4.4 SDN Management 95
• Switch S 4 is protected against its output link failure, that is, if link
(S 4 , S 2 ) fails, link (S 4 , S 5 ) could be used instead. However, S 4 is not
protected against its immediate upstream node (S 2 ) failure. Because
the backup path (S 4 , S 5 , S 2 , controller) will pass through S 2 .
• Switch S 6 is protected against both its outgoing link and its immediate upstream node failures: If link (S 6 ,S 3 ) or node S 3 fails, the control
traffic of S 3 will be sent over link (S 6 ,S 5 ) and it will not pass through
node S 3 .
Depending on how critical or frequent link failures are versus node
failures in the network, the network operator could assign different
costs to these two kinds of failures, for example, cost 𝛼 for node failure
and cost 𝛽 for link failure. For example, 𝛼 = 𝛽 could be interpreted and
used for scenarios where link and node failures are equally likely – or
when it is equally important to protect the network against both kinds
of failures. This way, the cost of not having protection at a node could
be evaluated at 𝛼 + 𝛽 if the node is not protected at all, at 𝛼 if it is protected only against its outgoing link failure, and at zero if it is protected
against the upstream node failure as well. For those switches directly
connected to the controller, the upstream node protection cannot be
defined (as the immediate upstream node is the controller). For those
nodes, therefore, the assigned cost is zero if they are protected against
their outgoing link failure and is 𝛼 + 𝛽 otherwise.
4.4.4.3 Downstream Versus Upstream Nodes
In this work, we assume that the traditional failure management tools
are deployed in the split-architecture network, that is, there is no
extended signaling mechanism for a node to inform its downstream
nodes of a failure. Therefore, if a switch is disconnected from the
controller (i.e., if there is no backup path programmed in the switch),
then all its downstream nodes will also be disconnected, even if
they are themselves locally protected against their outgoing links or
immediate upstream nodes failures. This means that in evaluating
networks resiliency, more weights should be assigned to nodes closer
to the controller (which is the root of the controller routing tree).
More precisely, the weight of each node should also be proportional
to the number of its downstream nodes.
In Figure 4.14, for example, failure of the link between S 2 and the
controller results in the disconnection of all S 1 , S 2 , S 4 , and S 5 from the
Précédent

- 115/195

Suivant