Sharon Goldberg

dblp:87/2320 · DBLP profile ↗
← Back
29ranked-venue papers
11as first author
1since 2021 · last 2024
0000-0002-1002-3332ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 13 · 6 first-authorSecurity and privacy · 9 · 3 first-author · 1 since 2021Systems, architecture and hardware · 3 · 1 first-authorSoftware engineering, systems software and programming languages · 2 · 1 first-authorDatabases, data management, data science and information retrieval · 2Theory of computation · 2 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
19 papers
Network security · 40% Cryptographic primitives and cryptanalysis · 21% Blockchain and cryptocurrency security · 15%
Computer networks
17 papers
Routing and switching · 48% Network measurement and analytics · 30% Internet architecture and protocols · 11%
Theoretical computer science
2 papers
Approximation and online algorithms · 47% Graph algorithms and graph theory · 47% Coding theory · 6%

Topics — the 30 heaviest of 48, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Network security
routing security
0.862017
MaxLength Considered Harmful to the RPKI · CoNEXT 2017
RPKI vs ROVER: comparing the risks of BGP security solutions · SIGCOMM 2014
BGP security in partial deployment: is the juice worth the squeeze? · SIGCOMM 2013
Authentication and access control › authentication
authentication protocols
0.812024
RADIUS/UDP Considered Harmful · USENIX Security Symposium 2024
Routing and switching
inter-domain routing
0.752017
MaxLength Considered Harmful to the RPKI · CoNEXT 2017
From the consent of the routed: improving the transparency of the RPKI · SIGCOMM 2014
Let the market drive deployment: a strategy for transitioning to BGP security · SIGCOMM 2011
Blockchain and cryptocurrency security › electronic cash
bitcoin
0.522017
TumbleBit: An Untrusted Bitcoin-Compatible Anonymous Payment Hub · NDSS 2017
Eclipse Attacks on Bitcoin's Peer-to-Peer Network · USENIX Security Symposium 2015
Routing and switching › inter-domain routing
BGP
0.422014
RPKI vs ROVER: comparing the risks of BGP security solutions · SIGCOMM 2014
BGP security in partial deployment: is the juice worth the squeeze? · SIGCOMM 2013
Cryptographic primitives and cryptanalysis › public-key cryptography › digital signatures › multiparty signatures
aggregate signatures
0.322014
Sequential aggregate signatures with lazy verification from trapdoor permutations · Inf. Comput. 2014
Sequential Aggregate Signatures with Lazy Verification from Trapdoor Permutations - (Extended Abstract) · ASIACRYPT 2012
Cryptographic primitives and cryptanalysis › public-key cryptography
digital signatures
0.322014
Sequential aggregate signatures with lazy verification from trapdoor permutations · Inf. Comput. 2014
Sequential Aggregate Signatures with Lazy Verification from Trapdoor Permutations - (Extended Abstract) · ASIACRYPT 2012
Network measurement and analytics › network performance measurement
latency and loss measurement
0.322014
FineComb: Measuring Microscopic Latency and Loss in the Presence of Reordering · IEEE/ACM Trans. Netw. 2014
Fine-grained latency and loss measurements in the presence of reordering · SIGMETRICS 2011
Network measurement and analytics › internet measurement
internet path measurement
0.322015
Path-Quality Monitoring in the Presence of Adversaries: The Secure Sketch Protocols · IEEE/ACM Trans. Netw. 2015
Path-quality monitoring in the presence of adversaries · SIGMETRICS 2008
Routing and switching › inter-domain routing › inter-domain routing security
RPKI
0.312017
MaxLength Considered Harmful to the RPKI · CoNEXT 2017
Privacy and data protection › anonymity
anonymous payment
0.312017
TumbleBit: An Untrusted Bitcoin-Compatible Anonymous Payment Hub · NDSS 2017
Blockchain and cryptocurrency security › off-chain payment
payment channel
0.312017
TumbleBit: An Untrusted Bitcoin-Compatible Anonymous Payment Hub · NDSS 2017
Network security › attack strategy
denial-of-service attack
0.212016
Attacking the Network Time Protocol · NDSS 2016
Network security › protocol security
network protocol security
0.212016
Attacking the Network Time Protocol · NDSS 2016
Network security › protocol security
time synchronization security
0.212016
Attacking the Network Time Protocol · NDSS 2016
Network security › protocol security
protocol vulnerabilities
0.212024
RADIUS/UDP Considered Harmful · USENIX Security Symposium 2024
Network security › protocol security
DNS security
0.212015
NSEC5: Provably Preventing DNSSEC Zone Enumeration · NDSS 2015
Blockchain and cryptocurrency security › blockchain network security
eclipse attack
0.212015
Eclipse Attacks on Bitcoin's Peer-to-Peer Network · USENIX Security Symposium 2015
Cryptographic primitives and cryptanalysis › one-way functions › trapdoor functions
trapdoor permutations
0.222014
Sequential Aggregate Signatures with Lazy Verification from Trapdoor Permutations - (Extended Abstract) · ASIACRYPT 2012
Sequential aggregate signatures with lazy verification from trapdoor permutations · Inf. Comput. 2014
Routing and switching › inter-domain routing › BGP
BGP security
0.212014
RPKI vs ROVER: comparing the risks of BGP security solutions · SIGCOMM 2014
Network measurement and analytics
end-to-end measurement
0.212014
FineComb: Measuring Microscopic Latency and Loss in the Presence of Reordering · IEEE/ACM Trans. Netw. 2014
Privacy and data protection
differential privacy
0.212014
Calibrating Data to Sensitivity in Private Data Analysis · Proc. VLDB Endow. 2014
Privacy and data protection
privacy-preserving data analysis
0.212014
Calibrating Data to Sensitivity in Private Data Analysis · Proc. VLDB Endow. 2014
Network security › routing security
RPKI
0.212014
From the consent of the routed: improving the transparency of the RPKI · SIGCOMM 2014
Network security › routing security › interdomain routing security
BGP security
0.212013
BGP security in partial deployment: is the juice worth the squeeze? · SIGCOMM 2013
Approximation and online algorithms
approximation algorithms
0.212013
The Diffusion of Networking Technologies · SODA 2013
Optical networks
optical code-division multiple access
0.122007
On the Teletraffic Capacity of Optical CDMA · IEEE Trans. Commun. 2007
Source-Matched Spreading Codes for Optical CDMA · IEEE Trans. Commun. 2007
Cryptographic primitives and cryptanalysis
cryptographic assumptions
0.112012
Sequential Aggregate Signatures with Lazy Verification from Trapdoor Permutations - (Extended Abstract) · ASIACRYPT 2012
Privacy and data protection
anonymity
0.112017
TumbleBit: An Untrusted Bitcoin-Compatible Anonymous Payment Hub · NDSS 2017
Network management and operations › fault management
failure localization
0.112008
Protocols and Lower Bounds for Failure Localization in the Internet · EUROCRYPT 2008

Methods — techniques the papers use, named apart from their topics

network measurement · 0.8security analysis · 0.5sublinear sketching · 0.4second moment estimation · 0.4game theory · 0.4lazy verification · 0.3stash recovery · 0.3order-agnostic packet digests · 0.3cryptographic protocol design · 0.3packet spoofing · 0.2off-path attack · 0.2cryptographic protocols · 0.2cryptographic protocol · 0.2threat modeling · 0.2probabilistic inference · 0.2data-driven analysis · 0.2linear programming · 0.2puncturing · 0.1
YearPublicationVenuePosition
2024 RADIUS/UDP Considered Harmful
Sharon Goldberg, Miro Haller, Nadia Heninger, Mike Milano, Daniel Shumow, Marc Stevens 0001, Adam Suhl
USENIX Security Symposium1
2019 Efficient Noninteractive Certification of RSA Moduli and Beyond
Sharon Goldberg, Leonid Reyzin, Omar Sagga, Foteini Baldimtsi
ASIACRYPT (3)1
2018 The Unintended Consequences of Email Spam Prevention
Sarah Scheffler, Yossi Gilad, Sharon Goldberg
PAM4
2017 MaxLength Considered Harmful to the RPKI
abstract
User convenience and strong security are often at odds, and most security applications need to find some sort of balance between these two (often opposing) goals. The Resource Public Key Infrastructure (RPKI), a security infrastructure built on top of interdomain routing, is not immune to this issue. The RPKI uses the maxLength attribute to reduce the amount of information that must be explicitly recorded in its cryptographic objects. MaxLength also allows operators to easily reconfigure their networks without modifying their RPKI objects. Our network measurements, however, suggest that the maxLength attribute strikes the wrong balance between security and user convenience. We therefore believe that operators should avoid using maxLength. We give operational recommendations and develop software that allow operators to reap many of the benefits of maxLength without its security costs.
Yossi Gilad, Omar Sagga, Sharon Goldberg
CoNEXT3
2017 TumbleBit: An Untrusted Bitcoin-Compatible Anonymous Payment Hub
Ethan Heilman, Leen Alshenibr, Foteini Baldimtsi, Alessandra Scafuro, Sharon Goldberg
NDSS5
2016 Attacking the Network Time Protocol
Aanchal Malhotra, Isaac E. Cohen, Erik Brakke, Sharon Goldberg
NDSS4
2015 NSEC5: Provably Preventing DNSSEC Zone Enumeration
Sharon Goldberg, Moni Naor, Dimitrios Papadopoulos 0001, Leonid Reyzin, Sachin Vasant, Asaf Ziv
NDSS1
2015 Eclipse Attacks on Bitcoin's Peer-to-Peer Network
Ethan Heilman, Alison Kendler, Aviv Zohar, Sharon Goldberg
USENIX Security Symposium4
2015 Path-Quality Monitoring in the Presence of Adversaries: The Secure Sketch Protocols
abstract
Edge networks connected to the Internet need effective monitoring techniques to inform routing decisions and detect violations of Service Level Agreements (SLAs). However, existing measurement tools, like ping, traceroute, and trajectory sampling, are vulnerable to attacks that can make a path look better than it really is. Here, we design and analyze a lightweight path-quality monitoring protocol that reliably raises an alarm when the packet-loss rate exceed a threshold, even when an adversary tries to bias monitoring results by selectively delaying, dropping, modifying, injecting, or preferentially treating packets. Our protocol is based on sublinear algorithms for sketching the second moment of stream of items and can monitor billions of packets using only 250-600 B of storage and the periodic transmission of a comparably sized IP packet. We also show how this protocol can be used to construct a more sophisticated protocol that allows the sender to localize the link responsible for the dropped packets. We prove that our protocols satisfy a precise definition of security, analyze their performance using numerical experiments, and derive analytic expressions for the tradeoff between statistical accuracy and system overhead. This paper contains a deeper treatment of results from earlier conference papers and several new results.
Sharon Goldberg, David Xiao, Eran Tromer, Boaz Barak, Jennifer Rexford
IEEE/ACM Trans. Netw.1
2015 Characterizing Web Censorship Worldwide: Another Look at the OpenNet Initiative Data
abstract
In this study, we take another look at 5 years of web censorship data gathered by the OpenNet Initiative in 77 countries using user-based testing with locally relevant content. Prior to our work, this data had been analyzed with little automation, focusing on what content had been blocked, rather than how blocking was carried out. In this study, we use more rigorous automation to obtain a longitudinal, global view of the technical means used for web censorship. We also identify blocking that had been missed in prior analyses. Our results point to considerable variability in the technologies used for web censorship, across countries, time, and types of content, and even across ISPs in the same country. In addition to characterizing web censorship in countries that, thus far, have eluded technical analysis, we also discuss the implications of our observations on the design of future network measurement platforms and circumvention technologies.
Phillipa Gill, Masashi Crete-Nishihata, Jakub Dalek, Sharon Goldberg, Adam Senft, Greg Wiseman
ACM Trans. Web4
2014 From the consent of the routed: improving the transparency of the RPKI
abstract
The Resource Public Key Infrastructure (RPKI) is a new infrastructure that prevents some of the most devastating attacks on interdomain routing. However, the security benefits provided by the RPKI are accomplished via an architecture that empowers centralized authorities to unilaterally revoke any IP prefixes under their control. We propose mechanisms to improve the transparency of the RPKI, in order to mitigate the risk that it will be used for IP address takedowns. First, we present tools that detect and visualize changes to the RPKI that can potentially take down an IP prefix. We use our tools to identify errors and revocations in the production RPKI. Next, we propose modifications to the RPKI's architecture to (1) require any revocation of IP address space to receive consent from all impacted parties, and (2) detect when misbehaving authorities fail to obtain consent. We present a security analysis of our architecture, and estimate its overhead using data-driven analysis.
Ethan Heilman, Danny Cooper, Leonid Reyzin, Sharon Goldberg
SIGCOMM4
2014 RPKI vs ROVER: comparing the risks of BGP security solutions
abstract
BGP, the Internet's interdomain routing protocol, is highly vulnerable to routing failures that result from unintentional misconfigurations or deliberate attacks. To defend against these failures, recent years have seen the adoption of the Resource Public Key Infrastructure (RPKI), which currently authorizes 4% of the Internet's routes. The RPKI is a completely new security infrastructure (requiring new servers, caches, and the design of new protocols), a fact that has given rise to some controversy. Thus, an alternative proposal has emerged: Route Origin Verification (ROVER}, which leverages the existing reverse DNS (rDNS) and DNSSEC to secure the interdomain routing system. Both RPKI and ROVER rely on a hierarchy of authorities to provide trusted information about the routing system. Recently, however, it has been argued that the misconfigured, faulty or compromised RPKI authorities introduce new vulnerabilities in the routing system, which can take IP prefixes offline. Meanwhile, the designers of ROVER claim that it operates in a "fail-safe mode", where "[o]ne could completely unplug a router verification application at any time and Internet routing would continue to work just as it does today". There has been debate in Internet community mailing lists about the pros and cons of both approaches. This poster therefore compares the impact of ROVER failures to those of the RPKI, in a threat model that covers misconfigurations, faults or compromises of their trusted authorities.
Aanchal Malhotra, Sharon Goldberg
SIGCOMM2
2014 How secure are secure interdomain routing protocols?
Sharon Goldberg, Michael Schapira, Peter Hummon, Jennifer Rexford
Comput. Networks1
2014 Sequential aggregate signatures with lazy verification from trapdoor permutations
Kyle Brogle, Sharon Goldberg, Leonid Reyzin
Inf. Comput.2
2014 Calibrating Data to Sensitivity in Private Data Analysis
abstract
We present an approach to differentially private computation in which one does not scale up the magnitude of noise for challenging queries, but rather scales down the contributions of challenging records. While scaling down all records uniformly is equivalent to scaling up the noise magnitude, we show that scaling records non-uniformly can result in substantially higher accuracy by bypassing the worst-case requirements of differential privacy for the noise magnitudes. This paper details the data analysis platform wPINQ , which generalizes the Privacy Integrated Query (PINQ) to weighted datasets. Using a few simple operators (including a non-uniformly scaling Join operator) wPINQ can reproduce (and improve) several recent results on graph analysis and introduce new generalizations ( e.g. , counting triangles with given degrees). We also show how to integrate probabilistic inference techniques to synthesize datasets respecting more complicated (and less easily interpreted) measurements.
Davide Proserpio, Sharon Goldberg, Frank McSherry
Proc. VLDB Endow.2
2014 FineComb: Measuring Microscopic Latency and Loss in the Presence of Reordering
abstract
Modern stock trading and cluster applications require microsecond latencies and almost no losses in data centers. This paper introduces an algorithm called FineComb that can obtain fine-grain end-to-end loss and latency measurements between edge routers in these networks. Such a mechanism can allow managers to distinguish between latencies and loss singularities caused by servers and those caused by the network. Compared to prior work, such as Lossy Difference Aggregator (LDA), which focused on switch-level latency measurements, the requirement of end-to-end latency measurements introduces the challenge of reordering that occurs commonly in IP networks due to churn. The problem is even more acute in switches across data center networks that employ multipath routing algorithms to exploit the inherent path diversity. Without proper care, a loss estimation algorithm can confound loss and reordering; furthermore, any attempt to aggregate delay estimates in the presence of reordering results in severe errors. FineComb deals with these problems using order-agnostic packet digests and a simple new idea we call stash recovery. Our evaluation demonstrates that FineComb is orders of magnitude more accurate than LDA in loss and delay estimates in the presence of reordering.
Myungjin Lee, Sharon Goldberg, Ramana Rao Kompella, George Varghese
IEEE/ACM Trans. Netw.2
2013 On the risk of misbehaving RPKI authorities
abstract
The RPKI is a new security infrastructure that relies on trusted authorities to prevent some of the most devastating attacks on interdomain routing. The threat model for the RPKI supposes that authorities are trusted and routing is under attack. Here we discuss the risks that arise when this threat model is flipped: when RPKI authorities are faulty, misconfigured, compromised, or compelled to misbehave. We show how design decisions that elegantly address the vulnerabilities in the original threat model have unexpected side effects in this flipped threat model. In particular, we show new targeted attacks that allow RPKI authorities, under certain conditions, to limit access to IP prefixes, and discuss the risk that transient RPKI faults can take IP prefixes offline. Our results suggest promising directions for future research, and have implications on the design of security architectures that are appropriate for the untrusted and error-prone Internet.
Danny Cooper, Ethan Heilman, Kyle Brogle, Leonid Reyzin, Sharon Goldberg
HotNets5
2013 BGP security in partial deployment: is the juice worth the squeeze?
abstract
As the rollout of secure route origin authentication with the RPKI slowly gains traction among network operators, there is a push to standardize secure path validation for BGP (i.e., S*BGP: S-BGP, soBGP, BGPSEC, etc.). Origin authentication already does much to improve routing security. Moreover, the transition to S*BGP is expected to be long and slow, with S*BGP coexisting in "partial deployment" alongside BGP for a long time. We therefore use theoretical and experimental approach to study the security benefits provided by partially-deployed S*BGP, vis-a-vis those already provided by origin authentication. Because routing policies have a profound impact on routing security, we use a survey of 100 network operators to find the policies that are likely to be most popular during partial S*BGP deployment. We find that S*BGP provides only meagre benefits over origin authentication when these popular policies are used. We also study the security benefits of other routing policies, provide prescriptive guidelines for partially-deployed S*BGP, and show how interactions between S*BGP and BGP can introduce new vulnerabilities into the routing system.
Robert Lychev, Sharon Goldberg, Michael Schapira
SIGCOMM2
2013 The Diffusion of Networking Technologies
abstract
There has been significant interest in the networking community on the impact of cascade effects on the diffusion of networking technology upgrades in the Internet. Thinking of the global Internet as a graph, where each node represents an economically-motivated Internet Service Provider (ISP), a key problem is to determine the smallest set of nodes that can trigger a cascade that causes every other node in the graph to adopt the protocol. We design the first approximation algorithm with a provable performance guarantee for this problem, in a model that captures the following key issue: a node's decision to upgrade should be influenced by the decisions of the remote nodes it wishes to communicate with. Given an internetwork G(V, E) and threshold function θ, we assume that node u activates (upgrades to the new technology) when it is adjacent to a connected component of active nodes in G of size exceeding node u's threshold θ(u). Our objective is to choose the smallest set of nodes that can cause the rest of the graph to activate. Our main contribution is an approximation algorithm based on linear programming, which we complement with computational hardness results and a near-optimum integrality gap Our algorithm, which does not rely on submodular optimization techniques, also highlights the substantial algorithmic difference between our problem and similar questions studied in the context of social networks.
Sharon Goldberg, Zhenming Liu
SODA1
2012 Sequential Aggregate Signatures with Lazy Verification from Trapdoor Permutations - (Extended Abstract)
Kyle Brogle, Sharon Goldberg, Leonid Reyzin
ASIACRYPT2
2012 Brief announcement: network-destabilizing attacks
abstract
We provide an explanation for the observed stability of today's Internet in the face of common configuration errors and attacks.
Robert Lychev, Sharon Goldberg, Michael Schapira
PODC2
2011 Let the market drive deployment: a strategy for transitioning to BGP security
abstract
With a cryptographic root-of-trust for Internet routing(RPKI [17]) on the horizon, we can finally start planning the deployment of one of the secure interdomain routing protocols proposed over a decade ago (Secure BGP [22], secure origin BGP [37]). However, if experience with IPv6 is any indicator, this will be no easy task. Security concerns alone seem unlikely to provide sufficient local incentive to drive the deployment process forward. Worse yet, the security benefits provided by the S*BGP protocols do not even kick in until a large number of ASes have deployed them.
Phillipa Gill, Michael Schapira, Sharon Goldberg
SIGCOMM3
2011 Fine-grained latency and loss measurements in the presence of reordering
abstract
Modern trading and cluster applications require microsecond latencies and almost no losses in data centers. This paper introduces an algorithm called FineComb that can estimate fine-grain end-to-end loss and latency measurements between edge routers in these data center networks. Such a mechanism can allow managers to distinguish between latencies and loss singularities caused by servers and those caused by the network. Compared to prior work, such as Lossy Difference Aggregator (LDA), that focused on switch-level latency measurements, the requirement of end-to-end latency measurements introduces the challenge of reordering that occurs commonly in IP networks due to churn. The problem is even more acute in switches across data center networks that employ multipath routing algorithms to exploit the inherent path diversity. Without proper care, a loss estimation algorithm can confound loss and reordering; further, any attempt to aggregate delay estimates in the presence of reordering results in severe errors. FineComb deals with these problems using order-agnostic packet digests and a simple new idea we call stash recovery. Our evaluation demonstrates that FineComb can provide orders of magnitude better accuracy in loss and delay estimates in the presence of reordering compared to LDA.
Myungjin Lee, Sharon Goldberg, Ramana Rao Kompella, George Varghese
SIGMETRICS2
2010 How secure are secure interdomain routing protocols
abstract
In response to high-profile Internet outages, BGP security variants have been proposed to prevent the propagation of bogus routing information. To inform discussions of which variant should be deployed in the Internet, we quantify the ability of the main protocols (origin authentication, soBGP, S-BGP, and data-plane verification) to blunt traffic-attraction attacks; i.e., an attacker that deliberately attracts traffic to drop, tamper, or eavesdrop on packets.
Sharon Goldberg, Michael Schapira, Peter Hummon, Jennifer Rexford
SIGCOMM1
2008 Protocols and Lower Bounds for Failure Localization in the Internet
Boaz Barak, Sharon Goldberg, David Xiao
EUROCRYPT2
2008 Rationality and traffic attraction: incentives for honest path announcements in bgp
abstract
We study situations in which autonomous systems (ASes) may have incentives to send BGP announcements differing from the AS-level paths that packets traverse in the data plane. Prior work on this issue assumed that ASes seek only to obtain the best possible outgoing path for their traffic. In reality, other factors can influence a rational AS's behavior. Here we consider a more natural model, in which an AS is also interested in attracting incoming traffic (e.g., because other ASes pay it to carry their traffic). We ask what combinations of BGP enhancements and restrictions on routing policies can ensure that ASes have no incentive to lie about their data-plane paths. We find that protocols like S-BGP alone are insufficient, but that S-BGP does suffice if coupled with additional (quite unrealistic) restrictions on routing policies. Our game-theoretic analysis illustrates the high cost of ensuring that the ASes honestly announce data-plane paths in their BGP path announcements.
Sharon Goldberg, Shai Halevi, Aaron D. Jaggard, Vijay Ramachandran, Rebecca N. Wright
SIGCOMM1
2008 Path-quality monitoring in the presence of adversaries
abstract
Edge networks connected to the Internet need effective monitoring techniques to drive routing decisions and detect violations of Service Level Agreements (SLAs). However, existing measurement tools, like ping, traceroute, and trajectory sampling, are vulnerable to attacks that can make a path look better than it really is. In this paper, we design and analyze path-quality monitoring protocols that reliably raise an alarm when the packet-loss rate and delay exceed a threshold, even when an adversary tries to bias monitoring results by selectively delaying, dropping, modifying, injecting, or preferentially treating packets.
Sharon Goldberg, David Xiao, Eran Tromer, Boaz Barak, Jennifer Rexford
SIGMETRICS1
2007 Source-Matched Spreading Codes for Optical CDMA
abstract
Puncturing is studied as a physical layer mechanism for efficiently transmitting datastreams containing bits of unequal priority via wavelength-time optical code-division multiple access. Puncturing increases system capacity, while ensuring that important bits are received with low bit-error rate
Sharon Goldberg, Varghese Baby, Paul R. Prucnal
IEEE Trans. Commun.1
2007 On the Teletraffic Capacity of Optical CDMA
abstract
The capacity of an optical code-division multi-access (CDMA) [OCDMA] network has traditionally been defined as the number of continuously transmitting circuits supported by the network. In this paper, we use teletraffic models to determine the teletraffic capacity of a circuit-switched OCDMA network where circuits carry bursty traffic. Our analysis is independent of the OCDMA implementation or spreading code. In conventional networks, e.g., a wavelength-routed network (WRN), new circuits are blocked when all wavelengths are occupied. In OCDMA when the number of codewords exceeds number of network subscribers, new circuits need not be blocked. Instead, capacity is limited by multiple access interference: when the number of actively transmitting circuits becomes excessive, the bit-error rate (BER) of all circuits on the network degrades, causing an outage. We find that through statistical multiplexing, the capacity of OCDMA exceeds that of a WRN except when circuit activity is very high while the constraints on outages are more stringent than those on blocking. In such cases, we show how OCDMA with call admission control can be used to match or exceed the capacity of a WRN. Overall, our analysis shows that OCDMA is well suited to applications when conventional blocking is undesirable, and/or circuits carry bursty traffic.
Sharon Goldberg, Paul R. Prucnal
IEEE Trans. Commun.1