Wide-area overlay networking to manage science DMZ accelerated flows

Wide-area overlay networking to manage science DMZ accelerated flows
复制标题

用于管理科学 DMZ 加速流量的广域覆盖网络

DOI:
10.1109/iccnc.2014.6785344
复制
发表时间:
2014
期刊:
2014 International Conference on Computing, Networking and Communications (ICNC)
影响因子:
--
通讯作者:
D. Panda
D. Panda
中科院分区:
--
文献类型:
--
作者:
P. Calyam;Alex Berryman;Erik Saule;H. Subramoni;P. Schopis;G. Springer;Ümit V. Çatalyürek;D. Panda

文献摘要

被引文献

相似文献

在大学校园中出现了一种新的趋势,即部署科学DMZ(非军事区)以支持涉及数据密集型应用程序(例如,需要访问远程仪器或公共云资源)的科学驱动程序。使用先进的技术,如“多域”软件定义的网络,零拷贝RDMA数据传输,主动测量和联合身份/访问加速流开始从科学DMZ建立在广域覆盖网络上,绕过传统的校园防火墙。本文提出了一种“校园科学DMZ参考体系结构”,用于自适应地管理广域覆盖网络上多个研究人员在共享基础设施组件上的主机到主机加速流。我们讨论了我们在处理科学DMZ内的策略规范、安全实施和性能工程挑战方面的新方法,以支持可扩展/可扩展的各种加速流。最后,我们给出了一个生物信息学驱动程序在双端校园科学DMZ试验床上应用的多学科案例研究。我们的案例研究展示了我们的参考架构如何实现新的“高吞吐量计算服务”,从而改善数据密集型科学用户的远程可访问性和对等协作,并简化校园网服务提供商的相关操作/管理。
There is a new trend emerging across university campuses to deploy Science DMZs (demilitarized zones) to support science drivers that involve for e.g., data-intensive applications needing access to remote instrumentation or public cloud resources. Using advanced technologies such as “multi-domain” software-defined networking, zero-copy RDMA data transfers, active measurements and federated identity/access - accelerated flows are starting to be setup from Science DMZs over wide-area overlay networks, by-passing traditional campus firewalls. In this paper, we present a “campus Science DMZ reference architecture” for adaptively managing host-to-host accelerated flows of multiple researchers over wide-area overlay networks with shared underlay infrastructure components. We discuss our novel approaches in handling challenges of policy specification, security enforcement, and performance engineering within Science DMZs to support diverse accelerated flows on a scalable/extensible basis. Lastly, we present a multi-disciplinary case study of a bioinformatics science driver application in a double-ended campus Science DMZ testbed. Our case study illustrates how our reference architecture can enable new “High-Throughput Computing services” that improve remote accessibility and peer-collaboration of data-intensive science users, and simplify related operations/management for campus network service providers.