Abstract
This paper presents Policy-based Federation (PBF) architecture for interworked Future Internet Virtualized Infrastructures (VIs). Each VI is an individually managed autonomous domain. Users may request slices of virtual resources across the federation, managed and controlled via inter-domain policies that abide by agreed upon federated SLAs. The key component of our PBF architecture is a Policy Service, which provides support for intra-domain policies (Obligation, Authorization, Role-Based Access Control) and for inter-domain Delegation policies. Delegation policies reserve resources in remote domains, update the number of resources exchanged, set alien domain obligations for cross-domain resource provisioning and define the exchange of internal domain information through the execution of remote semantic queries. Key to the architecture is the PBF Policy Ontology that specifies common federation concepts within the context of a user slice and the PBF services that trigger management actions. A prototype of the proposed architecture was developed and deployed in a European Future Internet federated testbed.
Similar content being viewed by others
Notes
NOVI, http://www.fp7-novi.eu.
PlanetLab, http://planet-lab.org.
GENI, http://www.geni.net.
SAVI, http://www.savinetwork.ca.
FEDERICA. http://www.fp7-federica.eu.
FIRE, http://wiki.ict-fire.eu.
Fed4FIRE, http://www.fed4fire.eu.
PlanetLab, http://planet-lab.org.
DMTF, http://www.dmtf.org.
Ponder2, http://ponder2.net.
References
Maglaris, V., Papagianni, C., Androulidakis, G., Grammatikou, M., Grosso, P., Van Der Ham, J., De Laat, C., Pietrzak, B., Belter, B., Steger, J., Laki, S., Campanella, M., Sallent, S.: Toward a holistic federated future internet experimentation environment: the experience of NOVI research and experimentation. IEEE Commun. Mag. 53(7), 136–144 (2015)
van der Ham, J., Stéger, J., Laki, S., Kryftis, Y., Maglaris, V., de Laat, C.: The NOVI information models. Future Gener. Comput. Syst. 42, 64–73 (2015)
Peterson, L., Anderson, T., Culler, D., Roscoe, T.: A blueprint for introducing disruptive technology into the internet. ACM SIGCOMM Comput. Commun. Rev. 33, 59–64 (2003)
Szegedi, P., Figuerola, S., Campanella, M., Maglaris, V., Cervelló-Pastor, C.: With evolution for revolution: managing FEDERICA for future internet research. IEEE Commun. Mag. 47(7), 34–39 (2009)
Grasa, E., Junyent, G., Figuerola, S., Lopez, A., Savoie, M.: UCLPv2: a network virtualization framework built on web services [web services in telecommunications, part II]. IEEE Commun. Mag. 46(3), 126–134 (2008)
Peterson, L., Ricci, R., Falk A., Chase, J.: Slice-based federation architecture. GENI Technical Document http://groups.geni.net/geni/raw-attachment/wiki/SliceFedArch/SFA2.0.pdf. July 2010
Bhatia, S., Bavier, A., Peterson, L., Sevinc, S.: sfatables: a Firewall-like policy engine for federated systems. In: IEEE Distributed computing systems (ICDCS), pp. 467–476 (2011)
Strassner, J.: Policy-based network management: solutions for the next generation. Morgan Kaufmann (2003)
Sloman, M.: Policy driven management for distributed systems. J. Netw. Syst. Manag. 2(4), 333–360 (1994)
Alaettinoglu, C., Villamizar, C., Gerich, E., Kessens, D., Meyer, D., Bates, T., Karrenberg, D., Terpstra, M.: Routing policy specification language (RPSL). RFC 2622 (1999)
Boyle, J., Cohen, R., Herzog, S., Rajan, R., Sastry, A., Durham, D.: The COPS (Common Open Policy Service) Protocol. RFC 2748 (2000)
Romeikat, R.: Domain-specific development of event condition action policies. Logos Verlag Berlin GmbH (2014)
Strassner, J.: DEN-ng: achieving business-driven network management. In: Network operations and management symposium—IEEE NOMS, pp. 753–766 (2002)
Strassner, J., Van Der Meer, S., Jennings, B., De Leon, M.P.: An autonomic architecture to manage ubiquitous computing networks and applications. In: Ubiquitous and Future Networks—ICUFN, pp.116–121 (2009)
Damianou, N., Dulay, N., Lupu, E., Sloman, M.: The ponder policy specification language. In: Lecture notes on computer science, pp. 18–38 (2001)
Twidle, K., Dulay, N., Lupu, E., Sloman, M.: Ponder2: a policy system for autonomous pervasive environments. In: IEEE autonomic and autonomous systems, pp. 330–335 (2009)
Davy, S., Jennings, B., Strassner, J.: The policy continuum-policy authoring and conflict analysis. Comput. Commun. 31(13), 2981–2995 (2008)
Kagal, L., Finin, T., Joshi, A.: A policy based approach to security for the semantic web. Int. Semant. Web Conf. 2870, 402–418 (2003)
Uszok, A., Bradshaw, J.M., Johnson, M., Jeffers, R., Tate, A., Dalton, J., Aitken, S.: KAoS policy management for semantic web services. IEEE Intell. Syst. 19(4), 32–41 (2004)
Han, W., Lei, C.: A survey on policy languages in network and security management. Comput. Netw. 56(1), 477–489 (2012)
Xu, M., Wijesekera, D., Zhang, X.: Runtime administration of an RBAC profile for XACML. IEEE Trans. Serv. Comput. 4(4), 286–299 (2011)
Batista, B.L., Fernandez, M.P.: PonderFlow: a new policy specification language to SDN OpenFlow-based networks. Int. J. Adv. Netw. Serv. 7(3 and 4), 163–172 (2014)
Giotis, K., Kryftis, Y., Maglaris, V.: Policy-based orchestration of NFV services in software defined networks. In: IEEE Network Softwarization (NetSoft), pp. 1–5 (2015)
Ata, S., Huang, D., Liu, X., Wada, A., Xing, T., Juluri, P., Chung, C.-J., Sato, Y., Medhi, D.: SeRViTR: a framework, implementation, and a testbed for a trustworthy future internet. Comput. Netw. 61, 128–146 (2014)
Van der Ham, J., Grosso, P., Van der Pol, R., Toonk, A., De Laat, C.: Using the network description language in optical networks. In: IEEE integrated network management, pp. 199–205 (2007)
Van der Ham, J., Papagianni, C., Steger, J., Matray, P., Kryftis, Y., Grosso, P., Lymberopoulos, L.: Challenges of an information model for federating virtualized infrastructures. In: IEEE systems and virtualization management, pp. 1–6 (2011)
Lymberopoulos, L., Grosso, P., Papagianni, C., Kalogeras, D., Androulidakis, G., Van Der Ham, J., De Laat, C., Maglaris, V.: Managing federations of virtualized infrastructures: a semantic-aware policy based approach. In: IEEE integrated network management, pp. 1235–1242 (2011)
Sloman, M., Lupu, E.: Engineering policy-based ubiquitous systems. Comput. J. 53(7), 1113–1127 (2010)
Lupu, E., Dulay, N., Sloman, M., Sventek, J., Heeps, S., Strowes, S., Twidle, K., Keoh, S.-L., Schaeffer-Filho, A.: AMUSE: autonomic management of ubiquitous e-health systems. Concurr. Comput. Pract. Exp. 20(3), 277–295 (2008)
Wibisono, A., Koning, R., Grosso, P., Belloum, A., Bubak, M., De Laat, C.: OIntEd: online ontology instance editor enabling a new approach to ontology development. J. Softw. Pract. Exp. 43, 1319–1335 (2013)
Chappell, D.: Enterprise service bus. O’Reilly Media, Inc. (2004)
Pashalidis, A., Mitchell, C.J.: A taxonomy of single sign-on systems. Inf. Secur. Priv. 2727, 249–264 (2003)
Stéger, J., Laki, S., Mátray, P.: A monitoring framework for federated virtualized infrastructures. Meas. Methodol. Tools 7586, 175–194 (2013)
Chowdhury, N.M., Rahman, M.R., Boutaba, R.: Virtual network embedding with coordinated node and link mapping. In: IEEE INFOCOM, pp. 783–791 (2009)
Papagianni, C., Leivadeas, A., Papavassiliou, S., Maglaris, V., Cervello-Pastor, C., Monje, A.: On the optimal allocation of virtual resources in cloud computing networks. IEEE Trans. Comput. 62(6), 1060–1071 (2013)
Bell, D.: UML basics: an introduction to the unified modeling language. The Rational Edge (2003)
Pérez, J., Arenas, M., Gutierrez, C.: Semantics and complexity of SPARQL. Int. Semant. Web Conf. 4237, 30–43 (2006)
Pittaras, C., Papagianni, C., Leivadeas, A., Grosso, P., van der Ham, J., Papavassiliou, S.: Resource discovery and allocation for federated virtualized infrastructures. Future Gener. Comput. Syst. 42, 55–63 (2015)
Acknowledgments
This work was partially supported by the European Commission, 7th Framework Programme for Research and Technological Development, Future Internet Research and Experimentation (FIRE), Grant No. 257867—NOVI.
The authors wish to thank their NOVI collaborators that greatly contributed to this work with their ideas and support. Notably we appreciated the help of: Dr. Leonidas Lymberopoulos (now with EXUS, Athens, Greece) and Dr. Chrysa Papagianni (NTUA); Dr. Paola Grosso, Dr. Jeroen van der Ham, Chariklis Pittaras and Prof. Cees de Laat (University of Amsterdam); Bartosz Belter, Pietrzak Błażej and Piotr Pikusa (Poznań Supercomputing and Networking Center—PSNC); Dr. József Stéger, Laki Sándor and Prof. Gábor Vattay (Eötvös Loránd University—ELTE, Budapest); Dr. Klaas Wierenga (Cisco Systems).
Author information
Authors and Affiliations
Corresponding author
Rights and permissions
About this article
Cite this article
Kryftis, Y., Grammatikou, M., Kalogeras, D. et al. Policy-Based Management for Federation of Virtualized Infrastructures. J Netw Syst Manage 25, 229–252 (2017). https://doi.org/10.1007/s10922-016-9390-z
Received:
Revised:
Accepted:
Published:
Issue Date:
DOI: https://doi.org/10.1007/s10922-016-9390-z