined in this document supports only a top-down migration (parent migrates before children).
SEcure Neighbor Discovery (SEND) Utilizes X.509v3 certificates for performing router authorization. This document specifies a certificate profile for SEND based on Resource Certificates along with extended key usage values required for SEND.
SEcure Neighbor Discovery (SEND) defines the Name Type field in the Trust Anchor option. This document request to IANA the creation and management of a registry for this field. This document also specifies a new Name Type field based on a certificate Subject Key Identifier (SKI).
This document specifies the process that Certification Authorities (CAs) and Relying Parties (RPs) participating in the Resource Public Key Infrastructure (RPKI) will need to follow to transition to a new (and probably cryptographically stronger) algorithm set. The process is expected to be completed over a timescale of several years. Consequently, no emergency transition is specified. The transition procedure defined in this document supports only a top-down migration (parent migrates before children). Information about the current status of this document, any errata, and how to provide feedback on it may be obtained at in effect on the date of publication of this document. Please review these documents carefully, as they describe your rights and restrictions with respect to this document. Code Components extracted from this document must include Simplified BSD License text as described in Section 4.e of the Trust Legal Provisions and are provided without warranty as described in the Simplified BSD License.
The characteristics of Latin American network infrastructures have global consequences, particularly in the area of interdomain traffic engineering. As an example, Latin America shows the largest de-aggregation factor of IP prefixes among all regional Internet registries, being proportionally the largest contributor to the growth and dynamics of the global BGP routing table. In this article we analyze the peculiarities of LA interdomain routing architecture, and provide up-to-date data about the combined effects of the multihoming and TE practices in the region. We observe that the Internet Research Task Force initiative on the separation of the address space into locators and identifiers can not only alleviate the growth and dynamics of the global routing table, but can also offer appealing TE opportunities for LA. We outline one of the solutions under discussion at the IRTF, the Locator/Identifier Separation Protocol, and examine its potential in terms of interdomain traffic management in the context of LA. The key advantage of LISP is its nondisruptive nature, but the existing proposals for its control plane have some problems that may hinder its possible deployment. In light of this, we introduce a promising control plane for LISP that can solve these issues, and at the same time has the potential to bridge the gap between intradomain and interdomain traffic management.
The Locator/Identifier Separation Protocol (LISP) is being considered in the Internet community as an evolutionary path towards Future Internet. Routing scalability and enhanced Traffic Engineering capabilities beyond BGP are major highlights of the proposal. An implementation from Cisco Systems is being tested in a global infrastructure named LISP+ALT, while an open source implementation, namely OpenLISP, is also being deployed. The main goal of our LISP implementation is to have a quick prototype development cycle, targeting real and simulated environments: the Linux Operating System and the ns-3 Network Simulator. We seek to analyze LISP capabilities, with emphasis in the manageability of the protocol, noticing that there is no clear Data and Control Plane separation in the specification.
The Internet has become a vast and complex infrastructure. One of the aspects of deeper concern in the community is routing scalability, which involves both the size and dynamics of the global Internet routing table. Many Future Internet initiatives stand for “clean slate” or disruptive approaches to overcome this issue; nevertheless, network operators need evolutionary solutions. In this paper we put forward a characterization of the IP prefix de-aggregation factor focussing on the Latin American region, where we found that a significant contribution to the growth of the routing table could be prevented by improving BGP configuration. In the context of our participation in the LISP+ALT testbed (an evolutionary Future Internet initiative), we identify initial management requirements for its deployment, according to our findings regarding the size and dynamics of the routing table.
The Locator/Identifier Separation Protocol (LISP) is one of the candidate solutions to address the scalability issues in inter-domain routing. The current proposals for its control plane (e.g., ALT, CONS, NERD) have various shortcomings, including the potential dropping of packets at LISP routers during the resolution of the EID-to-RLOC mapping. In this paper, we introduce a new Control Plane (CP) for LISP supported by an architecture that borrows concepts from both the Path Computation Element (PCE) and Intelligent Route Control (IRC). Our CP is able to tackle three different problems simultaneously: (i) packets sourced from end-hosts are neither dropped nor queued during the mapping resolution; (ii) the EID-to-RLOC mapping can be obtained and configured approximately within the DNS resolution time needed to fetch the destination EID address; and (iii) our approach can blend IRC with the PCE capabilities, to perform upstream/downstream Traffic Engineering (TE) through the dynamic management of the mappings. In particular, our CP supports the utilization of different LISP ingress and egress local routers for the same flow sourced from a domain.
Two-photon scanning fluorescence microscopy has become a powerful tool for imaging living cells and tissues. Most applications of two-photon microscopy employ a Ti:sapphire laser excitation source, which is not readily portable or rapidly tunable. This work explores the use of two-photon fiber laser excitation (TP-FLEX) as an excitation source for scanning two-photon microscopy. We have further demonstrated the use of a photonic crystal fiber (PCF) for facile tuning of the excitation wavelength over the range from 810 nm to 1100 nm. We generated two-photon fluorescence images at excitation wavelengths from 850 nm to 1100 nm detected on a scanning-stage microscope. By PCF wavelength tuning the dye BODIPY fl was selectively excited at 1000 nm whereas MitoTracker red was excited preferentially at 1100 nm. We discuss the potential for fiber laser sources coupled with PCF wavelength tuning as an attractive tunable excitation source for two-photon scanning fluorescence microscopy.
This work evaluates a femtosecond fiber laser for use in two‐photon fluorescence fluctuation spectroscopy. Fiber lasers present an attractive alternative to Ti:Sapphire systems because of their compact size and portability. Autocorrelation of the second harmonic generation signal from the laser demonstrates that its stability is sufficient for two‐photon fluorescence correlation spectroscopy. Fluorescence correlation spectroscopy autocorrelation traces were well fit by a Gaussian–Lorentzian squared model with a beam waist near the diffraction limit for the 810 nm wavelength. A photon counting histogram collected with this system also fit nicely to a single‐species model, further demonstrating the quality of the focal shape. The authors conclude that the output from the femtosecond fiber laser is sufficiently stable and has a high enough quality beam shape for fluctuation fluorescence methods, and thus represents an effective, compact, readily portable two‐photon excitation source. Microsc. Res. Tech., 2006. © 2006 Wiley‐Liss, Inc.