This paper presents an end-to-end architecture, called VSITE, for seamless integration of cloud resources into an enterprise's intranet at layer 2. VSITE allows a cloud provider to carve out its resources to serve multiple enterprises simultaneously while maintaining isolation and security. Resources (allocated to an enterprise) in the cloud provider appears "internal" to the enterprise. VSITE achieves this abstraction through the use of VPN technologies, the assignment of different VLANs to different enterprises, and the encoding of enterprise IDs in MAC addresses. Unlike traditional layer 2 VPN technology such as VPLS, VSITE suppresses layer 2 MAC learning related broadcast traffic from reaching the remote sites. VSITE makes use of location IP (represents location area) for scalable migration support. The MAC or IP address of a VM is not visible in data center core. VSITE hypervisor enforces security mechanisms to prevent enterprises from attacking one another. Thus, VSITE is scalable, secure and efficient, and it facilitates common data center operation such as VM migration. Because VSITE extends enterprise network at layer 2, this offers transparency to most existing applications and presents an easy migration path for an enterprise to leverage cloud computing resources.
[1]
Amin Vahdat,et al.
Helios: a hybrid electrical/optical switch architecture for modular data centers
,
2010,
SIGCOMM '10.
[2]
Hovav Shacham,et al.
Hey, you, get off of my cloud: exploring information leakage in third-party compute clouds
,
2009,
CCS.
[3]
Jennifer Rexford,et al.
Floodless in seattle: a scalable ethernet architecture for large enterprises
,
2008,
SIGCOMM '08.
[4]
Prashant J. Shenoy,et al.
The Case for Enterprise-Ready Virtual Private Clouds
,
2009,
HotCloud.
[5]
Albert G. Greenberg,et al.
VL2: a scalable and flexible data center network
,
2009,
SIGCOMM '09.
[6]
Sriram Ramabhadran,et al.
Cloud control with distributed rate limiting
,
2007,
SIGCOMM '07.
[7]
Amin Vahdat,et al.
PortLand: a scalable fault-tolerant layer 2 data center network fabric
,
2009,
SIGCOMM '09.