In-Band OAM Frank Brockners, Shwetha Bhandari, Sashank Dara, Carlos Pignataro (Cisco) Hannes Gedler (rtbrick) Steve Youell (JMPC) John Leddy (Comcast)

Slides:



Advertisements
Similar presentations
Request Dispatching for Cheap Energy Prices in Cloud Data Centers
Advertisements

SpringerLink Training Kit
Luminosity measurements at Hadron Colliders
From Word Embeddings To Document Distances
Choosing a Dental Plan Student Name
Virtual Environments and Computer Graphics
Chương 1: CÁC PHƯƠNG THỨC GIAO DỊCH TRÊN THỊ TRƯỜNG THẾ GIỚI
THỰC TIỄN KINH DOANH TRONG CỘNG ĐỒNG KINH TẾ ASEAN –
D. Phát triển thương hiệu
NHỮNG VẤN ĐỀ NỔI BẬT CỦA NỀN KINH TẾ VIỆT NAM GIAI ĐOẠN
Điều trị chống huyết khối trong tai biến mạch máu não
BÖnh Parkinson PGS.TS.BS NGUYỄN TRỌNG HƯNG BỆNH VIỆN LÃO KHOA TRUNG ƯƠNG TRƯỜNG ĐẠI HỌC Y HÀ NỘI Bác Ninh 2013.
Nasal Cannula X particulate mask
Evolving Architecture for Beyond the Standard Model
HF NOISE FILTERS PERFORMANCE
Electronics for Pedestrians – Passive Components –
Parameterization of Tabulated BRDFs Ian Mallett (me), Cem Yuksel
L-Systems and Affine Transformations
CMSC423: Bioinformatic Algorithms, Databases and Tools
Some aspect concerning the LMDZ dynamical core and its use
Bayesian Confidence Limits and Intervals
实习总结 (Internship Summary)
Current State of Japanese Economy under Negative Interest Rate and Proposed Remedies Naoyuki Yoshino Dean Asian Development Bank Institute Professor Emeritus,
Front End Electronics for SOI Monolithic Pixel Sensor
Face Recognition Monday, February 1, 2016.
Solving Rubik's Cube By: Etai Nativ.
CS284 Paper Presentation Arpad Kovacs
انتقال حرارت 2 خانم خسرویار.
Summer Student Program First results
Theoretical Results on Neutrinos
HERMESでのHard Exclusive生成過程による 核子内クォーク全角運動量についての研究
Wavelet Coherence & Cross-Wavelet Transform
yaSpMV: Yet Another SpMV Framework on GPUs
Creating Synthetic Microdata for Higher Educational Use in Japan: Reproduction of Distribution Type based on the Descriptive Statistics Kiyomi Shirakawa.
MOCLA02 Design of a Compact L-­band Transverse Deflecting Cavity with Arbitrary Polarizations for the SACLA Injector Sep. 14th, 2015 H. Maesaka, T. Asaka,
Hui Wang†*, Canturk Isci‡, Lavanya Subramanian*,
Fuel cell development program for electric vehicle
Overview of TST-2 Experiment
Optomechanics with atoms
داده کاوی سئوالات نمونه
Inter-system biases estimation in multi-GNSS relative positioning with GPS and Galileo Cecile Deprez and Rene Warnant University of Liege, Belgium  
ლექცია 4 - ფული და ინფლაცია
10. predavanje Novac i financijski sustav
Wissenschaftliche Aussprache zur Dissertation
FLUORECENCE MICROSCOPY SUPERRESOLUTION BLINK MICROSCOPY ON THE BASIS OF ENGINEERED DARK STATES* *Christian Steinhauer, Carsten Forthmann, Jan Vogelsang,
Particle acceleration during the gamma-ray flares of the Crab Nebular
Interpretations of the Derivative Gottfried Wilhelm Leibniz
Advisor: Chiuyuan Chen Student: Shao-Chun Lin
Widow Rockfish Assessment
SiW-ECAL Beam Test 2015 Kick-Off meeting
On Robust Neighbor Discovery in Mobile Wireless Networks
Chapter 6 并发:死锁和饥饿 Operating Systems: Internals and Design Principles
You NEED your book!!! Frequency Distribution
Y V =0 a V =V0 x b b V =0 z
Fairness-oriented Scheduling Support for Multicore Systems
Climate-Energy-Policy Interaction
Hui Wang†*, Canturk Isci‡, Lavanya Subramanian*,
Ch48 Statistics by Chtan FYHSKulai
The ABCD matrix for parabolic reflectors and its application to astigmatism free four-mirror cavities.
Measure Twice and Cut Once: Robust Dynamic Voltage Scaling for FPGAs
Online Learning: An Introduction
Factor Based Index of Systemic Stress (FISS)
What is Chemistry? Chemistry is: the study of matter & the changes it undergoes Composition Structure Properties Energy changes.
THE BERRY PHASE OF A BOGOLIUBOV QUASIPARTICLE IN AN ABRIKOSOV VORTEX*
Quantum-classical transition in optical twin beams and experimental applications to quantum metrology Ivano Ruo-Berchera Frascati.
The Toroidal Sporadic Source: Understanding Temporal Variations
FW 3.4: More Circle Practice
ارائه یک روش حل مبتنی بر استراتژی های تکاملی گروه بندی برای حل مسئله بسته بندی اقلام در ظروف
Decision Procedures Christoph M. Wintersteiger 9/11/2017 3:14 PM
Limits on Anomalous WWγ and WWZ Couplings from DØ
Presentation transcript:

In-Band OAM Frank Brockners, Shwetha Bhandari, Sashank Dara, Carlos Pignataro (Cisco) Hannes Gedler (rtbrick) Steve Youell (JMPC) John Leddy (Comcast) IETF 96 – RTGWG; July 20th, 2016 draft-brockners-proof-of-transit-01.txt draft-brockners-inband-oam-requirements-01.txt draft-brockners-inband-oam-data-01.txt draft-brockners-inband-oam-transport-01.txt

How to send OAM information in packet networks? “On-Board Unit” Speed control by police car In-band OAM OAM traffic embedded in the data traffic but not part of the payload of the packet OAM “effected by data traffic” Example: IPv4 route recording Out-of-band OAM OAM traffic is sent as dedicated traffic, independent from the data traffic (“probe traffic”) OAM “not effected by data traffic” Examples: Ethernet CFM (802.1ag), Ping, Traceroute Note the difference to transport OAM (SDH/SONET): In SONET/SDH there is a constant flow of frames OAM is a bit-stream/data between the data encoding sublayer and the physical media and present in every frame, but not part of the data payload This mode of OAM transport is often referred to as “out of band”, because OAM has it’s own “channel” – but still resides side by side with the payload data (if present)

In-Band/Passive OAM - Motivation Multipath Forwarding – debug ECMP networks Service/Path Verification – prove that traffic follows a pre-defined path Service/Quality Assurance – Prove traffic SLAs, as opposed to probe- traffic SLAs; Overlay/Underlay Derive Traffic Matrix Custom/Service Level Telemetry “Most large ISP's prioritize Speedtest traffic and I would even go as far to say they probably route it faster as well to keep ping times low.” Source: https://www.reddit.com/r/AskTechnology/comments/2i1nxc/ can_i_trust_my_speedtestnet_results_when_my_isp/

What if you could collect operational meta-data within your traffic? Example use-cases... Path Tracing for ECMP networks Service/Path Verification Derive Traffic Matrix SLA proof: Delay, Jitter, Loss Custom data: Geo-Location,.. Meta-data required... Node-ID, ingress i/f, egress i/f Proof of Transit (random, cumulative) Node-ID Sequence numbers, Timestamps Custom meta-data

In-Band OAM iOAM domain Gather telemetry and OAM information along the path within the data packet, as part of an existing/additional header No extra probe-traffic (as with ping, trace, ipsla) Transport options IPv6: Native v6 HbyH extension header or double-encap VXLAN-GPE: Embedded telemetry protocol header SRv6: Policy-Element (proof-of-transit only) NSH: Type-2 Meta-Data (proof-of-transit only) ... additional encapsulations being considered (incl. IPv4, MPLS) Deployment Domain-ingress, domain-egress, and select devices within a domaininsert/remove/update the extension header Information export via IPFIX/Flexible-Netflow/publish into Kafka Fast-path implementation Timestamp, Timestamp,.. Generic customer data Node-ID, Node-ID,.. Ingress/Egress I/F, .. Sequence number Proof of Transit Hdr OAM Payload iOAM domain

Payload Hdr B A 6 1 C 4 Payload Hdr Payload Hdr Payload Hdr A 1 C 4 Update POT meta-data B Insert POT meta-data 3 6 IPFIX POT Verifier Payload Hdr r=45/c=39 B A 6 1 C 4 Update POT meta-data 4 Payload Hdr A D Payload Hdr 2 Payload Hdr r=45/c=17 A 1 C 4 Payload Hdr r=45/c=0 A 1 POT meta-data Path-tracing data 1 5 C Update POT meta-data

In-Band OAM: Information carried Per node scope Hop-by-Hop information processing Device_Hop_L Node_ID Ingress Interface ID Egress Interface ID Time-Stamp Application Meta Data Set of nodes scope Hop-by-Hop information processing Service Chain Validation (Random, Cumulative) Edge to Edge scope Edge-to-Edge information processing Sequence Number

Tracing Option     0                   1                   2                   3     0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1    +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+    |  Option Type  |  Opt Data Len |IOAM-trace-type| Elements-left |    +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+<-+    |                                                               |  |    |                        Node data List [0]                     |  |    +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+  D    |                                                               |  a    |                        Node data List [1]                     |  t    .                              .                                .  S    +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+  p    |                        Node data List [n-1]                   |  c    |                                                               |  e    +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+  |    |                        Node data List [n]                     |  | 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ |   Hop_Lim     |              node_id                          | |     ingress_if_id             |         egress_if_id          | |                           timestamp                           | |                            app_data                           |

Proof-of-Transit Option 0 1 2 3 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ | Option Type | Opt Data Len | POT type = 0 | reserved | +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+<-+ | Random | | +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ P | Random(contd) | O +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ T | Cumulative | | +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ | | Cumulative (contd) | |

Edge-to-Edge Option 0 1 2 3 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ | Option Type | Opt Data Len | IOAM-E2E-Type | reserved | | E2E Option data format determined by IOAM-E2E-Type | Option Type: 000xxxxxx 8-bit identifier of the type of option. Opt Data Len: 8-bit unsigned integer. Length of the Option Data field of this option, in octets. iOAM-E2E-Type: 8-bit identifier of a particular iOAM E2E variant. 0: E2E option data is 64-bit Per Packet Counter (PPC) used to identify packet loss and reordering. Reserved: 8-bit. (Reserved Octet) Reserved octet for future use.g

Transport Options – IPv6, VXLAN-GPE, SRv6, NSH... IPv6: v6 HbyH extension header VXLAN-GPE: Embedded telemetry protocol header; Combines with NSH etc. SRv6: In-Band OAM TLV in v6 SR-header SRH (proof-of-transit only) NSH: Type-2 Meta-Data (proof-of- transit only) ... more to come: MPLS, IPv4,...

Proof of Transit

Cisco Live 2014 10/2/2017 Consider traffic engineering, policy based routing, service chaining: “How do you prove that traffic follows the suggested path?”

Ensuring Path and/or Service Chain Integrity Approach Meta-data added to all user traffic Based on “Share of a secret” Provisioned by controller over secure channel to segment hops where “proof of transit” is required Updated at every segment hop where proof of transit is required Verifier checks whether collected meta-data allows retrieval of secret “Proof of Transit”: Path verified Controller Secret B A C Verifier X

Solution Approach: Leverage Shamir’s Secret Sharing “A polynomial as secret” Each service is given a point on the curve When the packet travels through each service it collects these points A verifier can reconstruct the curve using the collected points Operations done over a finite field (mod prime) to protect against differential analysis (3,46)  (2,28)  (1,16) “Secret”: 3 𝑥 2 +3𝑥+10 B 3 𝑥 2 +3𝑥+10 A C Verifier X

Running Code: Experimental OpenSource Implementation Open source experimental Implementation: FD.io/VPP (see fd.io) Demo Videos: Google+ In-Band OAM group: https://plus.google.com/u/0/b/112958873072003542518/112958873072003542518/videos?hl=en Youtube In-Band OAM channel: https://www.youtube.com/channel/UC0WJOAKBTrftyosP590RrXw

Next Steps The authors appreciate thoughts, feedback, and text on the content of the documents from the RTGWG WG The authors also value feedback on where to progress the work? Is RTGWG interested in taking on inband OAM and/or the POT work?