IEEE Communications Magazine · 2006 · 34 citations · 3 references
EngineeringInformation SecurityNetwork ComputingConfidential ComputingHardware SecurityService PlaneSystems EngineeringNovel Network PlaneNetwork ManagementSecure ComputingInternet Of ThingsTrusted Execution EnvironmentAdvanced NetworkingNetwork VirtualizationSoftware-defined NetworkingSecure Lightpath CreationComputer EngineeringComputer ScienceData SecurityCryptographyProgrammable ParadigmEdge ComputingCloud Computing
We realize an open, programmable paradigm for application-driven network control by way of a novel network plane - the "service plane" - layered above legacy networks. The service plane bridges domains, establishes trust, and exposes control to credited users/applications while preventing unauthorized access and resource theft. The authentication, authorization, and accounting subsystem and the dynamic resource allocation controller are the two defining building blocks of our service plane. In concert, they act upon an interconnection request or a restoration request according to application requirements, security credentials, and domain-resident policy. We have experimented with such service plane in an optical, large-scale testbed featuring two hubs (NetherLight in Amsterdam, StarLight in Chicago) and attached network clouds, each representing an independent domain. The dynamic interconnection of the heterogeneous domains occurred at Layer 1. The interconnections ultimately resulted in an optical end-to-end path (lightpath) for use by the requesting grid application.
3
Tom DeFanti, Cees de Laat, Joe Mambretti et al. · Communications of the ACM · 2003 · 110 citations
Authorization of a QoS Path based on Generic AAA
Leon Gommans, Cees de Laat, Bas van Oudenaarde et al. · 2003 · 21 citations