Score
Designs and specifies virtual private cloud (VPC) network architectures, including subnetting, IP addressing, routing, security controls (firewalls, access lists), NAT, and load balancing. Plans and configures VPC connectivity such as VPC peering, transit gateways/interconnects, VPNs, and routing/segmentation policies, and analyzes performance, reliability, and cost trade-offs.
This work systematically characterizes the computational complexity boundary of the Virtual Network Embedding (VNE) problem on canonical physical topologies—trees, cycles, wheels, and cliques—focusing specifically on the impact of topology while isolating confounding factors such as resource packing. Method: We establish NP-hardness for VNE on wheels and cliques via novel reductions, and design polynomial-time exact algorithms for trees and cycles—based on dynamic programming and greedy strategies, respectively. Contribution/Results: This is the first study to rigorously delineate the complexity dichotomy of VNE across fundamental graph classes. The proposed algorithms achieve both theoretical optimality and practical implementability. Our results fill a critical gap in the structural complexity theory of VNE and provide rigorous algorithmic guarantees and complexity criteria for efficient virtualization deployment in constrained-topology infrastructures—such as legacy telecommunication networks.
Existing user-space network stacks suffer from poor portability and deployment challenges due to overreliance on vendor-specific vNIC hardware features (e.g., flow classification, RSS reconfiguration) and rigid execution models. This work introduces Machnet, a lightweight user-space network stack designed for public cloud VMs. Machnet proposes a novel “least-common-denominator” virtual NIC abstraction—defining a minimal, cross-vendor-compatible set of primitives—and adopts a microkernel architecture instead of a library OS to balance flexibility with low inter-process communication overhead. Leveraging zero-copy I/O and a streamlined protocol stack, it achieves throughput and latency comparable to high-end, hardware-optimized stacks—even on commodity vNICs. Evaluated across major public clouds, Machnet demonstrates broad compatibility, simplified deployment, and enhanced developer ergonomics. It establishes a new paradigm for practical, portable user-space networking in heterogeneous cloud environments.
该研究使用软件定义网络(SDN)技术设计校园网的核心层,通过RouteFlow平台和OSPF协议提高网络的可用性和路由效率。
To address network performance bottlenecks arising from surging datacenter traffic and the slowing of Moore’s Law, this paper proposes the Reconfigurable Datacenter Network (RDCN) architecture—a paradigm shift from static topologies. We introduce the first systematic taxonomy of RDCNs (categorized along static/dynamic and oblivious/aware dimensions) and establish a formal model that uncovers causal relationships between spatiotemporal traffic patterns and topology evolution. Integrating optical circuit switching, dynamic graph modeling, traffic demand forecasting, and topology optimization algorithms, RDCN enables on-demand, adaptive, real-time reconfiguration. Experimental evaluation demonstrates that demand-aware reconfiguration reduces tail latency by over 40% and improves throughput utilization by 2–3×. This work establishes a new, highly elastic, energy-efficient, and scalable network paradigm for next-generation datacenters—one that actively adapts to dynamic workloads rather than passively accommodating them.
This study addresses performance bottlenecks of OpenVPN on resource-constrained Linksys WRT54GL routers. It systematically investigates the impact of encryption algorithms (AES-128, Blowfish, 3DES) and transport protocols (TCP/UDP) on throughput and round-trip time (RTT). Methodologically, it employs a $2^{5-1}$ fractional factorial design—the first such application in this context—to quantify main and interaction effects of five key factors. Empirical evaluation is conducted on DD-WRT firmware with OpenSSL-based OpenVPN configurations. Results demonstrate that cryptographic overhead is the dominant throughput bottleneck, with AES-128 achieving optimal trade-offs between security and efficiency; meanwhile, transport protocol selection governs RTT behavior, with UDP yielding significantly lower latency than TCP. This work establishes a reproducible experimental framework and provides empirical guidance for lightweight VPN deployment on embedded systems.
This study addresses the challenge of dynamically updating time-constrained segment routing traffic engineering in IP/MPLS networks by proposing a column generation optimization framework that accounts for temporal reconfiguration costs. Under configuration change budget constraints, the proposed method jointly optimizes traffic distribution and segment routing complexity to minimize maximum link utilization. It integrates column generation algorithms with integer programming techniques to efficiently solve large-scale network problems. Experimental evaluations on real-world datasets from Orange demonstrate that 80.45% of the test instances achieve an optimality gap below 5%, effectively balancing network performance with configuration stability.
本文针对云数据中心虚拟网络请求资源分配问题,提出基于模式匹配的在线虚拟网络嵌入方法,通过构建匹配规则最大化资源利用。
This work addresses the scalability limitations of traditional flow-level load balancing in data center networks, which stems from switches maintaining per-flow state. To overcome this, the authors propose a fully host-driven, fine-grained load balancing scheme that offloads flow-segment identification and path selection entirely to end hosts. By leveraging SRv6 for stateless forwarding in switches, the approach eliminates the need for per-flow state in the data plane. It further introduces a path load estimation model based on in-flight bytes and a dynamic flow-segment timeout mechanism. Experimental results demonstrate that, under fixed-size flow scenarios, the proposed method reduces tail latency by 15% compared to random flow-segment balancing and by 33% relative to ECMP. Significant improvements in multipath utilization and overall performance are also observed under real-world application workloads.
本文研究了在Amazon EKS上使用VPC-Native网络模式的大规模Pod部署问题,对比了三种VPC-Native模式与两种overlay基线的性能。
This work addresses the challenge of efficiently implementing zero-trust-compliant, multi-tenant secure network connectivity in computationally or entropy-constrained environments. The authors propose and implement a cloud-native VPN-as-a-Service (VPNaaS) solution that, for the first time, integrates zero-trust network isolation capabilities with customizable cryptographic algorithms—supporting either RSA or elliptic curve cryptography. The system enables on-demand, dynamic provisioning of tenant-level isolated secure tunnels and seamlessly interoperates with mainstream identity and access management (IAM) platforms. By adhering to the principle of least privilege and enforcing strict multi-tenancy isolation, the proposed approach significantly enhances both deployment efficiency and security in resource-constrained settings.