• DocumentCode
    1606877
  • Title

    Security enhancements for a user-controlled lightpath provisioning system

  • Author

    Wu, Jing ; Savoie, Michel ; Zhang, Hanxi ; Campbell, Scott

  • Author_Institution
    Commun. Res. Centre Canada, Ottawa, ON, Canada
  • fYear
    2006
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    User owned and managed optical networks offer new benefits compared to carrier networks. There are basically two types of user owned and managed optical networks: metro dark fibre networks and long-haul wavelength networks. A user-controlled lightpath provisioning system is designed to address the network management challenges, where only the customer has complete visibility of its own network and no provider can see all the network elements. The prototyped management software has a service-oriented architecture and uses the Jini and JavaSpaces technologies. Within one management system for a federation, there are six key components: a Jini Lookup Service, an instance of JavaSpaces for storage of Light Path Objects (LPOs), a Jini Service Access Point (SAP), an LPO service, an instance of switch communication service for each switch in the transport layer and a Grid SAP. Since the new management system is a distributed system and the new management system may be deployed over a public Internet infrastructure, secure access to the management modules is required. The application of existing system security technologies to the new management system is analyzed. To securely transfer objects across a network, SSL is used to encrypt RMI data streams and thus data streams between Jini services. To securely execute a dynamically downloaded Java class, Jini adopts the Java security model. To securely use a dynamically downloaded proxy to communicate to a remote service, Jini Extensible Remote Invocation is implemented to support security features such as invocation constraints, remote method control, and the trust verification model.
  • Keywords
    Internet; grid computing; optical computing; optical fibre networks; security of data; software architecture; telecommunication network management; Grid SAP; JavaSpaces technologies; Jini Lookup Service; Jini extensible remote invocation; distributed system; dynamically downloaded proxy; invocation constraints; light path objects; long-haul wavelength networks; metro dark fibre networks; network management challenges; prototyped management software; public Internet infrastructure; remote method control; remote service; security enhancements; service access point; service-oriented architecture; trust verification model; user-controlled lightpath provisioning system; Communication switching; Communication system security; Data security; Internet; Java; Optical fiber networks; Service oriented architecture; Software prototyping; Switches; Technology management; Distributed Software Security; Network Management Software; User-Controlled Lightpath Provisioning;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computing & Informatics, 2006. ICOCI '06. International Conference on
  • Conference_Location
    Kuala Lumpur
  • Print_ISBN
    978-1-4244-0219-9
  • Electronic_ISBN
    978-1-4244-0220-5
  • Type

    conf

  • DOI
    10.1109/ICOCI.2006.5276416
  • Filename
    5276416