Thomas H. Clausen

dblp:65/6165 · also Thomas Heide Clausen · DBLP profile ↗
← Back
30ranked-venue papers
6as first author
10since 2021 · last 2025
0000-0002-7400-8887ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 15 · 3 first-author · 5 since 2021Systems, architecture and hardware · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Security and privacy · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Building a Zero Trust Federation
abstract
Zero trust is a security paradigm whose fundamental philosophy is that every access to a resource must be explicitly verified, without assuming trust based on origin or identity. In a federated environment composed of multiple domains, ensuring zero trust guarantees for accessing shared resources is a challenge, as information on requesters is generated by their originating domain, yet requires explicit verification from the domain owning the resource. This paper proposes a method for federating zero trust architectures, ensuring the preservation of zero trust guarantees when accessing federated resources. The proposed approach relies on remote attestation, enabling continuous authentication and monitoring of requesters, without requiring intrusive software installations on every device within the federation. Moreover, this paper proposes a proof-of-concept architecture that combines several open-source products, to build an architecture with advanced zero trust maturity level. The feasibility of the proposed federation method is demonstrated through this proof-of-concept, providing detailed information on the federation procedure and its implementation.
Alexandre Poirrier, Laurent Cailleux, Thomas H. Clausen
IEEE J. Sel. Areas Commun.3
2025 Is Trust Misplaced? A Zero-Trust Survey
abstract
Information technology (IT) security has been, and largely is, based on compartmentalization. To implement compartmentalization, system access privileges are granted depending on the topological location of systems, grouped into perimeters, with network mechanisms (firewalls, VLANs, ) enforcing isolation between perimeters, thus implicitly trusting systems based on their location. However, history has shown that such trust is misplaced. This has led to the emergence of an alternative paradigm, called zero trust. After contextualizing the history of IT and the emergence of zero trust for securing networks, this article presents a taxonomy of zero trust models and architectures, summarizing the goals and core principles of zero trust. Furthermore, an in-depth description of state-of-the-art technologies and methods, for transforming perimeter-based architectures to mature zero-trust architectures, is provided. This article presents a formalization of zero trust and of optimal zero-trust architectures, to which traditional architectures migrate, as well as a method for positioning migrating architectures relative to this ideal of zero trust, with as purpose of enabling a clearer understanding of the benefits and risks induced by a migration to zero trust. Finally, this article analyses the benefits, and drawbacks, of zero trust, focusing on the security properties granted by zero trust, as well as the vulnerabilities introduced.
Alexandre Poirrier, Laurent Cailleux, Thomas H. Clausen
Proc. IEEE3
2023 Understanding Semantics in Feature Selection for Fault Diagnosis in Network Telemetry Data
abstract
Expert systems for fault diagnosis are computationally expensive to build and maintain, and lack scalability and inherent adaptability to unknown events or modifications in the topology of the monitored system. While data-driven feature selection mechanisms can facilitate diagnosis without the hardship of developing and maintaining expert systems, purely data-driven mechanisms lack understanding of semantic importance within a feature set, and would benefit from additional domain knowledge. Part of this additional knowledge can be extracted from metadata. The proposed approach combines data-driven metrics and semantic information contained in the feature names to produce selections of features which best represent an underlying event. This study extends a cross entropy based optimization method to join semantic importance with data behavior. A benchmarking architecture is introduced to evaluate the benefits of semantic analysis, and demonstrate the performance and robustness of semantic feature selection on different types of faults in network telemetry datasets, modeled with the YANG data modeling language. The results illustrate the interest of such a complementary meta-data analysis for data-driven fault diagnosis, and highlight the robustness of the studied approach against variations in the input feature set.
Thomas Feltin, Juan Antonio Cordero, Frank Brockners, Thomas H. Clausen
NOMS4
2023 Optimal deployment of indoor wireless local area networks
abstract
Abstract We present a two‐phase methodology to address the problem of optimally deploying indoor wireless local area networks. In the first phase, we use Helmholtz's equation to simulate electromagnetic fields in a typical environment such as an office floor. The linear system which results from the discretization of this partial differential equation is solved with a state‐of‐the‐art library for sparse linear algebra. In the second phase, we formulate the network deployment problem in the setting of binary linear programming. This formulation employs the simulator output as input parameters, and jointly optimizes the number of access points, their locations, and their emission channels. We prove that this optimization problem is NP‐Hard, and use mathematical programming based techniques and heuristics to solve it. We present numerical experiments on medium‐sized buildings.
Antoine Oustry, Marion Le Tilly, Thomas H. Clausen, Claudia D'Ambrosio, Leo Liberti
Networks3
2022 Multi-Agent Reinforcement Learning for Network Load Balancing in Data Center
abstract
This paper presents the network load balancing problem, a challenging real-world task for multi-agent reinforcement learning (MARL) methods. Conventional heuristic solutions like Weighted-Cost Multi-Path (WCMP) and Local Shortest Queue (LSQ) are less flexible to the changing workload distributions and arrival rates, with a poor balance among multiple load balancers. The cooperative network load balancing task is formulated as a Dec-POMDP problem, which naturally induces the MARL methods. To bridge the reality gap for applying learning-based methods, all models are directly trained and evaluated on a real-world system from moderate- to large-scale setups. Experimental evaluations show that the independent and "selfish'' load balancing strategies are not necessarily the globally optimal ones, while the proposed MARL solution has a superior performance over different realistic settings. Additionally, the potential difficulties of the application and deployment of MARL methods for network load balancing are analysed, which helps draw the attention of the learning and network communities to such challenges.
Thomas H. Clausen
CIKM3
2022 Efficient Data-Driven Network Functions
abstract
Cloud environments require dynamic and adaptive networking policies. It is preferred to use heuristics over advanced learning algorithms in Virtual Network Functions (VNFs) in production because of high-performance constraints. This paper proposes Aquarius to passively yet efficiently gather observations and enable the use of machine learning to collect, infer, and supply accurate networking state information - without incurring additional signaling and management overhead. This paper illustrates the use of Aquarius with a traffic classifier, an auto-scaling system, and a load balancer - and demonstrates the use of three different machine learning paradigms - unsupervised, supervised, and reinforcement learning, within Aquarius, for inferring network state. Testbed evaluations show that Aquarius increases network state visibility and brings notable performance gains with low overhead.
Yoann Desmouceaux, Juan Antonio Cordero, W. Mark Townsley, Thomas H. Clausen
MASCOTS5
2022 Aquarius - Enable Fast, Scalable, Data-Driven Service Management in the Cloud
abstract
In order to dynamically manage and update networking policies in cloud data centers, Virtual Network Functions (VNFs) use, and therefore actively collect, networking state information - and in the process, incur additional control signaling and management overhead, especially in larger data centers. In the meantime, VNFs in production prefer distributed and straightforward heuristics over advanced learning algorithms to avoid intractable additional processing latency under high-performance and low-latency networking constraints. This paper identifies the challenges of deploying learning algorithms in the context of cloud data centers, and proposes Aquarius to bridge the application of machine learning (ML) techniques on distributed systems and service management. Aquarius passively yet efficiently gathers reliable observations, and enables the use of ML techniques to collect, infer, and supply accurate networking state information—without incurring additional signaling and management overhead. It offers fine-grained and programmable visibility to distributed VNFs, and enables both open- and close-loop control over networking systems. This paper illustrates the use of Aquarius with a traffic classifier, an auto-scaling system, and a load balancer—and demonstrates the use of three different ML paradigms—unsupervised, supervised, and reinforcement learning, within Aquarius, for network state inference and service management. Testbed evaluations show that Aquarius suitably improves network state visibility and brings notable performance gains for various scenarios with low overhead.
Yoann Desmouceaux, Juan Antonio Cordero, W. Mark Townsley, Thomas H. Clausen
IEEE Trans. Netw. Serv. Manag.5
2022 HLB: Toward Load-Aware Load Balancing
abstract
The purpose of network load balancers is to optimize quality of service to the users of a set of servers– basically, to improve response times and to reducing computing resources– by properly distributing workloads. This paper proposes a distributed, application-agnostic, Hybrid Load Balancer (HLB) that– without explicit monitoring or signaling– infers server occupancies and processing speeds, which allows making optimised workload placement decisions. This approach is evaluated both through simulations and extensive experiments, including synthetic workloads and Wikipedia replays on a real-world testbed. Results show significant performance gains, in terms of both response time and system utilisation, when compared to existing load-balancing algorithms.
Yoann Desmouceaux, Juan Antonio Cordero, W. Mark Townsley, Thomas H. Clausen
IEEE/ACM Trans. Netw.5
2021 Charon: Load-Aware Load-Balancing in P4
abstract
Load-Balancers play an important role in data centers as they distribute network flows across application servers and guarantee per-connection consistency. It is hard however to make fair load balancing decisions so that all resources are efficiently occupied yet not overloaded. Tracking connection states allows to infer server load states and make informed decisions, but at the cost of additional memory space consumption. This makes it hard to implement on programmable hardware, which has constrained memory but offers line-rate performance. This paper presents Charon, a stateless load-aware load balancer that has line-rate performance implemented in P4-NetFPGA. Charon passively collects load states from application servers and employs the power-of-2-choices scheme to make data-driven load balancing decisions and improve resource utilization. Per-connection consistency is preserved statelessly by encoding server ID in a covert channel. The prototype design and implementation details are described in this paper. Simulation results show performance gains in terms of load distribution fairness, quality of service, throughput and processing latency.
Carmine Rizzi, Yoann Desmouceaux, W. Mark Townsley, Thomas H. Clausen
CNSM5
2021 Joint Monitorless Load-Balancing and Autoscaling for Zero-Wait-Time in Data Centers
abstract
Cloud architectures achieve scaling through two main functions: (i) load-balancers, which dispatch queries among replicated virtualized application instances, and (ii) autoscalers, which automatically adjust the number of replicated instances to accommodate variations in load patterns. These functions are often provided through centralized load monitoring, incurring operational complexity. This article introduces a unified and centralized-monitoring-free architecture achieving both autoscaling and load-balancing, reducing operational overhead while increasing response time performance. Application instances are virtually ordered in a chain, and new queries are forwarded along this chain until an instance, based on its local load, accepts the query. Autoscaling is triggered by the last application instance, which inspects its average load and infers if its chain is under- or over-provisioned. An analytical model of the system is derived, and proves that the proposed technique can achieve asymptotic zero-wait time with high (and controlable) probability. This result is confirmed by extensive simulations, which highlight close-to-ideal performance in terms of both response time and resource costs.
Yoann Desmouceaux, Marcel Enguehard, Thomas H. Clausen
IEEE Trans. Netw. Serv. Manag.3
2020 Semantic feature selection for network telemetry event description
abstract
Model driven telemetry (MDT) enables the real-time collection of hundreds of thousands of counters on large-scale networks, with contextual information to each counter provided in the telemetry data structure definition. Explaining network events in such datasets implies substantial analysis by a domain expert. This paper presents an semantic feature selection method, to find the most important counters which describe a given event in a telemetry dataset, and facilitate the explanation process. This paper proposes a metric for estimating the importance of features in a dataset with descriptive feature names, to find those that are most meaningful to a human. With this estimation, this paper presents a cross-entropy based metric describing the quality of a selection of counters, which is combined with the data behavior to define an optimization goal. The computation of optimal selections distills intelligible and precise selections of counters with adjustable verbosity, and describes events with a few selected counters outlining the root cause of network events.
Thomas Feltin, Parisa Foroughi, Wenqin Shao, Frank Brockners, Thomas H. Clausen
NOMS5
2020 High-Accuracy Packet Pacing on Commodity Servers for Constant-Rate Flows
abstract
This paper addresses the problem of high-quality packet pacing for constant-rate packet consumption systems, with strict buffering limitations. A mostly-software pacing architecture is developed, which has minimal hardware requirements, satisfied by commodity servers - rendering the proposed solution easily deployable in existing (data-centre) infrastructures. Two algorithms (free-running and frequency-controlled pacing, for explicitly and implicitly indicated target rates, respectively) are specified, and formally analysed. The proposed solution, including both algorithms, is implemented, and is tested on real hardware and under real conditions. The performance of these implementations is experimentally evaluated and compared to existing mechanisms, available in general-purpose hardware. Results of both exhaustive experiments, and of an analytical modeling, indicate that the proposed approach is able to perform low-jitter packet pacing on commodity hardware, being thus suitable for constant rate transmission and consumption in media production scenarios.
Mohammed Hawari, Juan Antonio Cordero, Thomas H. Clausen
IEEE/ACM Trans. Netw.3
2019 Reliable BIER With Peer Caching
abstract
BIER (Bit-Indexed Explicit Replication) alleviates the operational complexities of multicast protocols (associated to the multicast tree and the incurred state in intermediate routers), by allowing for source-driven, per-packet destination selection, efficient encoding thereof in packet headers, and stateless forwarding along shortest-path multicast trees. BIER per-packet destination selection enables efficient reliable multicast delivery: packets not received by a subset of intended destinations can be efficiently BIER-retransmitted to only that subset. While BIER-based reliable multicast exhibits attractive performance attributes, relying on source retransmissions for packet recovery may be costly - even unnecessary, if topologically close peers are able to provide a copy of the packet. Thus, this paper extends the use of reliable BIER multicast to allow recovery also from peers, using Segment Routing (SR) to steer retransmission requests through a set of potential (local) candidates, before requesting retransmissions from the source as a last resort only. A general framework is introduced, which can accommodate different policies for the selection of candidate peers for retransmissions. Simple (both static and adaptive) policies are introduced and analyzed, both (i) theoretically and (ii) by way of simulations in data-center-like and real-world topologies. Results indicate that local peer recovery is able to substantially reduce the overall retransmission traffic, and that this can be achieved through simple policies, where no signalling is required to build a set of candidate peers.
Yoann Desmouceaux, Juan Antonio Cordero, Thomas H. Clausen
IEEE Trans. Netw. Serv. Manag.3
2018 Zero-Loss Virtual Machine Migration with IPv6 Segment Routing
Yoann Desmouceaux, W. Mark Townsley, Thomas H. Clausen
CNSM3
2018 Chasing Linux Jitter Sources for Uncompressed Video
Arthur Toussaint, Mohammed Hawari, Thomas H. Clausen
CNSM3
2018 Stateless Load-Aware Load Balancing in P4
abstract
Leveraging the performance opportunities offered by programmable hardware, stateless load-balancing architectures allowing line-rate processing are appealing. Moreover, it has been demonstrated that significantly fairer load-balancing can be achieved by an architecture that considers the actual load of application instances when dispatching connection requests. Architectures which maintain per-connection state for resiliency and/or track application load state for fairness are, however, at odds with hardware-imposed memory constraints. Thus, a desirable load-balancer for programmable hardware would be both stateless and able to dispatch queries to application instances according to their current load. This paper presents SHELL, a stateless application-aware load-balancer combining (i) a power-of-choices scheme using IPv6 Segment Routing to dispatch new flows to a suitable application instance from among multiple candidates, and (ii) the use of a covert channel to record/report which flow was assigned to which candidate in a stateless fashion. In addition, consistent hashing versioning is used to ensure that connections are maintained to the correct application instance, using Segment Routing to "browse" through the history when needed. The stateless design of SHELL makes it suitable for hardware implementation, and this paper describes the implementation of a P4-NetFPGA prototype. A performance evaluation of this SHELL implementation demonstrates throughput and latency characteristics comparable to other stateless load-balancing implementations, while enabling application instance-load-aware dispatching and significantly increasing per-connection consistency resiliency.
Benoit Pit-Claudel, Yoann Desmouceaux, Pierre Pfister, W. Mark Townsley, Thomas H. Clausen
ICNP5
2018 Use 'em or lose 'em: On unidirectional links in reactive routing protocols
Thomas H. Clausen, Juan Antonio Cordero, Jiazi Yi, Yuichi Igarashi
Ad Hoc Networks1
2018 6LB: Scalable and Application-Aware Load Balancing with Segment Routing
Yoann Desmouceaux, Pierre Pfister, Jerome Tollet, W. Mark Townsley, Thomas H. Clausen
IEEE/ACM Trans. Netw.5
2017 SRLB: The Power of Choices in Load Balancing with Segment Routing
abstract
Network load-balancers generally either do not take application state into account, or do so at the cost of a centralized monitoring system. This paper introduces a load-balancer running exclusively within the IP forwarding plane, i.e. in an application protocol agnostic fashion - yet which still provides application-awareness and makes real-time, decentralized decisions. To that end, IPv6 Segment Routing is used to direct data packets from a new flow through a chain of candidate servers, until one decides to accept the connection, based on its local state. This way, applications themselves naturally decide on how to share incoming connections, while incurring minimal network overhead, and no out-of-band signaling. Tests on different workloads - including realistic workloads such as replaying actual Wikipedia access traffic towards a set of replica Wikipedia instances - show significant performance benefits, in terms of shorter response times, when compared to a traditional random load-balancer.
Yoann Desmouceaux, Pierre Pfister, Jerome Tollet, W. Mark Townsley, Thomas H. Clausen
ICDCS5
2017 Lightweight On-demand Ad hoc Distance-vector Routing - Next Generation (LOADng): Protocol, extension, and applicability
Thomas H. Clausen, Jiazi Yi, Ulrich Herberg
Comput. Networks1
2015 Source-Destination Routing for Optimised Link State Routing Protocol
abstract
Typical routing protocols maintain, in their RIB (Routing Information Base) entries permitting destination-based forwarding: for a given data packet, the choice of next hop is a function of the destination address only. However, in deployments where a given network is multi-homed, and where ingress filtering is commonly applied, a routing protocol is required to be able to provide routes so as to forward a data packet (i) to the destination address of the data packet, while (ii) routing through the gateway for which the source address of the data packet is topologically correct. This is called source-destination routing. This paper presents an extension to the Optimized Link State Routing Protocol version 2 (OLSRv2), providing support for such source-destination routing. In a multi- homed network, this OLSRv2 extension provides routes for data packets based also on the source prefix announced by the gateways. The extension is interoperable with unextended OLSRv2. The performance of this extension is quantified by way of simulation studies.
Jiazi Yi, Thomas H. Clausen
VTC Fall2
2015 Depth-First Forwarding for Unreliable Networks: Extensions and Applications
abstract
This paper introduces extensions and applications of depth-first forwarding (DFF)-a data forwarding mechanism for use in unreliable networks such as sensor networks and Mobile Ad hoc NETworks with limited computational power and storage, low-capacity channels, device mobility, etc. Routing protocols for these networks try to balance conflicting requirements of being reactive to topology and channel variation while also being frugal in resource requirements-but when the underlying topology changes, routing protocols require time to re converge, during which data delivery failure may occur. DFF was developed to alleviate this situation: it reacts rapidly to local data delivery failures and attempts to successfully deliver data while giving a routing protocol time to recover from such a failure. An extension of DFF, denoted as DFF++, is proposed in this paper, in order to optimize the performance of DFF by way of introducing a more efficient search ordering. This paper also studies the applicability of DFF to three major routing protocols for the Internet of Things (IoT), including the Lightweight On-demand Ad hoc Distance-vector Routing Protocol-Next Generation (LOADng), the optimized link state routing protocol version 2 (OLSRv2), and the IPv6 routing protocol for low-power and lossy networks (RPL), and presents the performance of these protocols, with and without DFF, in lossy and unreliable networks.
Jiazi Yi, Thomas H. Clausen, Ulrich Herberg
IEEE Internet Things J.2
2012 LOADng: Towards AODV Version 2
abstract
The Ad hoc On-demand Distance-Vector routing protocol (AODV) was published in 2003 by the IETF, as experimental RFC 3561. This routing protocol was one of four routing protocols, developed by the IETF for use in mobile ad hoc networks (MANETs) -- with the other being DSR, TBRPF and OLSR. As operational experiences with these protocols accumulated, the IETF set forth on standardization of OLSRv2, a successor to OLSR, and DYMO -- with DYMO being the intended successor to DSR and AODV. Alas, while there was traction for and standardization of OLSRv2, interest in, development, standardization, and use of DYMO in MANETs slowly withered. AODV did, however, attract interest for routing in Low-power Lossy Networks (LLNs) due to its limited state requirements. Since 2005, several proposals for simplifying and adapting AODV specifically for LLNs emerged, in 2011 and 2012 with the use of one such adaptation of AODV in the G3-PLC standard for power line communications in smart grids, and with efforts within the IETF emerging towards a single LOADng specification, as next version of AODV. This paper presents this development -- from AODV, as specified in RFC3561 -- to LOADng. While the basic operation remains unchanged, LOADng presents simplifications, and additional features and flexibilities are introduced. This paper studies the impact of these changes "from AODV to LOADng", and observes that LOADng unites simplification, flexibility and performance improvements.
Thomas H. Clausen, Jiazi Yi, Axel Colin de Verdiere
VTC Fall1
2011 Delay Tolerant Networking with OLSRv2
abstract
This paper proposes a simple mechanism for enabling basic delay tolerant networking with off-the-shelf MANET routing protocols -- with the objective being to enable trading off slightly longer data delivery delays against resilience to a temporary lack of connectivity between a router and the ultimate destination of an IP data gram. As part of testing the benefit of said mechanism, an extreme network mobility model is proposed, entitled the "Pop Up model": a router appears in the network, and operates normally -- then may disable and disappear from the network to appear later elsewhere. Observed to cause severely degraded performance for MANET routing protocols, this model is used for testing the proposed mechanism in OLSRv2-routed MANETs. The proposed mechanism shows to vastly increase the data delivery ration, with reasonably low increases in delays and control traffic overhead incurred.
Ulrich Herberg, Thomas H. Clausen
EUC2
2011 A critical evaluation of the IPv6 Routing Protocol for Low Power and Lossy Networks (RPL)
abstract
With RPL - the “IPv6 Routing Protocol for Low-power Lossy Networks” - emerging as a Proposed Standard “Request For Comment” (RFC) in the Internet Engineering Task Force (IETF) after a ~2-year development cycle, this paper presents a critical evaluation of the resulting protocol and its applicability and limits. The paper presents a selection of observations of the protocol characteristics, exposes experiences acquired when producing a prototype implementation of RPL, and presents results obtained from testing this protocol - both in a network simulator, and in real-world experiments on a wireless sensor network testbed. The paper aims at providing a better understanding of possible weaknesses and limits of RPL, notably the possible directions that further protocol developments should explore, in order to address these.
Thomas H. Clausen, Ulrich Herberg, Matthias Philipp
WiMob1
2010 MANET network management and performance monitoring for NHDP and OLSRv2
abstract
Mobile Ad Hoc NETworks (MANETs) are generally thought of as infrastructureless and largely “un-managed” network deployments, capable of accommodating highly dynamic network topologies. Yet, while the network infrastructure may be “un-managed”, monitoring the network performance and setting configuration parameters once deployed, remains important in order to ensure proper “tuning” and maintenance of a MANET. This paper describes a management framework for the MANET routing protocol OLSRv2, and its constituent protocol NHDP. It does so by presenting considerations for “what to monitor and manage” in an OLSRv2 network, and how. The approach developed is based on the Simple Network Management Protocol (SNMP), and thus this paper details the various Management Information Bases (MIBs) for router status monitoring and control - as well as a novel approach to history-based performance monitoring. While SNMP may not be optimally designed for MANETs, it is chosen due to it being the predominant protocol for IP network management - and thus, efforts are made in this paper to “adapt” the management tools within the SNMP framework for reasonable behavior also in a MANET environment.
Ulrich Herberg, Thomas H. Clausen, Robert G. Cole
CNSM2
2010 Yet Another Autoconf Proposal (YAAP) for Mobile Ad Hoc NETworks
abstract
This paper addresses the issues of automatic address and prefix configuration of MANET routers. Specifically, the paper analyzes the differences between “classic IP networks” and MANETs, emphasizing the interface, link, topology, and addressing assumptions present in “classic IP networks”. The paper presents a model for how this can be matched to the specific constraints and conditions of a MANET-i.e., how MANETs can be configured to adhere to the Internet addressing architecture. This sets the stage for development of a MANET autoconfiguration protocol, enabling automatic configuration of MANET interfaces and prefix delegation. This autoconfiguration protocol is characterized by (i) adhering strictly to the Internet addressing architecture, (ii) being able to configure both MANET interface addresses and handle prefix delegation, and (iii) being able to configure both stand-alone MANETs, as well as MANETs connected to an infrastructure providing, e.g., globally scoped addresses/prefixes for use within the MANET. The protocol is specified through timed automatons which, by way of model checking, enable verification of certain protocol properties. Furthermore, a performance study of the basic protocol, as well as of various optimization and extensions hereto, is conducted based on network simulations.
Ulrich Herberg, Thomas H. Clausen
MSN2
2010 Router and Link Admittance Control in the Optimized Link State Routing Protocol Version 2 (OLSRv2)
abstract
This paper presents security mechanisms for router and link admittance control in OLSRv2. Digitally signing OLSRv2 control messages allows recipient routers to - individually - choose to admit or exclude the originating router for when populating link-state databases, calculating MPR sets etc. By additionally embedding signatures for each advertised link, recipient routers can also control admittance of each advertised link in the message, rendering an OLSRv2 network resilient to both identity-spoofing and link-spoofing attacks. The flip-side of the coin when using such a link-admittance mechanism is, that the number of signatures to include in each OLSRv2 control message is a function of the number of links advertised. For HELLO messages, this is essentially the number of neighbor routers, for TC messages, this is the number of MPR Selectors of the originator of the message. Also, upon receipt of a control message, these signatures are to be verified. This paper studies the impact of adding a link-admittance control mechanism to OLSRv2, both in terms of additional control-traffic overhead and additional in-router processing resources, using several cryptographic algorithms, such as RSA and Elliptic Curve Cryptography for very short signatures.
Thomas H. Clausen, Ulrich Herberg
NSS1
2004 OSPF-style database exchange and reliable synchronization in the optimized link-state routing protocol
abstract
The optimized link-state routing protocol (OLSR) is a proactive link-state routing protocol. While similar to the well-known Internet routing protocol OSPF, OLSR is designed to be simple, and to maintain connectivity in face of highly dense and dynamic networks, while being resource-economic (battery, bandwidth etc.) These characteristics make OLSR suitable as an underlaying routing protocol in a wide range of ad-hoc sensor networks. In this paper, we introduce an extension to OLSR: OSPF-style database exchange and reliable synchronization. The goal of this extension is to provide a mechanism, through which nodes in an ad-hoc sensor network can detect and correct discrepancies in their link-state databases. We qualify why the mechanism, found in OSPF, is not directly applicable for ad-hoc sensor networks, describe an adopted mechanism, accomplishing the same goal, and evaluate the performance of this mechanism in comparison to the database exchange mechanism found in OSPF. We finally discuss some applications of database exchange and reliable synchronization in ad-hoc sensor networks.
Thomas H. Clausen, Emmanuel Baccelli, Philippe Jacquet
SECON1
2004 Analyzing Control Traffic Overhead versus Mobility and Data Traffic Activity in Mobile Ad-Hoc Network Protocols
Laurent Viennot, Philippe Jacquet, Thomas H. Clausen
Wirel. Networks3