EDBT 2026 Demo / reviewers in the wild / expert
David Wolinsky
dblp:13/5827 · also David Isaac Wolinsky
· DBLP profile ↗
26ranked-venue papers
7as first author
0since 2021 · last 2016
0000-0002-6321-7333ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 10 · 3 first-authorSecurity and privacy · 6 · 1 first-authorComputer networks · 4 · 1 first-authorHuman-computer interaction and ubiquitous computing · 4 · 1 first-authorSoftware engineering, systems software and programming languages · 2 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
5 papers |
Network security · 47% Privacy and data protection · 28% Cryptographic primitives and cryptanalysis · 13% | |
| Computer architecture, parallel and distributed computing, and storage systems
7 papers |
Distributed systems · 66% Hardware reliability and fault tolerance · 13% Cloud and datacenter computing · 12% |
Topics — the 23 heaviest of 26, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Network security
anonymity networks |
0.5 | 3 | 2013 | Proactively Accountable Anonymous Messaging in Verdict · USENIX Security Symposium 2013 Hang with your buddies to resist intersection attacks · CCS 2013 Dissent in Numbers: Making Strong Anonymity Scale · OSDI 2012 |
Privacy and data protection
anonymity |
0.2 | 1 | 2016 | AnonRep: Towards Tracking-Resistant Anonymous Reputation · NSDI 2016 |
Privacy and data protection › anonymity
anonymous reputation |
0.2 | 1 | 2016 | AnonRep: Towards Tracking-Resistant Anonymous Reputation · NSDI 2016 |
Cryptographic primitives and cryptanalysis › public-key cryptography
digital signatures |
0.2 | 1 | 2016 | Keeping Authorities "Honest or Bust" with Decentralized Witness Cosigning · IEEE Symposium on Security and Privacy 2016 |
Cryptographic protocols and secure computation › authenticated data structure
transparency log |
0.2 | 1 | 2016 | Keeping Authorities "Honest or Bust" with Decentralized Witness Cosigning · IEEE Symposium on Security and Privacy 2016 |
Hardware reliability and fault tolerance › reliability analysis
correlated failures |
0.2 | 1 | 2014 | Heading Off Correlated Failures through Independence-as-a-Service · OSDI 2014 |
Distributed systems
fault tolerance |
0.2 | 1 | 2014 | Heading Off Correlated Failures through Independence-as-a-Service · OSDI 2014 |
Network security › anonymity networks › anonymous communication
anonymous messaging |
0.2 | 1 | 2013 | Proactively Accountable Anonymous Messaging in Verdict · USENIX Security Symposium 2013 |
Network security
traffic analysis |
0.2 | 1 | 2013 | Hang with your buddies to resist intersection attacks · CCS 2013 |
Distributed systems › peer-to-peer systems
overlay networks |
0.2 | 2 | 2008 | Improving peer connectivity in wide-area overlays of virtual workstations · HPDC 2008 Facilitating the deployment of ad-hoc virtual organizations with integrated social and overlay networks · HPDC 2008 |
High-performance computing
high-throughput computing |
0.1 | 1 | 2012 | PonD: dynamic creation of HTC pool on demand using a decentralized resource discovery system · HPDC 2012 |
Distributed systems › distributed resource management
resource discovery |
0.1 | 1 | 2012 | PonD: dynamic creation of HTC pool on demand using a decentralized resource discovery system · HPDC 2012 |
Cloud and datacenter computing › cloud service models
infrastructure as a service |
0.1 | 1 | 2011 | Experiences with self-organizing, decentralized grids using the grid appliance · HPDC 2011 |
Distributed systems
distributed coordination |
0.1 | 1 | 2009 | On the design of scalable, self-configuring virtual networks · SC 2009 |
Distributed systems
peer-to-peer systems |
0.1 | 1 | 2009 | On the design of scalable, self-configuring virtual networks · SC 2009 |
Distributed systems › distributed system architecture › communication architecture
virtual networks |
0.1 | 1 | 2009 | On the design of scalable, self-configuring virtual networks · SC 2009 |
Distributed systems › grid computing
virtual organizations |
0.1 | 1 | 2008 | Facilitating the deployment of ad-hoc virtual organizations with integrated social and overlay networks · HPDC 2008 |
Distributed systems › consensus
scalable consensus |
0.1 | 1 | 2016 | Keeping Authorities "Honest or Bust" with Decentralized Witness Cosigning · IEEE Symposium on Security and Privacy 2016 |
Privacy and data protection
pseudonymity |
0.0 | 1 | 2013 | Hang with your buddies to resist intersection attacks · CCS 2013 |
Network security › anonymity networks
anonymous communication |
0.0 | 1 | 2012 | Dissent in Numbers: Making Strong Anonymity Scale · OSDI 2012 |
Distributed systems
grid computing |
0.0 | 1 | 2011 | Experiences with self-organizing, decentralized grids using the grid appliance · HPDC 2011 |
Internet architecture and protocols › naming and addressing
IP address management |
0.0 | 1 | 2009 | On the design of scalable, self-configuring virtual networks · SC 2009 |
Internet architecture and protocols › middlebox
network address translation |
0.0 | 1 | 2008 | Improving peer connectivity in wide-area overlays of virtual workstations · HPDC 2008 |
Methods — techniques the papers use, named apart from their topics
signature aggregation · 0.5multisignature aggregation · 0.5cryptographic protocols · 0.2p2p overlay routing · 0.2distributed data store · 0.2trace-based simulation · 0.2cryptographic protocol design · 0.2peer-to-peer overlay · 0.1match-making · 0.1resource provisioning · 0.1decentralized deployment · 0.1structured p2p routing · 0.1social network integration · 0.1overlay networking · 0.1hole punching · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2016 | Building Privacy-Preserving Cryptographic Credentials from Federated Online IdentitiesabstractFederated identity providers, e.g., Facebook and PayPal, offer a convenient means for authenticating users to third-party applications. Unfortunately such cross-site authentications carry privacy and tracking risks. For example, federated identity providers can learn what applications users are accessing; meanwhile, the applications can know the users' identities in reality. John Maheswaran, Daniel Jackowitz, Ennan Zhai, David Wolinsky, Bryan Ford |
CODASPY | 4 |
| 2016 | AnonRep: Towards Tracking-Resistant Anonymous Reputation
Ennan Zhai, David Wolinsky, Ruichuan Chen, Ewa Syta, Chao Teng, Bryan Ford |
NSDI | 2 |
| 2016 | Keeping Authorities "Honest or Bust" with Decentralized Witness CosigningabstractThe secret keys of critical network authorities -- such as time, name, certificate, and software update services -- represent high-value targets for hackers, criminals, and spy agencies wishing to use these keys secretly to compromise other hosts. To protect authorities and their clients proactively from undetected exploits and misuse, we introduce CoSi, a scalable witness cosigning protocol ensuring that every authoritative statement is validated and publicly logged by a diverse group of witnesses before any client will accept it. A statement S collectively signed by W witnesses assures clients that S has been seen, and not immediately found erroneous, by those W observers. Even if S is compromised in a fashion not readily detectable by the witnesses, CoSi still guarantees S's exposure to public scrutiny, forcing secrecy-minded attackers to risk that the compromise will soon be detected by one of the W witnesses. Because clients can verify collective signatures efficiently without communication, CoSi protects clients' privacy, and offers the first transparency mechanism effective against persistent man-in-the-middle attackers who control a victim's Internet access, the authority's secret key, and several witnesses' secret keys. CoSi builds on existing cryptographic multisignature methods, scaling them to support thousands of witnesses via signature aggregation over efficient communication trees. A working prototype demonstrates CoSi in the context of timestamping and logging authorities, enabling groups of over 8,000 distributed witnesses to cosign authoritative statements in under two seconds. Ewa Syta, Iulia Tamas, Dylan Visher, David Wolinsky, Philipp Jovanovic, Linus Gasser, Nicolas Gailly, Ismail Khoffi, Bryan Ford |
IEEE Symposium on Security and Privacy | 4 |
| 2015 | Private Eyes: Secure Remote Biometric AuthenticationabstractWe propose an efficient remote biometric authentication protocol that gives strong protection to the user’s biometric data in case of two common kinds of security breaches: (1) loss or theft of the user’s token (smart card, handheld device, etc.), giving the attacker full access to any secrets embedded within it; (2) total penetration of the server. Only if both client and server are simultaneously compromised is the user’s biometric data vulnerable to exposure. The protocol works by encrypting the user’s biometric template in a way that allows it to be used for authentication without being decrypted by either token or server. Further, the encrypted template never leaves the token, and only the server has the information that would enable it to be decrypted. We have implemented our protocol using two iris recognition libraries and evaluated its performance. The overall efficiency and recognition performance is essentially the same compared to an unprotected biometric system. Ewa Syta, Michael J. Fischer, David Wolinsky, Avi Silberschatz, Gina Gallegos-García, Bryan Ford |
SECRYPT | 3 |
| 2014 | Heading Off Correlated Failures through Independence-as-a-Service
Ennan Zhai, Ruichuan Chen, David Wolinsky, Bryan Ford |
OSDI | 3 |
| 2014 | Security Analysis of Accountable Anonymity in DissentabstractUsers often wish to communicate anonymously on the Internet, for example, in group discussion or instant messaging forums. Existing solutions are vulnerable to misbehaving users, however, who may abuse their anonymity to disrupt communication. Dining Cryptographers Networks (DC-nets) leave groups vulnerable to denial-of-service and Sybil attacks; mix networks are difficult to protect against traffic analysis; and accountable voting schemes are unsuited to general anonymous messaging. dissent is the first general protocol offering provable anonymity and accountability for moderate-size groups, while efficiently handling unbalanced communication demands among users. We present an improved and hardened dissent protocol, define its precise security properties, and offer rigorous proofs of these properties. The improved protocol systematically addresses the delicate balance between provably hiding the identities of well-behaved users, while provably revealing the identities of disruptive users, a challenging task because many forms of misbehavior are inherently undetectable. The new protocol also addresses several nontrivial attacks on the original dissent protocol stemming from subtle design flaws. Ewa Syta, Henry Corrigan-Gibbs, Shu-Chun Weng, David Wolinsky, Bryan Ford, Aaron Johnson 0001 |
ACM Trans. Inf. Syst. Secur. | 4 |
| 2013 | Hang with your buddies to resist intersection attacksabstractSome anonymity schemes might in principle protect users from pervasive network surveillance--but only if all messages are independent and unlinkable. Users in practice often need pseudonymity--sending messages intentionally linkable to each other but not to the sender--but pseudonymity in dynamic networks exposes users to intersection attacks. We present Buddies, the first systematic design for intersection attack resistance in practical anonymity systems. Buddies groups users dynamically into buddy sets, controlling message transmission to make buddies within a set behaviorally indistinguishable under traffic analysis. To manage the inevitable tradeoffs between anonymity guarantees and communication responsiveness, Buddies enables users to select independent attack mitigation policies for each pseudonym. Using trace-based simulations and a working prototype, we find that Buddies can guarantee non-trivial anonymity set sizes in realistic chat/microblogging scenarios, for both short-lived and long-lived pseudonyms. David Wolinsky, Ewa Syta, Bryan Ford |
CCS | 1 |
| 2013 | Crypto-Book: an architecture for privacy preserving online identitiesabstractThrough cross-site authentication schemes such as OAuth and OpenID, users increasingly rely on popular social networking sites for their digital identities--but use of these identities brings privacy and tracking risks. We propose Crypto-Book, an extension to existing digital identity infrastructures that offers privacy-preserving, digital identities through the use of public key cryptography and ring signatures. Crypto-Book builds a privacy-preserving cryptographic layer atop existing social network identities, via third-party key servers that convert social network identities into public/private key-pairs on demand. Using linkable ring signatures, these key-pairs along with the public keys of other identities create unique pseudonyms untraceable back to the owner yet can resist anonymous abuse. John Maheswaran, David Wolinsky, Bryan Ford |
HotNets | 2 |
| 2013 | Proactively Accountable Anonymous Messaging in Verdict
Henry Corrigan-Gibbs, David Wolinsky, Bryan Ford |
USENIX Security Symposium | 2 |
| 2012 | PonD: dynamic creation of HTC pool on demand using a decentralized resource discovery systemabstractHigh Throughput Computing (HTC) platforms aggregate heterogeneous resources to provide vast amounts of computing power over a long period of time. Typical HTC systems, such as Condor and BOINC, rely on central managers for resource discovery and scheduling. While this approach simplifies deployment, it requires careful system configuration and management to ensure high availability and scalability. In this paper, we present a novel approach that integrates a self-organizing P2P overlay for scalable and timely discovery of resources with unmodified client/server job scheduling middleware in order to create HTC virtual resource Pools on Demand (PonD). This approach decouples resource discovery and scheduling from job execution/monitoring - a job submission dynamically generates an HTC platform based upon resources discovered through match-making from a large "sea" of resources in the P2P overlay and forms a "PonD" capable of leveraging unmodified HTC middleware for job execution and monitoring. We show that job scheduling time of our approach scales with O(log N), where N is the number of resources in a pool, through first-order analytical models and large-scale simulation results. To verify the practicality of PonD, we have implemented a prototype using Condor (called C-PonD), a structured P2P overlay, and a PonD creation module. Experimental results with the prototype in two WAN environments (PlanetLab and the FutureGrid cloud computing testbed) demonstrates the utility of C-PonD as a HTC approach without relying on a central repository for maintaining all resource information. Though the prototype is based on Condor, the decoupled nature of the system components - decentralized resource discovery, PonD creation, job execution/monitoring - is generally applicable to other grid computing middleware systems. Kyungyong Lee 0001, David Wolinsky, Renato J. O. Figueiredo |
HPDC | 2 |
| 2012 | Dissent in Numbers: Making Strong Anonymity Scale
David Wolinsky, Henry Corrigan-Gibbs, Bryan Ford, Aaron Johnson 0001 |
OSDI | 1 |
| 2011 | SOLARE: Self-Organizing Latency-Aware Resource EnsembleabstractThis paper proposes and evaluates Self-Organizing Latency-Aware Resource Ensemble (SOLARE), a peer-to-peer self-organizing and self-managing cluster system based upon network coordinates and utility functions. In contrast to previous works, SOLARE is a fully decentralized clustering algorithm without any central units such as servers, super peers, cluster heads or landmarks. Furthermore, SOLARE allows for adaptability to dynamic network changes by monitoring the utility of a cluster and migrating nodes to other higher-utility clusters when the utility of an existing cluster is low. Quantitative, simulation-driven evaluations show that SOLARE is able to satisfy user demands expressed by utility functions that integrate system parameters in terms of intra cluster latencies and the number of cluster members. Also, we verify the ability of SOLARE to adapt to dynamic network changes through simulation based experiments that consider the number of nodes which migrate into another cluster and average utility value as nodes join SOLARE. Heungsik Eom, David Wolinsky, Renato J. O. Figueiredo |
HPCC | 2 |
| 2011 | Experiences with self-organizing, decentralized grids using the grid applianceabstract"Give a man a fish, feed him for a day. Teach a man to fish, feed him for a lifetime" -- Lau Tzu Large-scale grid computing projects such as TeraGrid and Open Science Grid provide researchers vast amounts of compute resources but with requirements that could limit access, results delayed due to potentially long job queues, and environments and policies that might affect a user's work flow. In many scenarios and in particular with the advent of Infrastructure-as-a-Service (IaaS) cloud computing, individual users and communities can benefit from less restrictive, dynamic systems that include a combination of local resources and on-demand resources provisioned by one or more IaaS provider. These types of scenarios benefit from flexibility in deploying resources, remote access, and environment configuration. David Wolinsky, Renato J. O. Figueiredo |
HPDC | 1 |
| 2010 | SocialDNS: A decentralized naming service for collaborative P2P VPNsabstractThe ability to define domain names for resources in a collaborative virtual organization is usually reserved to network administrators through centralized domain name servers. We propose SocialDNS, a decentralized, naming service that gives individual collaborators the power to choose the domain nam Pierre St. Juste, David Wolinsky, Kyungyong Lee 0001, P. Oscar Boykin, Renato J. O. Figueiredo |
CollaborateCom | 2 |
| 2010 | On the design of autonomic, decentralized VPNsabstractDecentralized and P2P (peer-to-peer) VPNs (virtual private networks) have recently become quite popular for connecting users in small to medium collaborative environments, such as academia, businesses, and homes. In the realm of VPNs, there exist centralized, decentralized, and P2P solutions. Centra David Wolinsky, Kyungyong Lee 0001, P. Oscar Boykin, Renato J. O. Figueiredo |
CollaborateCom | 1 |
| 2010 | Towards Collaborative Research and Education in Computer Architecture with the Archer SystemabstractArcher is a simulation environment and computing resource for research in the field of computer architecture. Archer facilitates the creation of an on-demand computing grid, the deployment of simulation tools on this grid and the batch scheduling of large-scale simulation jobs on this grid. These features enable the use of Archer for simulation-based research as well as dissemination of tools and results among multiple research groups. This paper overviews and reports our experience in the use of Archer for collaborative research and for education. Girish Venkatasubramanian, David Wolinsky, Renato J. O. Figueiredo |
MASCOTS | 2 |
| 2010 | Addressing the P2P Bootstrap Problem for Small Overlay NetworksabstractPeer-to-Peer (P2P) overlays provide a framework for building distributed applications consisting of few to many resources with features including self-configuration, scalability, and resilience to node failures. Such systems have been successfully adopted in large-scale Internet services for content delivery networks, file sharing, and data storage. In small-scale systems, they can be useful to address privacy concerns as well as support for network applications that lack dedicated servers. The bootstrap problem, finding an existing peer in the overlay, remains a challenge to enabling these services for small-scale P2P systems. In large networks, the solution to the bootstrap problem has been the use of dedicated services, though creating and maintaining these systems requires expertise and resources, which constrain their usefulness and make them unappealing for small-scale systems. This paper surveys and summarizes requirements that allow peers potentially constrained by network connectivity to bootstrap small-scale overlays through the use of existing public overlays. In order to support bootstrapping, a public overlay must support the following requirements: a method for reflection in order to obtain publicly reachable addresses, so peers behind network address translators and firewalls can receive incoming connection requests; communication relaying to share public addresses and communicate when direct communication is not feasible; and rendezvous for discovering remote peers, when the overlay lacks stable membership. After presenting a survey of various public overlays, we identify two overlays that match the requirements: XMPP overlays, such as Google Talk and Live Journal Talk, and Brunet, a structured overlay based upon Symphony. We present qualitative experiences with prototypes that demonstrate the ability to bootstrap small-scale private structured overlays from public Brunet or XMPP infrastructures. David Wolinsky, Pierre St. Juste, P. Oscar Boykin, Renato J. O. Figueiredo |
Peer-to-Peer Computing | 1 |
| 2010 | SocialVPN: Enabling wide-area collaboration with integrated social and overlay networks
Pierre St. Juste, David Wolinsky, P. Oscar Boykin, Michael J. Covington, Renato J. O. Figueiredo |
Comput. Networks | 2 |
| 2009 | On the design of scalable, self-configuring virtual networksabstractVirtual networks (VNs) provide methods that simplify resource management, deal with connectivity constraints, and support legacy applications in distributed systems, by enabling global addressability of VN-connected machines through either a common layer 2 Ethernet or a NAT-free layer 3 IP network. This paper presents a novel VN design that supports dynamic, seamless addition of new resources with emphasis on scalability in a unified private IP address space. Key features of this system are: (1) Scalable connectivity via a P2P overlay with the ability to bypass overlay routing in LAN communications, (2) support for static and dynamic address allocation in conjunction with virtual nameservers through a distributed data store, and (3) support for transparent migration of IP endpoints across widearea networks. David Wolinsky, Yonggang Liu 0004, Pierre St. Juste, Girish Venkatasubramanian, Renato J. O. Figueiredo |
SC | 1 |
| 2008 | Archer: A Community Distributed Computing Infrastructure for Computer Architecture Research and Education
Renato J. O. Figueiredo, P. Oscar Boykin, José A. B. Fortes, Tao Li 0006, Jie-Kwon Peir, David Wolinsky, Lizy Kurian John, David R. Kaeli, David J. Lilja, Sally A. McKee, Gokhan Memik, Alain J. Roy, Gary S. Tyson |
CollaborateCom | 6 |
| 2008 | Middleware Integration and Deployment Strategies for Cyberinfrastructures
Sebastien Goasguen, Krishna Madhavan, David Wolinsky, Renato J. O. Figueiredo, Jaime Frey, Alain J. Roy, Paul Ruth, Dongyan Xu |
GPC | 3 |
| 2008 | Facilitating the deployment of ad-hoc virtual organizations with integrated social and overlay networksabstractDeploying virtual organizations (VOs) is difficult for small- and medium-scale collaborations: the overheads in establishing and managing trust, and in deploying and managing computational resources distributed across multiple organizations are daunting to many potential users, presenting a barrier to entry that significantly hinders wider deployment of VOs. We advocate an approach where social networking and self-configuring overlay virtual networks are integrated in a novel way that allows simple deployment and management of ad-hoc infrastructures for VOs. There are three central principles in our approach: (1) user relationships which have been increasingly recorded in social networking systems provide the opportunity to bootstrap trust relationships; (2) connections established at a social networking layer can efficiently be mapped to the IP layer of virtual network overlays to support existing TCP/IP applications for collaboration and resource sharing while maintaining security against untrusted parties; and (3) systems integrating social and virtual networks can be self-configuring, enabling deployment of collaborative infrastructures by non-experts. We discuss motivations for this approach, describe a prototype implementation which integrates the Facebook social network and the IPOP overlay network, and discuss a use case scenario towards ad-hoc social cycle-sharing virtual Condor pools. Renato J. O. Figueiredo, P. Oscar Boykin, Pierre St. Juste, David Wolinsky |
HPDC | 4 |
| 2008 | Improving peer connectivity in wide-area overlays of virtual workstationsabstractSelf-configuring virtual networks rely on structured P2P routing to provide seamless connectivity among nodes through overlay routing of virtual IP packets, support decentralized hole-punching to establish bi-directional communication links among nodes behind network address translators, and dynamic configuration of virtual IP addresses. Our experiences with deployments of virtual networks in support of wide-area overlays of virtual workstations (WOWs) reveal that connectivity constraints imposed by symmetric NATs and by Internet route outages often hinder P2P overlay structure maintenance and routability, subsequently limiting the ability of WOWs to deliver high-throughput computing through aggregation of resources in different domains. Arijit Ganguly, P. Oscar Boykin, David Wolinsky, Renato J. O. Figueiredo |
HPDC | 3 |
| 2008 | Provisioning of virtual environments for wide area desktop grids through redirect-on-write distributed file systemabstractWe describe and evaluate a thin client solution for desktop grid computing based on virtual machine appliances whose images are fetched on-demand and on a per-block basis over wide-area networks. The approach uses a distributed file system redirection mechanism which enables the use of unmodified NFS clients/servers and local buffering of file system modifications during the appliances lifetime. The file system redirection technique is achieved through user-level proxies, and can be integrated with virtual private network overlays to provide transparent access to image servers even if they are behind firewalls. We have implemented and evaluated a prototype system which allows thin client diskless appliances to boot over a proxy VM bringing on-demand only a small fraction of the appliance image (16 MB out of WOMB) and showing low runtime overhead for CPU-intensive applications. The paper also presents decentralized mechanisms to support seamless image version upgrades. Vineet Chadha, David Wolinsky, Renato J. O. Figueiredo |
IPDPS | 2 |
| 2008 | Simplifying resource sharing in voluntary grid computing with the grid applianceabstractResearch projects in many fields are increasingly reliant on the use of computer-based simulation and computing grids. Many projects have successfully leveraged voluntary computing infrastructures by developing and distributing "@home" applications using the BOINC framework. Through generous contributions from the general public, these systems now have a computing backbone on which to have their data processed or simulations run. A shortcoming of such systems is that most users are often limited to contributing resources and few users are capable of developing or porting their own applications in order to use these resources. While many users are satisfied with receiving points (an intangible good) in return for their contribution, the need to port applications presents a barrier to entry to many other users who can potentially benefit from using the voluntary resources. In this paper, we describe enhancements made to the "grid appliance", a virtual machine based system which enables an execution environment in which users are given the opportunity to voluntarily share (providing and using) resources and run unmodified x86/Linux applications. Voluntary grids introduce a host of issues to tackle, most importantly getting users involved quickly. With that in mind, the grid appliance provides many tools for making a user-friendly environment for users, developers, and administrators. This paper summarizes the challenges of getting users involved, reducing the overhead for administrators, and describes the solutions used in the grid appliance. David Wolinsky, Renato J. O. Figueiredo |
IPDPS | 1 |
| 2007 | Decentralized Dynamic Host Configuration in Wide-Area Overlays of Virtual WorkstationsabstractWide-area overlays of virtual workstations (WOWs) have been shown to provide excellent infrastructure for deploying high throughput computing environments on commodity desktop machines by (1) offering scalability to a large number of nodes, (2) facilitating addition of new nodes even if they are behind NATs/firewalls and (3) supporting unmodified applications and middleware. However, deployment of WOWs from scratch still requires setting up a bootstrapping network and managing centralized DHCP servers for IP address management. In this paper we describe novel techniques that allow multiple users to create independent, isolated virtual IP namespaces for their WOWs without requiring a dedicated bootstrapping infrastructure, and to provision dynamic host configuration (e.g. IP addresses) to unmodified DHCP clients without requiring the setup and management of a central DHCP server. We give qualitative and quantitative arguments to establish the feasibility of our approach. Arijit Ganguly, David Wolinsky, P. Oscar Boykin, Renato J. O. Figueiredo |
IPDPS | 2 |