Peilin Hong

dblp:15/2421 · DBLP profile ↗
← Back
73ranked-venue papers
0as first author
14since 2021 · last 2025
0000-0002-3027-1990ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 42 · 10 since 2021Security and privacy · 8 · 1 since 2021Systems, architecture and hardware · 4Artificial intelligence and machine learning · 2 · 2 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2Theory of computation · 1
YearPublicationVenuePosition
2025 CPM-based Hierarchical Text Classification
abstract
In the field of natural language processing, hierarchical text classification (HTC) has emerged as a critical task for organizing and analyzing large volumes of text data. The previous work of HTC often falls short in fully leveraging the hierarchical structure of labels, resulting in suboptimal performance. In addition, it is difficult to capture nuanced relationships between parent and child classes, leading to inaccurate predictions and insufficient differentiation between sibling classes under the same parent category. This gap underscores the need for approaches that can more effectively integrate and utilize both hierarchical and corpus-specific information to improve HTC performance. To address these issues, Concept-aware Prompt Mechanism (CPM) is proposed for HTC, which leverages concept information embedded within hierarchical labels to enhance the representation of these labels and improve classification accuracy. Specifically, we introduce a concept initialization module that extracts concept features from hierarchical labels and a novel concept prompt template to integrate these features into the classification process. Our experimental results demonstrate that the proposed CPM achieves state-of-the-art performance on two benchmark datasets, improving Micro-F1 and Macro-F1 scores to varying degrees, particularly in datasets with complex label hierarchies.
Yihao Peng, Peilin Hong
J. Artif. Intell. Res.4
2024 SIM: Sub-RTT-based Incast Mitigation in Data Center Networks
abstract
Recently, many Remote Direct Memory Access (RDMA) congestion control (CC) algorithms have been proposed to ensure the performance of high-speed Data Center Networks (DCNs). However, there is an inherent feedback delay in end-to-end CC, resulting in the inability to exert control over each flow within its first RTT. Upon many-to-one (Incast), the immediate high queue introduces significant latency to the short flows. In this paper, we propose SIM, a Sub-RTT-based Incast mitigation scheme to enhance congestion control. SIM offers two key functionalities: it enables the detection and notification of Incast within Sub-RTT, and it provides an adaptive adjustment algorithm that responds based on the severity of the Incast. Simulation results show that SIM fundamentally reduces the peak queue of Incast and shortens 99% FCT slowdown of short flows by up to 70% and 47% compared to the state-of-the-art congestion control schemes in DCNs, respectively.
Guanglei Chen, Peilin Hong
ISCC4
2024 Context-aware graph embedding with gate and attention for session-based recommendation
Junlong Chi, Peilin Hong, Guangming Lu 0002, David Zhang 0001, Bingzhi Chen
Neurocomputing3
2024 CACC: A Congestion-Aware Control Mechanism to Reduce INT Overhead and PFC Pause Delay
abstract
Nowadays, Remote Direct Memory Access (RDMA) is gaining popularity in data centers for low CPU overhead, high throughput, and ultra-low latency. As one of the state-of-the-art RDMA Congestion Control (CC) mechanisms, HPCC leverages the In-band Network Telemetry (INT) features to achieve accurate control and significantly shortens the Flow Completion Time (FCT) for short flows. However, there exists redundant INT information increasing the processing latency at switches and affecting flows’ throughput. Besides, its end-to-end feedback mechanism is not timely enough to help senders cope well with bursty traffic, and there still exists a high probability of triggering Priority-based Flow Control (PFC) pauses under large-scale incast. In this paper, we propose a Congestion-Aware (CA) control mechanism called CACC, which attempts to push CC to the theoretical low INT overhead and PFC pause delay. CACC introduces two CA algorithms to quantize switch buffer and egress port congestion, separately, along with a fine-grained window size adjustment algorithm at the sender. Specifically, the buffer CA algorithm perceives large-scale congestion that may trigger PFC pauses and provides early feedback, significantly reducing the PFC pause delay. The egress port CA algorithm perceives the link state and selectively inserts useful INT data, achieving lower queue sizes and reducing the average overhead per packet from 42 bytes to 2 bits. In our evaluation, compared with HPCC, PINT, and Bolt, CACC shortens the average and tail FCT by up to 27% and 60.1%, respectively.
Xiwen Jie, Jiangping Han, Guanglei Chen, Peilin Hong, Kaiping Xue
IEEE Trans. Netw. Serv. Manag.5
2023 A Defense Strategy Against LDDoS Attack Aggregation in DCN
abstract
Multi-tenancy and the vulnerabilities of network isolation make Low-Rate Distributed Denial-of-Service (LDDoS) severe threats to cloud data centers. Due to the stealthy nature of the LDDoS attack, it is not easy to detect in data center networks (DCN) with frequent Incast traffic. And the traditional Detect-Drop defense strategy may drop some benign flows, significantly reducing user experience. To this end, this paper first proposes a mathematical model that reveals the attack aggregation mechanism and queuing pattern of LDDoS attack in DCN. On this basis, this article proposes a novel defense strategy that can interfere with LDDoS attack aggregation without breaking the benign user's connection. When there is an attack detected, the information of normal and suspicious flows will be roughly grouped and notified to the preceding switch, where they will enter different switch queues separately. Afterward, the packets in the suspicious flow queue will be added with a subtle delay when dequeuing. As for the attack flows, it directly results in the inability to aggregate into large pulses. For the normal flow, it merely increases the flow completion time (FCT) by a few microseconds. It is due to this property that the method proposed can defend against attacks without affecting the connection of the normal flows. The simulation results are consistent with the theoretical analysis and show that this strategy can effectively recover the network performance. Moreover, it achieves excellent robustness at low detection accuracy, making it suitable for running in DCN.
Peilin Hong
ICC3
2023 FACC: Flow-Size-Aware Congestion Control in Data Center Networks
abstract
The distribution of traffic shows a characteristic of different flow sizes in Data Center Networks (DCNs), which requires diverse demands for data transmission. However, most existing congestion control schemes treat all the flows equivalently and have a consistent control logic, which cannot meet the diverse demands of applications. In this paper, we propose FACC, a flow-size-aware congestion control scheme. In FACC, we design a distinguished congestion control logic to assign the transmission demands of different kinds of flows in the network. To meet the diverse demands, FACC provides an adaptable congestion window (cwnd) adjustment by assigning customized weights with a well-designed flow-size-aware reward function. Simulation results show that FACC can reduce the average FCT and the 99- th percentile FCT slowdown of short flows by 35% and 23% compared to the state-of-the-art congestion control schemes in DCNs, respectively.
Guanglei Chen, Jiangping Han, Xiwen Jie, Peilin Hong, Kaiping Xue
ISCC4
2023 F2-HPCC: Achieve Faster Convergence and Better Fairness for HPCC
abstract
In recent years, Remote Direct Memory Access (RDMA) has been widely deployed in data centers to provide low-latency and high-bandwidth services. To ensure high performance in RDMA networks, congestion control manages queue depth on switches to minimize queueing delays. Although HPCC, the state-of-the-art scheme, can significantly reduce the flow completion time (FCT) of short flows, it still suffers from slow convergence and unfairness, which will affect the tail FCT of large flows. In this paper, we first analyze the causes of these defects and then propose an improved scheme called F2-HPCC, which introduces a self-adjusting additive increase algorithm to accelerate converging and a sliding window algorithm to improve fairness. In our evaluation, F2- HPCC achieves faster convergence and fairer allocations without sacrificing queue length and shortens the tail FCT of large flows by up to 33% under real data center workloads.
Xiwen Jie, Runzhou Li, Guanglei Chen, Peilin Hong
ISCC5
2022 Efficient and Secure Attribute-Based Access Control With Identical Sub-Policies Frequently Used in Cloud Storage
abstract
Under the assumption of honest-but-curious cloud service provider, various cryptographic techniques have been used to address the issues of data access control and confidentiality in public cloud storage. Among which, attribute-based encryption (ABE) has been shown to be an attractive scheme. Although the technique of ABE brings in various benefits, its onerous overhead should not be ignored. In this article, based on an improved LSSS (linear secret sharing scheme) matrix expression integrated in CP-ABE (Ciphertext-Policy Attribute-Based Encryption) algorithm, we present an efficient and secure attribute-based access control scheme for the scenarios where multiple data are shared and encrypted with frequently used sub-policies. In the scheme, a user can store the parameters about a specific sub-policy in his/her first decryption, which can be reused in the subsequent data decryptions whose embedded access policies include the same sub-policy so as to significantly reduce the computation cost. Our proposed scheme is proved to be semantically secure under chosen plaintext attacks and can well preserve the confidentiality of the data sharing system. Our analysis and experimentation also show that our scheme does significantly reduce the decryption time and while trades in only very little storage overhead, and thus effectively promotes the efficiency.
Kaiping Xue, Na Gai, Jianan Hong, David S. L. Wei, Peilin Hong, Nenghai Yu
IEEE Trans. Dependable Secur. Comput.5
2022 Reliability Enhancement for VR Delivery in Mobile-Edge Empowered Dual-Connectivity Sub-6 GHz and mmWave HetNets
abstract
The reliability of current virtual reality (VR) delivery is low due to the limited resources on VR head-mounted displays (HMDs) and the transmission rate bottleneck of sub-6 GHz networks. In this paper, we propose a dual-connectivity sub-6 GHz and mmWave heterogeneous network architecture empowered by mobile edge capability. The core idea of the proposed architecture is to utilize the complementary advantages of sub-6 GHz links and mmWave links to conduct a collaborative edge resource design, which aims to improve the reliability of VR delivery. From the perspective of stochastic geometry, we analyze the reliability of VR delivery and theoretically demonstrate that sub-6 GHz links can be used to enhance the reliability of VR delivery despite the large mmWave bandwidth. Based on our analytical work, we formulate a joint caching and computing optimization problem with the goal to maximize the reliability of VR delivery. By analyzing the coupling caching and computing strategies at HMDs, sub-6 GHz and mmWave base stations (BSs), we further transform the problem into a multiple-choice multi-dimension knapsack problem. A best-first branch and bound algorithm and a difference of convex programming algorithm are proposed to obtain the optimal and sub-optimal solution, respectively. Numerical simulations demonstrate the performance improvement using the proposed algorithms, and reveal that caching more monocular videos at sub-6 GHz BSs and more stereoscopic videos at mmWave BSs can improve the VR delivery reliability efficiently.
Zhuojia Gu, Hancheng Lu, Peilin Hong, Yongdong Zhang 0001
IEEE Trans. Wirel. Commun.3
2022 Resource Allocation for Uplink NOMA-Based D2D Communication in Energy Harvesting Scenario: A Two-Stage Game Approach
abstract
Energy harvesting (EH) endows device-to-device (D2D) communication and cellular equipment with the ability of continuous communication to provide internet-of-things (IoT) services in natural areas. While the available energy, which relies on EH, becomes an extra nonnegligible factor in resource allocation. Besides, we integrate uplink non-orthogonal multiple access (NOMA) with D2D communication to provide multiple access for D2D transmitters for more efficient IoT service and more efficient utilization of limited spectrum. In this scenario, ingenious resource allocation approach is a key focus for utilizing the advantages in energy and spectral efficiency. Aiming to investigate the inherent resource allocation issue, we set our goal as maximizing the energy efficiency for both NOMA-based D2D groups and cellular users (CUs), where the power and spectrum allocation are both considered. Then we propose a two-stage game approach, which is theoretically proved to be capable of obtaining the equilibrium and a stable result, to solve the unilateral energy efficiency maximization problems. Besides, an energy-aware screening method is proposed to reduce the computations based on the available energy of user equipment. Finally, the effectiveness of our proposed method is verified through elaborated simulation results.
Runzhou Li, Peilin Hong, Kaiping Xue, Ming Zhang 0029, Te Yang
IEEE Trans. Wirel. Commun.2
2022 Cooperative Robust Video Multicast in Integrated Terrestrial-Satellite Networks
abstract
Integrated terrestrial-satellite networks (ITSNs) are the promising trends of future networks. However, there exist great challenges when performing video multicast in ITSNs due to the strong heterogeneity of users in comprehensive satellite coverage and the inter-system complex co-channel interference. To overcome these, we make the first attempt to propose an efficient cooperative robust video multicast (CRVM-ITSN) framework in ITSNs. The basic idea is to leverage the non-orthogonal multiple access technique in the cooperative transmission of ITSNs to achieve high-efficiency robust video multicast. The desired robust multicast performance realizes that the recovered video quality can adapt to diverse channel conditions of users. In CRVM-ITSN, to achieve the optimal cooperative transmission performance, power allocation and chunk scheduling of video data are jointly formulated as a distortion minimization problem, which is a non-convex mixed integer non-linear programming problem. To solve it, we design a provably convergent optimal algorithm by converting it to be convex. Besides, based on the theorem on optimal chunks selection of satellite cooperative transmission, a low-complexity chunk grouping algorithm is proposed to accelerate the optimal algorithm. Simulation results have demonstrated the superiority of proposed CRVM-ITSN against existing reference schemes, achieving about 4.1dB more gains in the recovered video quality.
Ming Zhang 0029, Hancheng Lu, Peilin Hong
IEEE Trans. Wirel. Commun.3
2021 Flow-level Adaptive Routing Scheme for RDMA enabled Dragonfly Network
abstract
To minimize the number of expensive global links, Dragonfly topology is developed greatly in today's data centers. However, deploying Remote Direct Memory Access (RDMA) applications inside Dragonfly requires the network to provide a routing scheme running at the flow level to avoid packet disorder. The existing Dragonfly routing scheme uses queue length to estimate link load, which is not a reasonable criterion for flow-level routing. In this paper, we use the amount of remaining data of flows to estimate the flow completion time and propose our routing scheme, named Remaining Data-based Adaptive Load-balance (RDAL). We compare the performance of RDAL with another routing scheme at the flow level. Our simulation shows that for flow-level routing, RDAL provides improvements in both average flow completion time and saturation throughput, especially in the adversarial traffic pattern. At most, RDAL can increase saturation throughput by 12% and reduce average flow completion time by 34% than UGAL, the state-of-the-art routing scheme for Dragonfly,
Ming Zhang 0029, Peilin Hong
GLOBECOM3
2021 Flow-Level Rerouting in RDMA-Enabled Dragonfly Networks
abstract
Due to the characteristic of large-radix routers, the Dragonfly topology can achieve low diameter, high performance/cost ratio. However, in the Dragonfly networks deployed with Remote Direct Memory Access (RDMA), existing packet-level routing algorithms which are mostly based on queue length information, are neither good enough to achieve load balancing nor meet the requirement of in order. To tackle the above issues, we first analyze the drawbacks of flow-level source routing in RDMA-enabled Dragonfly networks. Then, a flow-level rerouting scheme that can estimate traffic distribution and link load based on the routers' history information is proposed. Finally, the simulation results show that our scheme can obtain significant performance gains over existing algorithms in both average flow completion time (AFCT) and saturation throughput. In particular, under the adversarial traffic pattern, our scheme can greatly reduce the AFCT of flow-level UGAL by 25% and improve the saturation throughput by 13% while avoiding disorder.
Yuyan Wu, Runzhou Li, Peilin Hong
GLOBECOM3
2021 Resource Aware Routing for Service Function Chains in SDN and NFV-Enabled Network
abstract
Owing to the Network Function Virtualization (NFV) and Software-Defined Networks (SDN), Service Function Chain (SFC) has become a popular service in SDN and NFV-enabled network. However, as the Virtual Network Function (VNF) of each type is generally multi-instance and flows with SFC requests must traverse a series of specified VNFs in predefined orders, it is a challenge for dynamic SFC formation to optimally select VNF instances and construct paths. Moreover, the load balancing and end-to-end delay need to be paid attention to, when routing flows with SFC requests. Additionally, fine-grained scheduling for traffic at flow level needs differentiated routing which should take flow features into consideration. Unfortunately, traditional algorithms cannot fulfill all these requirements. In this paper, we study the Differentiated Routing Problem considering SFC (DRP-SFC) in SDN and NFV-enabled network. We formulate the DRP-SFC as a Binary Integer Programming (BIP) model aiming to minimize the resource consumption costs of flows with SFC requests. Then a novel routing algorithm, Resource Aware Routing Algorithm (RA-RA), is proposed to solve the DRP-SFC. Performance evaluation shows that RA-RA can efficiently solve the DRP-SFC and surpass the performance of other existing algorithms in acceptance rate, throughput, hop count and load balancing.
Jianing Pei, Peilin Hong, Kaiping Xue, Defang Li
IEEE Trans. Serv. Comput.2
2020 Optimal VNF Placement via Deep Reinforcement Learning in SDN/NFV-Enabled Networks
abstract
The emerging paradigm - Software-Defined Networking (SDN) and Network Function Virtualization (NFV) - makes it feasible and scalable to run Virtual Network Functions (VNFs) in commercial-off-the-shelf devices, which provides a variety of network services with reduced cost. Benefitting from centralized network management, lots of information about network devices, traffic and resources can be collected in SDN/NFV-enabled networks. Using powerful machine learning tools, algorithms can be designed in a customized way according to the collected information to efficiently optimize network performance. In this paper, we study the VNF placement problem in SDN/NFV-enabled networks, which is naturally formulated as a Binary Integer Programming (BIP) problem. Using deep reinforcement learning, we propose a Double Deep Q Network-based VNF Placement Algorithm (DDQN-VNFPA). Specifically, DDQN determines the optimal solution from a prohibitively large solution space and DDQN-VNFPA then places/releases VNF Instances (VNFIs) following a threshold-based policy. We evaluate DDQN-VNFPA with trace-driven simulations on a real-world network topology. Evaluation results show that DDQN-VNFPA can get improved network performance in terms of the reject number and reject ratio of Service Function Chain Requests (SFCRs), throughput, end-to-end delay, VNFI running time and load balancing compared with the algorithms in existing literatures.
Jianing Pei, Peilin Hong, Miao Pan, Jianqing Liu, Jingsong Zhou
IEEE J. Sel. Areas Commun.2
2020 Two-Phase Virtual Network Function Selection and Chaining Algorithm Based on Deep Learning in SDN/NFV-Enabled Networks
abstract
With the advances of Software-Defined Networks (SDN) and Network Function Virtualization (NFV), Service Function Chain (SFC) has been becoming a popular paradigm to carry and complete network services. Such new computing and networking paradigm enables Virtual Network Functions (VNFs) to be placed in software entities/virtual machines over a network of physical equipments in elastic and flexible way with low capital and operation expenses. VNFs are chained together to steer traffic as needed. However, most of the existing traffic steering and routing path computation algorithms for SFC are complex, unscalable, and low time-efficiency. In this paper, we study the VNF Selection and Chaining Problem (VNF-SCP) in SDN/NFV-enabled networks. We formulate VNF-SCP as a Binary Integer Programming (BIP) model in order to compute routing path for each SFC Request (SFCR) with the minimum end-to-end delay. Then, a novel Deep Learning-based Two-Phase Algorithm (DL-TPA) is introduced, where VNF selection network and VNF chaining network are designed to achieve intelligent and efficient VNF selection and chaining for SFCRs. Performance evaluation shows that DL-TPA can achieve high prediction accuracy and time efficiency of routing path computation, and the overall network performance can be improved significantly.
Jianing Pei, Peilin Hong, Kaiping Xue, Defang Li, David S. L. Wei, Feng Wu 0001
IEEE J. Sel. Areas Commun.2
2020 Service Outsourcing in F2C Architecture with Attribute-based Anonymous Access Control and Bounded Service Number
abstract
F2C (fog-to-cloud) enables service providers to rent the low-cost cloud/fog resources to publish their services, and the fog nodes, which are deployed at the edge, can provide short-latency service to users. However, new security threats come along with this new computing paradigm, where the access control and trusted payment are concerned in this work. We propose a privacy-preserving authentication scheme. By integrating k-times anonymous authentication (k-TAA) and attribute-based access control, in our proposed scheme, service providers can autonomously determine a fine-grained access policy and the maximal access times for authorized users. Thus, users who satisfy the access policy can receive benefits of this service for certain number of times without leaking any private information. Our authentication phase has a low latency because it is offloaded to the fog as what the service does. This paper presents a lightweight and trusted billing mechanism using Merkle Hash Tree (MHT), which can detect the cloud's service forgery with high probability, without costing too much of service provider's bandwidth and computation. Rigorous security analysis proves that the proposed scheme is secure against malicious users, fogs, and cloud, and the experimental results show the significant performance advantage on both the delay reduction and service providers' cost saving.
Jianan Hong, Kaiping Xue, Na Gai, David S. L. Wei, Peilin Hong
IEEE Trans. Dependable Secur. Comput.5
2020 SecGrid: A Secure and Efficient SGX-Enabled Smart Grid System With Rich Functionalities
abstract
Smart grid adopts two-way communication and rich functionalities to gain a positive impact on the sustainability and efficiency of power usage, but on the other hand, also poses serious challenges to customers' privacy. Existing solutions in smart grid usually use cryptographic tools, such as homomorphic encryption, to protect individual privacy, which, however, can only support limited and simple functionalities. Moreover, the resource-constrained smart meters need to perform heavy asymmetric cryptography in these solutions, and thus unnecessarily increases load on smart grid. In this paper, we present a practical and secure SGX-enabled smart grid system, named SecGrid. Our system leverages trusted hardware SGX to ensure that grid utilities can efficiently execute rich functionalities on customers' private data, while guaranteeing their privacy. With our well-devised security protocols in SecGrid, only the smart meters need to perform AES encryption. To validate the superiority of our design, we conduct security analysis and experimentation. Security analysis shows that SecGrid can thwart various attacks from malicious adversaries, and the experimental results show that SecGrid is much faster than the existing privacy-preserving schemes in smart grid.
Shaohua Li 0002, Kaiping Xue, David S. L. Wei, Hao Yue 0001, Nenghai Yu, Peilin Hong
IEEE Trans. Inf. Forensics Secur.6
2020 Shared Bottleneck-Based Congestion Control and Packet Scheduling for Multipath TCP
abstract
In order to be TCP-friendly, the original Multipath TCP (MPTCP) congestion control algorithm is always restricted to gain no better throughput than a traditional single-path TCP on the best path. However, it is unable to maximize the throughput over all available paths when they do not go through a shared bottleneck. Also, bottleneck fairness based solutions detect the bottleneck and conduct different congestion control algorithms at different bottleneck sets to increase throughput while remaining fair to single TCP. However, existing solutions generally detect shared bottlenecks through delay correlation and loss correlation between two flows, which often lead to misjudgement in dynamic and complex network scenarios. Therefore, in this paper, we first propose a new Shared Bottleneck based Congestion Control scheme, called SB-CC, which leverages ECN (Explicit Congestion Notification) mechanism to detect shared bottlenecks among subflows and estimate the congestion degree of each subflow. Then, with the congestion degree, SB-CC balances the loads among all subflows, and smooths out congestion window fluctuation. Also, in order to prevent throughput degradation due to out-of-order packets, we propose a Shared Bottleneck based Forward Prediction packet Scheduling scheme, called SB-FPS. SB-FPS distributes data according to the window size changes of each subflow, and thus could more accurately schedule data in shared bottleneck scenarios. We implement our proposed scheme in the Linux kernel and simulation platform to evaluate the performance in different scenarios. Measurement results indicate that our scheme can detect the bottleneck more accurately and improve the overall network performance while still keeping bottleneck fairness.
Wenjia Wei, Kaiping Xue, Jiangping Han, David S. L. Wei, Peilin Hong
IEEE/ACM Trans. Netw.5
2020 TAFC: Time and Attribute Factors Combined Access Control for Time-Sensitive Data in Public Cloud
abstract
The new paradigm of outsourcing data to the cloud is a double-edged sword. On the one hand, it frees data owners from the technical management, and is easier for data owners to share their data with intended users. On the other hand, it poses new challenges on privacy and security protection. To protect data confidentiality against the honest-but-curious cloud service provider, numerous works have been proposed to support fine-grained data access control. However, till now, no schemes can support both fine-grained access control and time-sensitive data publishing. In this paper, by embedding timed-release encryption into Ciphertext-Policy Attribute-based Encryption (CP-ABE), we propose a new time and attribute factors combined access control on time-sensitive data for public cloud storage (named TAFC). Based on the proposed scheme, we further propose an efficient approach to design access policies faced with diverse access requirements for time-sensitive data. Extensive security and performance analysis shows that our proposed scheme is highly efficient and satisfies the security requirements for time-sensitive data storage in public cloud.
Jianan Hong, Kaiping Xue, Yingjie Xue, Weikeng Chen, David S. L. Wei, Nenghai Yu, Peilin Hong
IEEE Trans. Serv. Comput.7
2019 Cost-Efficient Virtual Network Function Placement and Traffic Steering
abstract
Benefiting from Network Function Virtualization (NFV), Service Function Chain (SFC) that is composed of a set of ordered Virtual Network Functions (VNFs) has become a popular network service pattern. One of the most important issues for Internet Service Providers (ISPs) is to determine the optimal placement of VNFs and the traffic steering of SFC to optimize the total network cost while guaranteeing resource constraints. In this paper, we study the cost-efficient VNF Placement and Traffic Steering (VNFP-TS) problem. First, we formulate the problem as a Binary Integer Programming (BIP) model aiming to minimize the node running cost, VNF placement cost and communication cost jointly. Then a heuristic Dynamic Programming based Cost Optimization Algorithm (DP-COA) is proposed to divide and conquer the problem. Finally, we evaluate the proposed algorithm by numerical simulations and confirm that DP-COA can achieve high network performance in terms of acceptance rate of SFC Requests (SFCRs) and throughput, and efficiently reduce the total network cost comparing with algorithms in existing literatures.
Jianing Pei, Peilin Hong, Defang Li
ICC3
2019 Energy Harvesting-Based D2D Relaying Achieving Energy Cooperation Underlaying Cellular Networks
abstract
Energy Harvesting (EH)-based cellular communication has emerged for the merit of simple deployment and continuous energy supply recently. However, the amounts of harvested energy are not always enough to meet the communication requirements of cellular devices. In this paper, we propose an energy cooperation scheme taking advantage of Device-to-Device (D2D) relaying technology, in which those devices with insufficient energy are aided by others to accomplish data transmission. In this scheme, we study the energy efficiency optimization problem, which involves the D2D relay selection, spectrum reusing and power allocation issues. Mathematically, it is formulated as a Mixed-Integer Nonlinear Programming (MINLP) problem, which turns out to be NP-hard. Thus we make a detailed mathematical analysis to the problem and introduce a two-layer optimization algorithm, and based on which, a suboptimal solution with lower computational complexity is then proposed. The simulation results show that the schemes are valid and can achieve significant improvement in system transmission rate and the satisfaction rate of users' communication requirements.
Runzhou Li, Peilin Hong, Defang Li, Jianing Pei
ICC2
2019 Multi-Task Deep Learning Based Dynamic Service Function Chains Routing in SDN/NFV-Enabled Networks
abstract
With the development of Software-Defined Networks (SDNs) and Network Function Virtualization (NFV), Service Function Chains (SFCs), that steer the traffic through a series of specified Virtual Network Functions (VNFs) with predefined orders, has become a popular network service paradigm. Compared with the rule-based routing algorithms, deep-learning technology has great potential to achieve efficient path computation for SFC Requests (SFCRs) in an intelligent way. However, traditional intelligent models have trouble in the speed of convergence, which incurs long training time and high computation consumptions. In this paper, we propose a novel Multi-Task Deep Learning (MTDL) based architecture, which improve generalization by sharing related information of tasks, to assure fast convergence in training process, and an MTDL-based Routing Algorithm (MTDL-RA) to efficiently compute routing paths with the minimum end-to-end delay for SFCRs. Performance evaluation results demonstrate that our proposed MTDL-based architechture and routing algorithm can achieve significantly reduction in the training time and obtain high performance in terms of SFCR acceptance rate and the delay of paths, respectively.
Jingsong Zhou, Peilin Hong, Jianing Pei
ICC2
2019 Virtual network function placement and resource optimization in NFV and edge computing enabled networks
Defang Li, Peilin Hong, Kaiping Xue, Jianing Pei
Comput. Networks2
2019 Healthchain: A Blockchain-Based Privacy Preserving Scheme for Large-Scale Health Data
abstract
With the dramatically increasing deployment of the Internet of Things (IoT), remote monitoring of health data to achieve intelligent healthcare has received great attention recently. However, due to the limited computing power and storage capacity of IoT devices, users' health data are generally stored in a centralized third party, such as the hospital database or cloud, and make users lose control of their health data, which can easily result in privacy leakage and single-point bottleneck. In this paper, we propose Healthchain, a large-scale health data privacy preserving scheme based on blockchain technology, where health data are encrypted to conduct fine-grained access control. Specifically, users can effectively revoke or add authorized doctors by leveraging user transactions for key management. Furthermore, by introducing Healthchain, both IoT data and doctor diagnosis cannot be deleted or tampered with so as to avoid medical disputes. Security analysis and experimental results show that the proposed Healthchain is applicable for smart healthcare system.
Jie Xu 0031, Kaiping Xue, Shaohua Li 0002, Hangyu Tian, Jianan Hong, Peilin Hong, Nenghai Yu
IEEE Internet Things J.6
2019 PPSO: A Privacy-Preserving Service Outsourcing Scheme for Real-Time Pricing Demand Response in Smart Grid
abstract
In power utility service outsourcing, some time-sensitive computations (e.g., dynamic prices prediction) are outsourced to a third-party service provider. This brings in new privacy threats to customers. Although some existing works focus on achieving privacy-preserving temporal and spatial aggregation for one center, they basically cannot be directly applied to the scenario of service outsourcing with multiple centers (e.g., with power utility and service providers). We thus propose a privacy-preserving service outsourcing scheme, called PPSO, for real-time pricing demand response in smart grid with fault tolerance and flexible customers' enrollment and revocation. In our proposed PPSO, power utility can outsource the dynamic pricing prediction to a service provider, while still preserving customers' privacy. Extensive experiment results demonstrate that PPSO has less computation overhead and lower transmission delay compared with existing schemes.
Kaiping Xue, Qingyou Yang, Shaohua Li 0002, David S. L. Wei, Min Peng 0001, Imran Memon, Peilin Hong
IEEE Internet Things J.7
2019 An Attribute-Based Controlled Collaborative Access Control Scheme for Public Cloud Storage
abstract
In public cloud storage services, data are outsourced to semi-trusted cloud servers which are outside of data owners' trusted domain. To prevent untrustworthy service providers from accessing data owners' sensitive data, outsourced data are often encrypted. In this scenario, conducting access control over these data becomes a challenging issue. Attribute-based encryption (ABE) has been proved to be a powerful cryptographic tool to express access policies over attributes, which can provide a fine-grained, flexible, and secure access control over outsourced data. However, the existing ABE-based access control schemes do not support users to gain access permission by collaboration. In this paper, we explore a special attribute-based access control scenario where multiple users having different attribute sets can collaborate to gain access permission if the data owner allows their collaboration in the access policy. Meanwhile, the collaboration that is not designated in the access policy should be regarded as a collusion and the access request will be denied. We propose an attribute-based controlled collaborative access control scheme through designating translation nodes in the access structure. Security analysis shows that our proposed scheme can guarantee data confidentiality and has many other critical security properties. Extensive performance analysis shows that our proposed scheme is efficient in terms of storage and computation overhead.
Yingjie Xue, Kaiping Xue, Na Gai, Jianan Hong, David S. L. Wei, Peilin Hong
IEEE Trans. Inf. Forensics Secur.6
2019 Availability Aware VNF Deployment in Datacenter Through Shared Redundancy and Multi-Tenancy
abstract
By means of network function virtualization (NFV), dedicated proprietary network devices can be implemented as software and instantiated flexibly on common-off-the-shelf servers, in the form of virtual network functions (VNF). NFV can bring great cost reduction as well as operation flexibility. However, it also brings new problems, one of which is how to meet the availability of network services in the VNF deployment process, because of the error prone nature of software. The availability aware VNF deployment problem has attracted attention by academics, and reserving redundancy has been treated as the de facto technology. Compared with traditional backup schemes for physical machines, resource orchestration in NFV is more flexible and the characteristics of software should be considered to improve resource utilization efficiency. Based on the above considerations, in this paper we further study the availability aware VNF deployment problem in datacenter networks. To improve the resource utilization efficiency, the sharing mechanism of redundancy and multi-tenancy technology are taken into account. Then we formulate the problem mathematically and propose a joint deployment and backup scheme (JDBS). Finally, we conduct a numerical simulation in detail and compare it with four contrasting schemes in the existing literature. The simulation results show that JDBS is obviously superior to the contrasting schemes and can save about 40% resources at most.
Defang Li, Peilin Hong, Kaiping Xue, Jianing Pei
IEEE Trans. Netw. Serv. Manag.2
2019 Efficiently Embedding Service Function Chains with Dynamic Virtual Network Function Placement in Geo-Distributed Cloud System
abstract
Network Function Virtualization (NFV) and Software-Defined Networks (SDN) enable Internet Service Providers (ISPs) to place Virtual Network Functions (VNFs) to achieve the performance and security benefit without incurring high Operating Expenses (OPEX) and Capital Expenses (CAPEX). In NFV environment, Service Function Chains (SFCs) always need to steer the traffic through a series of VNF instances in predefined orders. Moreover, the required number and placement of VNF instances should be optimized to adapt to dynamic network load. Therefore, it is considerable for ISPs to conduct an optimal SFC embedding strategy to improve the network performance and revenue. In the paper, we study the SFC Embedding Problem (SFC-EP) with dynamic VNF placement in geo-distributed cloud system. We formulate this problem as a Binary Integer Programming (BIP) model aiming to embed SFC requests with the minimum embedding cost. Furthermore, the novel SFC eMbedding APproach (SFC-MAP) and VNF Dynamic Release Algorithm (VNF-DRA) have been proposed to efficiently embed SFC requests and optimize the number of placed VNF instances. Performance evaluation results show that the proposed algorithms can provide higher performance in terms of SFC request acceptance rate, network throughput, and mean VNF utilization rate and efficiently reduce the total VNF running time compared with the algorithms in existing literatures.
Jianing Pei, Peilin Hong, Kaiping Xue, Defang Li
IEEE Trans. Parallel Distributed Syst.2
2018 Combining Data Owner-Side and Cloud-Side Access Control for Encrypted Cloud Storage
abstract
People endorse the great power of cloud computing, but cannot fully trust the cloud providers to host privacy-sensitive data, due to the absence of user-to-cloud controllability. To ensure confidentiality, data owners outsource encrypted data instead of plaintexts. To share the encrypted files with other users, ciphertext-policy attribute-based encryption (CP-ABE) can be utilized to conduct fine-grained and owner-centric access control. But this does not sufficiently become secure against other attacks. Many previous schemes did not grant the cloud provider the capability to verify whether a downloader can decrypt. Therefore, these files should be available to everyone accessible to the cloud storage. A malicious attacker can download thousands of files to launch economic denial of sustainability (EDoS) attacks, which will largely consume the cloud resource. The payer of the cloud service bears the expense. Besides, the cloud provider serves both as the accountant and the payee of resource consumption fee, lacking the transparency to data owners. These concerns should be resolved in real-world public cloud storage. In this paper, we propose a solution to secure encrypted cloud storages from EDoS attacks and provide resource consumption accountability. It uses CP-ABE schemes in a black-box manner and complies with arbitrary access policy of the CP-ABE. We present two protocols for different settings, followed by performance and security analysis.
Kaiping Xue, Weikeng Chen, Jianan Hong, Peilin Hong
IEEE Trans. Inf. Forensics Secur.5
2018 PPMA: Privacy-Preserving Multisubset Data Aggregation in Smart Grid
abstract
Privacy-preserving data aggregation has been extensively studied in smart grid. However, almost all existing schemes aggregate the total electricity consumption data of the whole user set, which sometimes cannot meet the fine-grained demands from control center in smart grid. In this paper, we propose a privacy-preserving multisubset data aggregation scheme, named PPMA, in smart grid. PPMA can aggregate users' electricity consumption data of different ranges, while guaranteeing the privacy of individual users. Detailed security analysis shows that PPMA can protect individual user's electricity consumption privacy against a strong adversary. In addition, extensive experiments results demonstrate that PPMA has less computation overhead and no more extra communication and storage costs.
Shaohua Li 0002, Kaiping Xue, Qingyou Yang, Peilin Hong
IEEE Trans. Ind. Informatics4
2018 Virtual Network Function Placement Considering Resource Optimization and SFC Requests in Cloud Datacenter
abstract
Network function virtualization (NFV) brings great conveniences and benefits for the enterprises to outsource their network functions to the cloud datacenter. In this paper, we address the virtual network function (VNF) placement problem in cloud datacenter considering users' service function chain requests (SFCRs). To optimize the resource utilization, we take two less-considered factors into consideration, which are the time-varying workloads, and the basic resource consumptions (BRCs) when instantiating VNFs in physical machines (PMs). Then the VNF placement problem is formulated as an integer linear programming (ILP) model with the aim of minimizing the number of used PMs. Afterwards, a Two-StAge heurisTic solution (T-SAT) is designed to solve the ILP. T-SAT consists of a correlation-based greedy algorithm for SFCR mapping (first stage) and a further adjustment algorithm for virtual network function requests (VNFRs) in each SFCR (second stage). Finally, we evaluate T-SAT with the artificial data we compose with Gaussian function and trace data derived from Google's datacenters. The simulation results demonstrate that the number of used PMs derived by T-SAT is near to the optimal results and much smaller than the benchmarks. Besides, it improves the network resource utilization significantly.
Defang Li, Peilin Hong, Kaiping Xue, Jianing Pei
IEEE Trans. Parallel Distributed Syst.2
2017 FADM: DDoS Flooding Attack Detection and Mitigation System in Software-Defined Networking
abstract
Distributed Denial-of-Service (DDoS) flooding attack is one of the most serious threats to network security. Software-Defined Networking (SDN) has recently emerged as a new network management platform, and its centralized control architecture brings many new opportunities for defending against network attacks. In this paper, we propose FADM, an efficient and lightweight framework to detect and mitigate DDoS attacks in SDN. Firstly, the network traffic information is collected through the SDN controller and sFlow agents. Then an entropy-based method is used to measure network features, and the SVM classifier is applied to identify network anomalies. By adopting these methods together, the timeliness and accuracy of attack detection are effectively improved. To keep the major network functionality working, we propose an efficient attack mitigation mechanism based on the white-list and traffic migration. By introducing the mitigation agent to the network, attack traffic can be timely blocked while benign traffic can be forwarded as usual, which prevents the controller resources from being exhausted and ensures that legitimate users can access the network normally. The experimental results show that multiple DDoS attacks can be accurately detected and effectively mitigated by FADM, which enables the network to recover in a short time.
Dingwen Hu, Peilin Hong
GLOBECOM2
2017 Energy-Efficient Scheduling and Power Allocation for Energy Harvesting-Based D2D Communication
abstract
Energy Harvesting (EH)-based Device-to-Device (D2D) communication brings some challenges in resources management due to the joint influence of the volatility of available energy and the interference between cellular and D2D users. In this paper, we focus on improving the energy efficiency of EH-based D2D communication for the scenario where multiple EH- based D2D communication links multiplex the uplink channel resource of one cellular user (CU). Considering the variation of transmission requests based on available energy in different time slots, a short-term sum energy efficiency maximization problem for EH-based D2D communication is formulated to integrate the transmission scheduling and power allocation while maintaining a given transmission rate requirement for both CU and D2D links. The modeled problem is a non-convex mixed integer non- linear programming (MINLP) problem. In view of the NP-hardness property of the optimization problem, we develop a two-layer convex approximation iteration algorithm (CAIA) to obtain a feasible suboptimal solution. Finally, numerical simulation results indicate the performance of CAIA in aspects of average energy efficiency and transmission rate of D2D communication.
Ying Luo 0002, Peilin Hong, Ruolin Su
GLOBECOM2
2017 Coupled Slow-Start: Improving the Efficiency and Friendliness of MPTCP's Slow-Start
abstract
Multipath TCP (MPTCP) is designed to offer higher throughput than single-path TCP, and meanwhile MPTCP flow is fair to concurrent TCP flows at the bottleneck. Although the coupled congestion control in current MPTCP can achieve the goals by coupling different subflows, it only focuses on Congestion Avoidance but each subflow still behaves like an independent TCP flow in Slow-Start. However, during Slow-Start, MPTCP is unfair to concurrent TCP flows as it uses more network resources at the shared bottleneck than single-path TCP. Worse still, since the exponential growth of multiple concurrent subflows' congestion windows often results in serious buffer overflow and packet loss at the shared bottleneck, the latency of short flows using MPTCP is often not as good as using TCP. This leads to the fact that MPTCP cannot satisfy the above design goals when handling short flows. To address this issue, we present a Coupled Slow-Start (CSS) Algorithm in this paper. CSS links the exponential growth of subflows' congestion windows to ensure the fairness and reduce the burstiness of Slow- Start. To reduce the packet loss, CSS resets the Slow-Start Threshold (ssthresh) of different subflows for MPTCP to safely move to Congestion Avoidance when it achieves its expected throughput. Our simulation shows that CSS can lower short flows' latency of up to 45% and significantly reduce the packet loss in two typical network environments, meanwhile CSS is TCP-friendly at the shared bottleneck. Simulation results also indicate that CSS can perform at least as well as original MPTCP for the bulk data transfer in common network environments.
Yansen Wang, Kaiping Xue, Hao Yue 0001, Jiangping Han, Peilin Hong
GLOBECOM6
2017 Receive Buffer Pre-division Based Flow Control for MPTCP
Jiangping Han, Kaiping Xue, Hao Yue 0001, Peilin Hong, Nenghai Yu, Fenghua Li 0001
MSN4
2017 CABE: A New Comparable Attribute-Based Encryption Construction with 0-Encoding and 1-Encoding
abstract
Attribute-based encryption (ABE) has opened up a popular research topic in cryptography over the past few years. It can be used in various circumstances, as it provides a flexible way to conduct fine-grained data access control. Despite its great advantages in data access control, current ABE based access control system cannot satisfy the requirement well when the system judges the access behavior according to attribute comparison, such as “greater than x” or “less than x”, which are called comparable attributes in this paper. In this paper, based on a set of well-designed sub-attributes representing each comparable attribute, we construct a comparable attribute-based encryption scheme (CABE for short) to address the aforementioned problem. The novelty lies in that we provide a more efficient construction based on the generation and management of the sub-attributes with the notion of 0-encoding and 1-encoding. Extensive analysis shows that: Compared with the existing schemes, our scheme drastically decreases the storage, communication and computation overheads, and thus is more efficient in dealing with the applications with comparable attributes.
Kaiping Xue, Jianan Hong, Yingjie Xue, David S. L. Wei, Nenghai Yu, Peilin Hong
IEEE Trans. Computers6
2017 Two-Cloud Secure Database for Numeric-Related SQL Range Queries With Privacy Preserving
abstract
Industries and individuals outsource database to realize convenient and low-cost applications and services. In order to provide sufficient functionality for SQL queries, many secure database schemes have been proposed. However, such schemes are vulnerable to privacy leakage to cloud server. The main reason is that database is hosted and processed in cloud server, which is beyond the control of data owners. For the numerical range query (“>,” “<;,” and so on), those schemes cannot provide sufficient privacy protection against practical challenges, e.g., privacy leakage of statistical properties, access pattern. Furthermore, increased number of queries will inevitably leak more information to the cloud server. In this paper, we propose a two-cloud architecture for secure database, with a series of intersection protocols that provide privacy preservation to various numeric-related range queries. Security analysis shows that privacy of numerical information is strongly protected against cloud providers in our proposed scheme.
Kaiping Xue, Shaohua Li 0002, Jianan Hong, Yingjie Xue, Nenghai Yu, Peilin Hong
IEEE Trans. Inf. Forensics Secur.6
2017 RAAC: Robust and Auditable Access Control With Multiple Attribute Authorities for Public Cloud Storage
abstract
Data access control is a challenging issue in public cloud storage systems. Ciphertext-policy attribute-based encryption (CP-ABE) has been adopted as a promising technique to provide flexible, fine-grained, and secure data access control for cloud storage with honest-but-curious cloud servers. However, in the existing CP-ABE schemes, the single attribute authority must execute the time-consuming user legitimacy verification and secret key distribution, and hence, it results in a single-point performance bottleneck when a CP-ABE scheme is adopted in a large-scale cloud storage system. Users may be stuck in the waiting queue for a long period to obtain their secret keys, thereby resulting in low efficiency of the system. Although multi-authority access control schemes have been proposed, these schemes still cannot overcome the drawbacks of single-point bottleneck and low efficiency, due to the fact that each of the authorities still independently manages a disjoint attribute set. In this paper, we propose a novel heterogeneous framework to remove the problem of single-point performance bottleneck and provide a more efficient access control scheme with an auditing mechanism. Our framework employs multiple attribute authorities to share the load of user legitimacy verification. Meanwhile, in our scheme, a central authority is introduced to generate secret keys for legitimacy verified users. Unlike other multi-authority access control schemes, each of the authorities in our scheme manages the whole attribute set individually. To enhance security, we also propose an auditing mechanism to detect which attribute authority has incorrectly or maliciously performed the legitimacy verification procedure. Analysis shows that our system not only guarantees the security requirements but also makes great performance improvement on key generation.
Kaiping Xue, Yingjie Xue, Jianan Hong, Hao Yue 0001, David S. L. Wei, Peilin Hong
IEEE Trans. Inf. Forensics Secur.7
2016 A Two-Layer Caching Model for Content Delivery Services in Satellite-Terrestrial Networks
abstract
With the development of satellite communication technologies and user requirements for pervasive network access, there is a trend to integrate satellites into the terrestrial network infrastructure. Such kind of satellite-terrestrial network is often used for content delivery services as satellites are with wide-area coverage. In terrestrial networks such as Internet, in-network caching has been proved to be an effective method to improve the network performance in terms of throughput and delay. Based on this observation, we involve caches in the satellite-terrestrial networks. Particularly, a two-layer caching model is proposed for content delivery, where caches placed in the ground stations constitute the first caching layer and caches deployed in the satellite forms the second one. On the satellite, to make full use of the broadcast advantage, we set a window to aggregate the requests for the same files from ground stations. These requests will be served by one satellite broadcasting when the aggregation window expires. Our goal is to minimize the downlink and uplink satellite bandwidth consumption, which requires joint caching optimization between the satellite and ground stations. We formulate the joint caching optimization problem as a nonlinear integer programming problem. Furthermore, a caching strategy based on the genetic algorithm is proposed to solve the problem efficiently. The simulation results show that the proposed caching strategy significantly outperforms content popularity based and random caching strategies in terms of satellite bandwidth consumption.
Hao Wu 0042, Jian Li 0031, Hancheng Lu, Peilin Hong
GLOBECOM4
2016 LABAC: A Location-Aware Attribute-Based Access Control Scheme for Cloud Storage
abstract
Data access control is a challenging issue in cloud storage. Ciphertext-Policy Attribute-based Encryption (CP-ABE) is a potential cryptographic technique to address the above issue, which is able to enforce data access control based on users' permanent characteristics. However, in some scenarios, access policies are associated with users' temporary conditions (such as access time and location) as well as their permanent ones. CP-ABE cannot deal with such situations commendably. In this paper, we focus on the scenario where users' access privilege is determined by their attributes, together with their locations. To cope with this data access control requirement, we propose a location-aware attribute-based access control mechanism (LABAC) for cloud. In LABAC, we uniquely integrate CP-ABE with location trapdoors to make up access policies. In this way, data owners can flexibly combine both users' attributes and locations to implement a fine-grained control of their data. A competitive advantage of LABAC is that it requires no any additional revocation mechanisms to revoke location-aware access privilege when user location changes. Security and performance analysis are presented which show the security and efficiency of LABAC for practical implementations.
Yingjie Xue, Jianan Hong, Kaiping Xue, Peilin Hong
GLOBECOM5
2016 Energy-Aware Service Function Placement for Service Function Chaining in Data Centers
abstract
Nowadays, data centers deploy a large number of servers and network devices to provide various service functions (e.g. firewalls, deep packet inspection, content caches, WAN optimizers, etc.) and sufficient network connection. Most traffic in data centers is subject to treatment by multiple service functions (SFs) which form an ordered service function chain (SFC). In this paper, we study the energy-aware service function placement problem for SFC in data centers. By considering the computing, bandwidth resources constrains and the power models both in servers and switches, a new service function placement algorithm Merge-RD is proposed to save the energy consumption in data centers. The simulation results indicate that the Merge-RD can effectively reduce the energy consumption and average transmission delay in data center compared with some existing service function placement algorithms while guaranteeing the packet delivery ratio at a high level.
Peilin Hong
GLOBECOM3
2015 RPA-RA: A Resource Preference Aware Routing Algorithm in Software Defined Network
abstract
In Software Defined Network(SDN), every switch contains multiple flow tables, each flow table containing multiple flow entries. The number of flow entries determines the number of flows that can be forwarded by the switch. Link resources(like bandwidth) is no longer the only one to be considered when routing because node resources(like flow table) may also cause network bottlenecks. Moreover, from a view of network traffic, different flows have different preference to these network resources. In this paper, we use Analytic Hierarchy Process to analysis the characteristics of network traffic, then based on K-shortest path algorithm, a novel Resource Preference Aware Routing Algorithm, simplified as RPA-RA, is proposed. RPA-RA selects the most proper path for a flow from k shortest paths by considering the resource preference of the flows. The aim is to balance the usage of link bandwidth and the flow table simultaneously when routing, so that the network can accept and process more flows. At last, our algorithm is validated with POX and Mininet. The simulation results show that RPA- RA can balance the usage of the flow table and bandwidth, result in fewer resource bottlenecks, and make the network accept more flows relatively.
Defang Lee, Peilin Hong, Jianfei Li
GLOBECOM2
2015 OCPS: Offset Compensation based Packet Scheduling mechanism for multipath TCP
abstract
As terminals are equipped with multiple interfaces and allowed to access heterogeneous networks, transferring data simultaneously through all the available paths becomes possible and also brings many benefits. Multipath TCP (MPTCP) distributes an application stream over different TCP connections. Since different paths have disparate latencies, out-of-order packets problem occurs at receiver. Large number of these packets exhaust the limited receive buffer and make the receive window stall, which greatly degrade the throughput. Thus, a scheduling mechanism plays an important role to keep in-order delivery. Previous intelligent scheduling mechanisms schedule data independently each time and doesn't utilize the feedback carried in acknowledgements, which lose flexibility. Our Offset Compensation based Packet Scheduling (OCPS) mechanism gets feedback information from SACK options and gains the knowledge of whether last scheduling round still causes out-of-order problem. Then it modifies the scheduling next round accordingly by using an offset. The simulation results illustrate our mechanism enhance throughput and reduce cache occupancy at receiver.
Dan Ni, Kaiping Xue, Peilin Hong, Hao Lu 0008
ICC3
2015 Uplink traffic cellular-first access scheme in cellular/WLAN integrated networks
abstract
In cellular/WLAN integrated networks, WLAN APs are usually deployed to offload the heavy traffic of cellular networks. Due to the inherent asymmetry of downlink and uplink in WLAN, competitions increase rapidly along with uplink traffic being offloaded to WLAN, which degrades system performance significantly. In this paper, we propose a new access scheme, i.e. uplink traffic cellular-first access (UTCFA) scheme. By offloading uplink traffic within WLAN coverage to contention-free cellular networks as much as possible, UTCFA scheme improves WLAN channel utilization significantly. We derive the throughput produced by UTCFA by theoretical analysis and perform extensive simulations to validate these theoretical results. Particularly, we find that the well-known WLAN-first access scheme is a special case of the proposed scheme. The simulation results also show that UTCFA can significantly improve the system performance and provide better support for quality of service guaranteed services.
Peilin Hong, Hancheng Lu
WCNC2
2015 Optimal power management under delay constraint in cellular networks with hybrid energy sources
Jinlin Peng, Peilin Hong, Kaiping Xue
Comput. Networks2
2015 Energy-Aware Cellular Deployment Strategy Under Coverage Performance Constraints
abstract
The last ten years have witnessed explosive growth in mobile data traffic, which leads to rapid increases in energy consumption of cellular networks. One potential solution to this issue is to seek out a green deployment strategy. In this paper, we investigate the energy-efficient deployment strategy under coverage performance constraints for both homogeneous and heterogeneous cellular networks. Unlike just considering the base station (BS) density in previous work, we jointly optimize the BS density and the BS transmission power. First, we derive the relation between the average coverage probability and deployment strategy (i.e., BS density and BS transmission power) with stochastic geometry tools. Then, based on the expression results, we formulate a network energy consumption minimization framework considering coverage performance constraints and jointly determine the optimal macro BS (MaBS) density, MaBS transmission power, and micro BS (MiBS) density. With practical data sets, numerical simulation results show the following: 1) compared with homogeneous network deployment, heterogeneous network deployment has the advantage in energy efficiency performance, and 2) our joint BS density and BS transmission power optimization strategy exceeds the existing strategy, which just considers the BS density optimization in terms of energy efficiency.
Jinlin Peng, Peilin Hong, Kaiping Xue
IEEE Trans. Wirel. Commun.2
2014 VNE-RFD: Virtual network embedding with resource fragmentation consideration
abstract
Virtual Network Embedding (VNE) is one of the critical techniques in network virtualization. In this paper, we attempt to improve the performance of VNE in terms of acceptance ratio of Virtual Network (VN) requests by considering resource fragmentation in a substrate network. Different from existing work, we involve a new metric called Resource Fragmentation Degree (RFD) to quantitatively measure the status of resource fragmentation at substrate nodes and links. The definition of RFD is derived from the conception of connectivity in graph theory. Actually, RFD of a node (or a link) is only determined by residual resources at its neighbor nodes and adjacent links. Thus it can be derived efficiently. For a node (or a link), maximum RFD is reached when either all of its neighbor nodes or all of its adjacent links are running out of resources. In this case, resources at the node (or the link) are entirely fragmented. With consideration of RFD, we then formulate the problem of VNE as a mixed integer program. The optimization objective includes minimizing fragmented resources indicated by RFD in the substrate network. Finally, an online algorithm called VNE-RFD is proposed to solve the problem. Simulation results show that VNE-RFD can effectively reduce resource fragmentation and thus accept more VN requests compared with some existing algorithms.
Hancheng Lu, Peilin Hong
GLOBECOM4
2014 Fine-grained Forward Prediction based Dynamic Packet Scheduling Mechanism for multipath TCP in lossy networks
abstract
Nowadays, multi-interface terminals in heterogeneous network may access Internet through various access technologies, and further aggregate network resources from multiple paths as much as possible. Multipath TCP exploits multiple paths simultaneously by stripping data of a connection over multiple TCP flows, each of which is through a disjoint path. However, it encounters the problem caused by the great number of out-of-order packets at receiver due to dissimilar path characteristics, i.e. latency, bandwidth, packet loss rate, etc. The previous intelligent scheduling mechanisms to keep in-order delivery all ignored packet losses and became fragile in lossy networks. In this paper, we present Fine-grained Forward Prediction based Dynamic Packet Scheduling Mechanism(F2P-DPS) for multipath TCP. It utilizes the idea of TCP modeling to estimate the latency on the path under scheduling and the data amount sent on the other paths simultaneously, which takes packet loss rate into consideration, and then decides which packets to send on the under-scheduling path. From the simulation, we can see that our mechanism obviously improves throughput and reduces cache occupancy at receiver in lossy networks.
Dan Ni, Kaiping Xue, Peilin Hong, Sean Shen
ICCCN3
2014 Evaluating the controller capacity in software defined networking
abstract
The flow-based OpenFlow architecture decouples the control plane and data plane, and it has involved great evolution towards traditional networks. A particular important issue in OpenFlow architecture is controller capacity, which can be defined as the number of switches a controller can manage. In this paper, we model the flow set-up requests from switches to controller as a batch arrival process Mk/M /1. Further, we analyze the controller performance with queuing theory, and derive the expression of average flow service time. Under the circumstance of a limited flow set-up time, the number of switches is determined, this provides a method to evaluate the controller capacity. Moreover, we extend the scene of a single controller to multiple controllers. All of these results are meaningful to large scale OpenFlow network deployment in the future.
Long Yao, Peilin Hong
ICCCN2
2014 Congestion exposure enabled TCP with network coding for hybrid wired-wireless network
abstract
TCP with network coding (TCP/NC) makes the packet loss, which is caused by wireless transmission error, have no effect on congestion control. Current proposals prefer to use delay-based congestion control aspect(congestion avoidance phase) of TCP Vegas to deal with the congestion problem of TCP/NC. However, it is oversimplified and may lead to unfairness when both TCP flow and TCP/NC flow coexist in the congested wired bottleneck link in hybrid wired-wireless network. In this paper, congestion exposure enabled TCP/NC, named CEE-TCP/NC, is proposed to make TCP/NC be friendlier to TCP protocols in the case of congestion. CEE-TCP/NC replaces TCP's loss-based congestion indicator with a method based on analyzing gaps in the ACK stream that arrive at the TCP sender. Further, different levels of congestion can be detected and actions against congestion are taken accordingly. By theoretic analysis and simulation, we show that the scheme not only inherits the advantage of network coding to eliminate the effect of wireless transmission error, but also avoids damaging the performance of other competing flows.
Kaiping Xue, Peilin Hong, Sean Shen
ICCCN3
2014 A lightweight dynamic pseudonym identity based authentication and key agreement protocol without verification tables for multi-server architecture
Kaiping Xue, Peilin Hong, Changsha Ma
J. Comput. Syst. Sci.2
2014 Distributed access control with adaptive privacy preserving property for wireless sensor networks
abstract
Access control plays an important role in protecting security-sensitive sensor data from being utilized by malicious users. Despite the numerous studies on access control for wireless sensor networks WSNs, however, few of them pay attention to preserving user privacy, which has recently been an urgent demand of the network users. In this paper, we propose two access control schemes with different privacy preserving properties for WSNs, which can adaptively satisfy the demands of the sensor network users. First, on the basis of our signcryption approach, we propose a distributed query protected access control scheme where the query message is encrypted in the process of user authentication. Because no other users could decrypt and read the query message, the user can preserve the privacy of the target data type. With the additional help with proxy signature, we then design a distributed anonymous access control scheme. Apart from protecting the data type information, distributed anonymous access control preserves the privacy of the user's access behavior by anonymizing the user's identity. In contrast to the previous privacy-preserved access control schemes for WSNs, our schemes can efficiently protect the privacy of users without significantly increasing the network overhead and the energy consumption on sensors. Copyright © 2013 John Wiley & Sons, Ltd.
Changsha Ma, Kaiping Xue, Peilin Hong
Secur. Commun. Networks3
2014 A Dynamic Secure Group Sharing Framework in Public Cloud Computing
abstract
With the popularity of group data sharing in public cloud computing, the privacy and security of group sharing data have become two major issues. The cloud provider cannot be treated as a trusted third party because of its semi-trust nature, and thus the traditional security models cannot be straightforwardly generalized into cloud based group sharing frameworks. In this paper, we propose a novel secure group sharing framework for public cloud, which can effectively take advantage of the cloud servers' help but have no sensitive data being exposed to attackers and the cloud provider. The framework combines proxy signature, enhanced TGDH and proxy re-encryption together into a protocol. By applying the proxy signature technique, the group leader can effectively grant the privilege of group management to one or more chosen group members. The enhanced TGDH scheme enables the group to negotiate and update the group key pairs with the help of cloud servers, which does not require all of the group members been online all the time. By adopting proxy re-encryption, most computationally intensive operations can be delegated to cloud servers without disclosing any private information. Extensive security and performance analysis shows that our proposed scheme is highly efficient and satisfies the security requirements for public cloud based secure group sharing.
Kaiping Xue, Peilin Hong
IEEE Trans. Cloud Comput.2
2013 Equiphase Precoder Design for Cooperative Communication with Complex Field Network Coding
abstract
Complex field network coding (CFNC) can be employed to achieve ideal throughput as high as 1/2 symbol per source per time slot (sym/S/TS) in relay-based cooperative communications. In this paper, equiphase precoder (EP) scheme for CFNC-based system (EP-CFNC) is proposed to achieve better symbol error probability (SEP) performance. The distribution of transmitted symbol's constellation is carefully designed against noise. The theoretical analysis provides a method to estimate the SEP and verifies the coding gain obtained by equiphase precoder. Moreover, simulation results, in both additive complex White Gaussian noise (AWGN) channels and Rayleigh fading channels, show that SEP can be substantially reduced via the proposed EP-CFNC algorithm.
Hao Lu 0008, Peilin Hong, Kaiping Xue
VTC Fall2
2013 A temporal-credential-based mutual authentication and key agreement scheme for wireless sensor networks
Kaiping Xue, Changsha Ma, Peilin Hong
J. Netw. Comput. Appl.3
2013 High-Throughput Cooperative Communication with Interference Cancellation for Two-Path Relay in Multi-Source System
abstract
Relay-based cooperative communication has become a research focus in recent years because it can achieve diversity gain in wireless networks. In existing works, network coding and the two-path relay scheme is exploited to deal with the increase in network size and the half-duplex nature of relay, respectively. To further improve bandwidth efficiency, we propose a novel cooperative transmission scheme which combines network coding and the two-path relay scheme together in the multi-source system. Due to the utilization of two-path relay, our proposed scheme achieves full-rate transmission. Adopting complex field network coding (CFNC) at both the sources and the relays ensures that symbols from different sources are allowed to be broadcasted in the same time slot. We also adopt physical-layer network coding (PNC) at the relay nodes to deal with the inter-relay interference caused by the two-path relay. With careful process design, our scheme can achieve the ideal throughput up to 1 symbol per source per time slot (sym/S/TS). Furthermore, the theoretical analysis provides a method to estimate the symbol error probability (SEP) and throughput in complex additive white Gaussian noise (AWGN) and Rayleigh fading channels. The simulation results verify the improvements achieved by the proposed scheme.
Hao Lu 0008, Peilin Hong, Kaiping Xue
IEEE Trans. Wirel. Commun.2
2012 A novel cluster-based channel assignment scheme for wireless mesh networks
abstract
Since multi-radio multi-channel wireless mesh networks are widely brought into use, the channel assignment scheme plays a critical role in determining the performance of wireless mesh networks. Nowadays many channel assignment schemes have been proposed to enhance the performance of the wireless networks. However, most of the existing schemes assume that all the interference links induce the same level of interference on the target link, which will lead to poor network performance as the assumption deviates from the actual situation. In this paper, we propose a novel clique-based clustering channel assignment (CCCA) scheme which takes different levels of interfering links into consideration. By locally calculating maximum cliques in the interfering graph, CCCA logically partitions the networks into clusters and executes channel assignment in three stages to minimize interference of links including both non-coordinated interference and coordinated interference. The simulation results demonstrate that CCCA can significantly increase the network throughput, improve the fairness of network capacity distribution and decrease the end-to-end delay, which enhances the performance of the wireless mesh networks effectively.
Kaiping Xue, Peilin Hong, Zhenguo Du
CCNC3
2012 Hierarchically modulated coded cooperation for relay system
abstract
Coded cooperation (CC) is an excellent scheme for cooperative communication. However, the throughput of CC is not high enough. In this paper, we propose a novel cooperative scheme called hierarchically modulated coded cooperation (HMCC). This scheme takes the frame group as the input instead of a single frame in CC and adopts hierarchical modulation in source node according to the asymmetry between the links of source-relay and source-destination, expecting that some frames can be received by destination node directly and others are forwarded by relay node. In HMCC, a higher order modulation can be used by source node. Theoretical analysis and simulation show that HMCC achieves a better performance on throughput compared to other schemes. On the other hand, HMCC distributes burst errors to the frame group owing to the hierarchical modulation, which suggests that HMCC is able to struggle against the burst errors.
Zhenguo Du, Peilin Hong, Kaiping Xue, Jinlin Peng
CCNC2
2012 Uplink performance of LTE-based multi-hop cellular network with out-of-band relaying
abstract
In this paper, we present a new architecture to mitigate inter-cell interference in the uplink and improve the uplink capacity of Long Term Evolution (LTE), which is named LTE-based multi-hop cellular networks with out-of-band relaying. Based on the receiving reference signal strength of User Equipments (UEs), each cell is divided into two parts, the inner circle and the outer ring. Each UE is dual-mode including an LTE air interface and an IEEE 802.11 air interface. An active UE in outer ring is free to choose an available idle UE in inner circle as a relay station (RS) within its IEEE 802.11 radio coverage area for dual-hop communication with the E-UTRAN NodeB (eNB). We analyze the probability of RS selection under this architecture. Then an analytic mode is used to compute the effect on uplink capacity. Our results show that system's uplink capacity can be improved significantly when some parameters are appropriately selected.
Peilin Hong, Kaiping Xue
CCNC2
2012 A novel power control scheme for femtocell in heterogeneous networks
abstract
Heterogeneous networks (HetNets) can provide a significant performance leap while cross-tier interference will become serious in HetNets. This paper focuses on solutions to the enhanced inter-cell interference coordination (eICIC) through adaptive power control. Four observations are concluded through the analysis of a typical interference case. A novel power control scheme without additional signalling exchange is proposed for femtocell. The remarkable performance is confirmed via system level simulation for the metrics of outage probability (OP) and energy efficiency (EE). The result shows that the novel power control scheme reducing the OP of macro cell UE (MUE) and femto cell UE (HUE) can improve the HUE throughput and maintain the highest EE from the view of system.
Jinzhu Zhang, Peilin Hong, Kaiping Xue
CCNC2
2012 A Hybrid Approach of Time-Frequency Domain Interference Coordination for QoS Guarantee in Macro-Femto Co-Channel Deployment
abstract
Femto is introduced to enhance the indoor coverage and the system capacity in LTE-Advanced system. Some methods, such as time domain interference coordination (TDIC) and frequency domain interference coordination (FDIC), have been discussed to deal with the interference between macro and femto cell when they are deployed in co- channel manner. However, TDIC operates well even though the system load is heavy but it cannot offer enough throughput in certain scenarios. On the contrary, FDIC could offer high throughput under light-load conditions at the cost of much more bandwidth. Combined the advantages of TDIC and FDIC, an approach of hybrid domain interference coordination (HDIC) is proposed and a greedy algorithm is designed in this paper. Moreover, different to the pure TDIC, TDIC used in HDIC is enhanced by allowing the user hopping to a better carrier to cooperate, namely carrier selective TDIC (CS-TDIC). Simulations show that HDIC could improve the average throughput of system in the case of light load and enable more users to meet their QoS demand of services when the load is heavy.
Zhenguo Du, Peilin Hong, Kaiping Xue
VTC Fall2
2012 A Dynamic Energy Savings Scheme Based on Enhanced Mobility Load Balancing
abstract
Nowadays, energy saving in wireless communications has become a hot topic as energy consumption increasingly becomes a global environment problem. In this paper, we formulate an Energy Consumption Rating (ECR) minimization problem in a multi-layer network and provide analysis of its property and complexity. To solve this problem, we propose the Enhanced Mobility Load Balancing (EMLB) firstly. A heuristic and practical algorithm is then introduced, which transfers traffic using EMLB in vertical and horizontal directions and adaptively switches off/on some cells based on traffic load condition. The performance of the proposed algorithm is evaluated by comparing with existing static and dynamic schemes through system level simulations. The simulation results demonstrate that our proposed scheme not only has good system throughput performance, but also achieves significant power saving in typical traffic scenario.
Jinlin Peng, Peilin Hong, Kaiping Xue
VTC Fall2
2012 Cluster-Based Resource Allocation for Interference Mitigation in LTE Heterogeneous Networks
abstract
In order to provide high data rate for indoor services, femtocells are proposed in LTE-Advanced system. Under this architecture, the main problem is how to reduce the interference between macro and femto cells and that among femtocells. In this paper, an interference graph is constructed in which the vertexes are Macro User (MUE) and femtocell. Besides, Regional Average Channel State (RACS) metric is proposed to estimate the weight of interference. Therefore, a dynamic spectrum assignment algorithm called hybrid clustering based on interference graph (HCIG) is proposed to reduce the interference, in which the optimal clustering problem is constructed as a MAX-K cut problem and a heuristic algorithm is given. Based on the cluster results, a resource allocation scheme is given to reduce the interference and improve the spectrum efficiency. System level simulation results show that compared to other three schemes, the SINR of both MUE and femto user are improved by HCIG.
Peilin Hong, Kaiping Xue, Jinlin Peng
VTC Fall2
2012 Small World P2P overlay for video sharing service
abstract
Measurement studies of YouTube show that there are some distinctive properties regarding to video sharing service, e.g., small clip size, suggestion links between related clips. This observation motivates us to explore the possibility to use peer-assisted approach to offload content providers. Specifically, we want to leverage the suggestion links between video clips to construct cooperative caching overlay. In this paper, taking advantage of this correlation between video clips, we design a distributed algorithm to adapt the overlay towards a loosely connected Small World Network (SWN), in which similar-interest peers are clustered together by short links to maximize streaming cooperation, and long links are introduced to reduce switching delay when one peer switches to an unrelated clip. The simulation results indicate that our algorithm can reduce server load significantly, and maintains the overlay as a SWN.
Kaiping Xue, Peilin Hong, Zhenguo Du
WCNC3
2011 Impact of traffic pattern on benefits of practical Multi-hop Network Coding in wireless networks
abstract
In the pioneering works, network coding has shown great potential to improve the performance of wireless networks. However, most of them are implemented under specific traffic pattern. Since various traffic patterns will affect the promising gains of network coding, in this paper, we study how traffic pattern affects the benefits of general practical network coding scheme-Multi-hop Network Coding (MNC) in wireless networks. First, we analyze the idiosyncratic properties of MNC and raise two practical issues of MNC neglected before: iteration coding and path division. Subsequently, we put forward traffic factors to describe some characteristics of realistic traffic flows, and then qualitatively analyze the relations between the traffic factors and the gains of MNC. In addition, throughput boundary with MNC is formulated in the perspective of flows. Our evaluation also shows that particular MNC should be applied according to different traffic patterns to maximize network throughput and reduce the systematic overhead.
Kaiping Xue, Peilin Hong, Hancheng Lu
CCNC3
2010 Conflict Avoidance between Mobility Robustness Optimization and Mobility Load Balancing
abstract
In Long Term Evolution (LTE) networks, Mobility Robustness Optimization (MRO) and Mobility Load Balancing (MLB) are two important functions to auto-optimize the network performances. There is a close correlation between them, as they both choose adjusting handover parameters as optimization actions. The conflict may occur between the two functions when they adjust the same handover parameter in opposite directions. This can not improve the performances but waste network resources. In this paper, we present a novel scheme to solve the problem. In order to prevent the occurrence of the conflict, we set an allowed range for MLB in which the handover problems can be prevented. Analyses and simulation results demonstrate that the proposed scheme can effectively solve the conflict problem and improve the performances of both functions.
Peilin Hong, Kaiping Xue, Min Peng 0001
GLOBECOM2
2010 Using Security Context Pre-Transfer to Provide Security Handover Optimization for Vehicular Ad Hoc Networks
abstract
In VANETs(Vehicular Ad Hoc Networks), moving from one RSU's coverage region to another will bring reauthentication in the new security domain, which can be named security handover problem. In this paper, based on mobility predictability, we propose a novel anonymous communication scheme called SCPT to address the security handover problem. It uses hash chain for vehicle's anonymous authentication. And it uses security context pre-transfer to provide security handover optimization. From security analysis and performance evaluation, SCPT can achieve security requirement in VANETs, and also reduce the implement latency after vehicle's handover.
Kaiping Xue, Peilin Hong, Xiaolei Tie
VTC Fall2
2009 Multiple stochastic paths scheme on partially-trusted relay quantum key distribution network
Zhengfu Han, Guang-Can Guo, Peilin Hong
Sci. China Ser. F Inf. Sci.5
2007 Improving the Performance of Fast Handovers in Mobile IPv6
abstract
The fast handovers for mobile IPv6 protocol has been proposed to improve handover latency due to mobile IPv6 procedures. However, in practice, the performance of fast handovers suffers from problems such as the predictive latency and reactive loss. To address these problems, in this paper, cross-layer interactions between the link layer and the network layer are introduced. First, we propose a network controlled link layer trigger on the mobile node to reduce the predictive latency. Moreover, the network controlled link layer trigger can also configure a reduced set of potential channels during scanning. Further, we propose a link triggered buffering mechanism on the access router to alleviate packet loss in reactive fast handover. Experiments in an IEEE 802.11 based test-bed show that the proposed schemes improve the performance of fast handovers in terms of handover latency and packet loss.
Hancheng Lu, Peilin Hong
GLOBECOM3
2007 An Experimental Study on Fast Handovers for Mobile IPv6
Hancheng Lu, Xiaolei Tie, Peilin Hong
WiMob3
2006 TAP: Traffic-aware topology control in on-demand ad hoc networks
Peilin Hong, Zhen-quan Qin
Comput. Commun.2
2005 Name resolution in on-demand MANET
abstract
As an important service, DNS is essential to lots of network applications such as e-mail and SIP. But traditional DNS can not work well in mobile ad hoc network (MANET) owing to the lack of fixed infrastructure. This paper proposes a novel DNS framework for the on-demand MANET by extending a DNS message in the routing protocol. The simulation results are showed that the new framework has better performance in reducing the overhead of domain name resolution.
Peilin Hong
WiMob (3)2