Abstract

In this paper, we focused on two prevailing architectural approaches for control-plane virtualization in multi-tenant OpenFlow-ready SDN domains: The first permits the delegation of a specific, non-overlapping part of the overall flowspace to each tenant OpenFlow controller, exposing him/her the entire substrate topology; the second conceals the substrate topology to tenants by abstracting resources and exposing user-controlled (tenant) Virtual Networks (VNs). For both cases, we propose and analyze three control-plane slicing methods (domain, switch and port-wide), enforced by the management plane, that safeguard control-plane isolation among tenant VNs. Their effectiveness is assessed in terms of control-plane resources (number of flowspace policy rule entries, table lookup times and memory consumption) via measurements on a prototype implementation. To that end, we introduced and prototyped the Flowspace Slicing Policy (FSP) rule engine, an automated mechanism translating substrate management-plane policies into VN mapping control-plane rules. Our experiments, involving thousands of tenants VN requests over a variety of WAN-scale network topologies (e.g. Internet2/OSE3 and GÉANT), demonstrate that the port-wide slicing method is the most efficient in terms of tenant request acceptance ratio, within acceptable control-plane delays and memory consumption.

Keywords:
Computer science OpenFlow Forwarding plane Multitenancy Slicing Network topology Software-defined networking Network virtualization Virtualization Distributed computing Node (physics) Computer network Topology (electrical circuits) Software Operating system Engineering Software development

Metrics

9
Cited By
1.00
FWCI (Field Weighted Citation Impact)
29
Refs
0.80
Citation Normalized Percentile
Is in top 1%
Is in top 10%

Citation History

Topics

Software-Defined Networks and 5G
Physical Sciences →  Computer Science →  Computer Networks and Communications
Network Security and Intrusion Detection
Physical Sciences →  Computer Science →  Computer Networks and Communications
Internet Traffic Analysis and Secure E-voting
Physical Sciences →  Computer Science →  Artificial Intelligence

Related Documents

JOURNAL ARTICLE

Multi-Tenant Isolation in Software Defined Networks

Irum, S.Luedke, P.Warnke, K.Schulte, G.

Journal:   Zenodo (CERN European Organization for Nuclear Research) Year: 2018
BOOK-CHAPTER

Multi-tenant Isolation in Software Defined Networks

Sarah IrumPatrick LuedkeKlaus WarnkeGerrit Schulte

Lecture notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering Year: 2018 Pages: 367-376
JOURNAL ARTICLE

Network slicing in software datapaths for 5G multi-tenant networks

Escolar, Antonio Matencio

Journal:   Zenodo (CERN European Organization for Nuclear Research) Year: 2024
JOURNAL ARTICLE

Network slicing in software datapaths for 5G multi-tenant networks

Escolar, Antonio Matencio

Journal:   Zenodo (CERN European Organization for Nuclear Research) Year: 2024
© 2026 ScienceGate Book Chapters — All rights reserved.