首页> 外文期刊>Communications Surveys & Tutorials, IEEE >A Survey of Network Isolation Solutions for Multi-Tenant Data Centers
【24h】

A Survey of Network Isolation Solutions for Multi-Tenant Data Centers

机译:多租户数据中心的网络隔离解决方案概述

获取原文
获取原文并翻译 | 示例

摘要

The infrastructure-as-a-service model is one of the fastest growing opportunities for cloud-based service providers. It provides an environment that reduces operating and capital expenses while increasing agility and reliability of critical information systems. In this multitenancy environment, cloud-based service providers are challenged with providing a secure isolation service combining different vertical segments, such as financial or public services, while nevertheless meeting industry standards and legal compliance requirements within their data centers. In order to achieve this, new solutions are being designed and proposed to provide traffic isolation for a large numbers of tenants and their resulting traffic volumes. This survey highlights key challenges that cloud-based service providers might encounter while providing multitenant environments. It also succinctly describes some key solutions for providing simultaneous tenant and network isolation, as well as highlights their respective advantages and disadvantages. We begin with generic routing encapsulation introduced in 1994 in “RFC 1701,” and will conclude with today’s latest solutions. We detail 15 of the newest architectures and then compare their complexities, the overhead they induce, their VM migration abilities, their resilience, their scalability, and their multidata center capacities. This paper is intended for, but not limited to, cloud-based service providers who want to deploy the most appropriate isolation solution for their needs, taking into consideration their existing network infrastructure. This survey provides details and comparisons of various proposals while also highlighting possible guidelines for future research on issues pertaining to the design of new network isolation architectures.
机译:基础设施即服务模型是基于云的服务提供商增长最快的机会之一。它提供了一种环境,可减少运营和资本支出,同时提高关键信息系统的敏捷性和可靠性。在这种多租户环境中,基于云的服务提供商面临的挑战是提供安全隔离服务,该服务结合了不同的垂直细分市场,例如金融或公共服务,同时又要满足其数据中心内的行业标准和法律合规性要求。为了实现这一点,正在设计和提出新的解决方案,以为大量租户及其产生的流量提供流量隔离。该调查重点介绍了基于云的服务提供商在提供多租户环境时可能遇到的主要挑战。它还简要介绍了一些用于同时提供租户和网络隔离的关键解决方案,并重点介绍了它们各自的优点和缺点。我们从1994年在“ RFC 1701”中引入的通用路由封装开始,然后以今天的最新解决方案结束。我们详细介绍了15种最新的体系结构,然后比较了它们的复杂性,它们引起的开销,其VM迁移能力,其弹性,可伸缩性以及它们的多数据中心容量。本文面向(但不限于)基于云的服务提供商,他们希望在考虑其现有网络基础结构的情况下为其需求部署最合适的隔离解决方案。这项调查提供了各种建议的详细信息和比较,同时还着重指出了有关与新网络隔离体系结构设计有关的问题的未来研究的可能准则。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号