SlideShare ist ein Scribd-Unternehmen logo
1 von 14
Downloaden Sie, um offline zu lesen
Network Infrastructure for Academic IC CAD Environments




                       EUROCON 2011 - E-Learning II

   Network Infrastructure for Academic IC
            CAD Environments
Pedro Coke, Cândido Duarte, André Cardoso, Vítor Grade Tavares, Pedro Guedes de Oliveira

                                          April 29, 2011




                              Microelectronics Students’ Group
                  DEEC - Departamento de Engenharia Electrotécnica e de Computadores
                         FEUP - Faculdade de Engenharia, Universidade do Porto
                          Rua Dr. Roberto Frias, s/n, 4200-465 Porto, Portugal
                              Sala I325, Telephone: 225574199 - Ext 3230
                               web: usgroup.eu   e-mail: info@usgroup.eu



                                        April 29, 2011      1/14
Network Infrastructure for Academic IC CAD Environments

                                                                      Introduction



At the Microelectronics Students’ Group,
students are able to take part in the
development of IC projects


            The group provides a well-suited working environment for
            IC CAD design
            Over time, however, more complex projects demanded a
            more reliable and secure computer network infrastructure.




                          April 29, 2011      2/14
Network Infrastructure for Academic IC CAD Environments

                                                                         Introduction

This need was approached through an extracurricular
activity
The project gathered students in Computer Sciences and Electronics and
Computers Engineering, interested in developing knowledge on network
security, allowing them to:
  · Pursue their own topics of interest
  · Autonomously explore solutions to fulfil requirements
  · Consolidate knowledge through hands-on experience




                             April 29, 2011      3/14
Network Infrastructure for Academic IC CAD Environments

                                                                                    Project
                                                                                          Kick-off




The students started by reviewing the current solution in
order to identify existing problems

  · Maintaining software copies on many machines
  · More users than machines available
  · Sensitive information transmitted on public network




                             April 29, 2011      4/14
Network Infrastructure for Academic IC CAD Environments

                                                                                    Project
                                                                                  Requirements




Following this analysis, the project requirements were
defined

  · Centralized user authentication
  · Filesystem distribution throughout the network
      · User storage
      · IC-CAD software
  · Secure infrastructure on insecure network




                             April 29, 2011      5/14
Network Infrastructure for Academic IC CAD Environments

                                                                        Core Services
                                                                                 Authentication




The Kerberos protocol allows secure
authentication over a non-secure network

It relies on symmetric key cryptography to provide
authentication for users and services.

  · MIT Kerberos V
  · All core network services rely on Kerberos for authentication




                              April 29, 2011      6/14
Network Infrastructure for Academic IC CAD Environments

                                                                         Core Services
                                                                               Directory Service



LDAP is an application protocol for
querying and modifying directory services
on the network

Used by host machines to query for users and groups.

  · OpenLDAP server
  · Stores user and group information
  · Secured using Kerberos V




                               April 29, 2011      7/14
Network Infrastructure for Academic IC CAD Environments

                                                                       Core Services
                                                                                          Storage


AFS is a networked filesystem that
provides a location-transparent file name
space

  · OpenAFS server
  · Stores IC-CAD software and users’ homes
  · Uses Kerberos authentication
  · Access control lists (ACL) allow flexible permissions
  · Flexible volume management system with load-balancing




                             April 29, 2011      8/14
Network Infrastructure for Academic IC CAD Environments

                                                                    Single Sign-On



SSO mechanisms allow users to seamlessly authenticate
on all core services

Upon first authentication request, Kerberos issues a
Ticket-Granting-Ticket, which can be used for authentication to other
services without re-entering credentials.

PAM and NSS are used to integrate Kerberos, LDAP and OpenAFS at
login time.




                              April 29, 2011      9/14
Network Infrastructure for Academic IC CAD Environments

                                                                  OS Deployment


Automated installation mechanisms allow
for non-interactive OS deployment.

The used operating system is CentOS, and Anaconda kickstart files allow
for fully automatic installation.

  · Host boots from network
  · Configuration files are copied over the network via SSH
  · Custom profile system to differentiate between hosts
  · Local package mirror to speed up install
  · Host is fully usable at first boot


                              April 29, 2011     10/14
Network Infrastructure for Academic IC CAD Environments

                                                             Network Topology


All hosts are connected via a Gigabit
Ethernet switch to avoid performance
losses

A single computer runs all network services, and is
connected via a 2Gb connection through NIC bonding
to further reduce bottlenecks.

Redundancy through several servers was considered,
but due the lab’s already limited resources only one
server was deployed.



                              April 29, 2011     11/14
Network Infrastructure for Academic IC CAD Environments

                                                                             Conclusion


The implemented infrastructure was deployed in the
Microelectronics Students’ Group laboratory network

Running in production environment for several months without significant
issues, providing a well suited environment for IC design.



A simple security assessment was done using the Nessus
vulnerability scanner, which revealed no faults.




                             April 29, 2011     12/14
Network Infrastructure for Academic IC CAD Environments

                                                                             Conclusion




All the defined project requirements were fulfilled

The team was able to meet the goal of designing and implementing a
network service infrastructure from scratch.

It allowed students to develop knowledge on areas not always thoroughly
explored during courses, with complete autonomy.




                             April 29, 2011     13/14
Network Infrastructure for Academic IC CAD Environments




                                                                 Thank you.


DEEC - Departamento de Engenharia Electrotécnica e de Computadores
FEUP - Faculdade de Engenharia, Universidade do Porto
Rua Dr. Roberto Frias, s/n, 4200-465 Porto, Portugal
Sala I325, Telephone: 225574199 - Ext: 3230
web: usgroup.eu   e-mail: info@usgroup.eu




                          April 29, 2011      14/14

Weitere ähnliche Inhalte

Was ist angesagt?

Resume.2016.03.08
Resume.2016.03.08Resume.2016.03.08
Resume.2016.03.08Zhijie Li
 
Enabling High Level Application Development In The Internet Of Things
Enabling High Level Application Development In The Internet Of ThingsEnabling High Level Application Development In The Internet Of Things
Enabling High Level Application Development In The Internet Of ThingsPankesh Patel
 
Issues in Elliptic Curve Cryptography Implementation - Internetworking Indone...
Issues in Elliptic Curve Cryptography Implementation - Internetworking Indone...Issues in Elliptic Curve Cryptography Implementation - Internetworking Indone...
Issues in Elliptic Curve Cryptography Implementation - Internetworking Indone...Marisa Paryasto
 
Delay Analysis of Layered Video Caching in Crowdsourced Heterogeneous Wireles...
Delay Analysis of Layered Video Caching in Crowdsourced Heterogeneous Wireles...Delay Analysis of Layered Video Caching in Crowdsourced Heterogeneous Wireles...
Delay Analysis of Layered Video Caching in Crowdsourced Heterogeneous Wireles...Behrouz Jedari
 
Impact of Soft Errors in Silicon on Reliability and Availability of Servers
Impact of Soft Errors in Silicon on Reliability and Availability of ServersImpact of Soft Errors in Silicon on Reliability and Availability of Servers
Impact of Soft Errors in Silicon on Reliability and Availability of ServersIshwar Parulkar
 
David Bernard Link
David Bernard LinkDavid Bernard Link
David Bernard Linklremy83
 

Was ist angesagt? (11)

Resume.2016.03.08
Resume.2016.03.08Resume.2016.03.08
Resume.2016.03.08
 
Enabling High Level Application Development In The Internet Of Things
Enabling High Level Application Development In The Internet Of ThingsEnabling High Level Application Development In The Internet Of Things
Enabling High Level Application Development In The Internet Of Things
 
MPG tech law
MPG tech lawMPG tech law
MPG tech law
 
MPG tech law
MPG tech lawMPG tech law
MPG tech law
 
Resume
ResumeResume
Resume
 
Issues in Elliptic Curve Cryptography Implementation - Internetworking Indone...
Issues in Elliptic Curve Cryptography Implementation - Internetworking Indone...Issues in Elliptic Curve Cryptography Implementation - Internetworking Indone...
Issues in Elliptic Curve Cryptography Implementation - Internetworking Indone...
 
Resume
ResumeResume
Resume
 
Delay Analysis of Layered Video Caching in Crowdsourced Heterogeneous Wireles...
Delay Analysis of Layered Video Caching in Crowdsourced Heterogeneous Wireles...Delay Analysis of Layered Video Caching in Crowdsourced Heterogeneous Wireles...
Delay Analysis of Layered Video Caching in Crowdsourced Heterogeneous Wireles...
 
Impact of Soft Errors in Silicon on Reliability and Availability of Servers
Impact of Soft Errors in Silicon on Reliability and Availability of ServersImpact of Soft Errors in Silicon on Reliability and Availability of Servers
Impact of Soft Errors in Silicon on Reliability and Availability of Servers
 
David Bernard Link
David Bernard LinkDavid Bernard Link
David Bernard Link
 
REV2009
REV2009REV2009
REV2009
 

Andere mochten auch

Generation of planar radiographs from 3D anatomical models using the GPU
Generation of planar radiographs from 3D anatomical models using the GPU Generation of planar radiographs from 3D anatomical models using the GPU
Generation of planar radiographs from 3D anatomical models using the GPU thyandrecardoso
 
Generation of planar radiographs from 3D anatomical models using the GPU
Generation of planar radiographs from 3D anatomical models using the GPUGeneration of planar radiographs from 3D anatomical models using the GPU
Generation of planar radiographs from 3D anatomical models using the GPUthyandrecardoso
 
Generation of Planar Radiographs from 3D Anatomical Models Using the GPU
Generation of Planar Radiographs from 3D Anatomical Models Using the GPUGeneration of Planar Radiographs from 3D Anatomical Models Using the GPU
Generation of Planar Radiographs from 3D Anatomical Models Using the GPUthyandrecardoso
 
New microsoft office power point presentation
New microsoft office power point presentationNew microsoft office power point presentation
New microsoft office power point presentationSathish Kumar
 
IMRT: Intensity Modulated Radiotherapy
IMRT: Intensity Modulated RadiotherapyIMRT: Intensity Modulated Radiotherapy
IMRT: Intensity Modulated RadiotherapyShatha M
 
The Six Highest Performing B2B Blog Post Formats
The Six Highest Performing B2B Blog Post FormatsThe Six Highest Performing B2B Blog Post Formats
The Six Highest Performing B2B Blog Post FormatsBarry Feldman
 
The Outcome Economy
The Outcome EconomyThe Outcome Economy
The Outcome EconomyHelge Tennø
 

Andere mochten auch (8)

Generation of planar radiographs from 3D anatomical models using the GPU
Generation of planar radiographs from 3D anatomical models using the GPU Generation of planar radiographs from 3D anatomical models using the GPU
Generation of planar radiographs from 3D anatomical models using the GPU
 
Generation of planar radiographs from 3D anatomical models using the GPU
Generation of planar radiographs from 3D anatomical models using the GPUGeneration of planar radiographs from 3D anatomical models using the GPU
Generation of planar radiographs from 3D anatomical models using the GPU
 
Generation of Planar Radiographs from 3D Anatomical Models Using the GPU
Generation of Planar Radiographs from 3D Anatomical Models Using the GPUGeneration of Planar Radiographs from 3D Anatomical Models Using the GPU
Generation of Planar Radiographs from 3D Anatomical Models Using the GPU
 
New microsoft office power point presentation
New microsoft office power point presentationNew microsoft office power point presentation
New microsoft office power point presentation
 
IMRT: Intensity Modulated Radiotherapy
IMRT: Intensity Modulated RadiotherapyIMRT: Intensity Modulated Radiotherapy
IMRT: Intensity Modulated Radiotherapy
 
IMRT and 3DCRT
IMRT and 3DCRT IMRT and 3DCRT
IMRT and 3DCRT
 
The Six Highest Performing B2B Blog Post Formats
The Six Highest Performing B2B Blog Post FormatsThe Six Highest Performing B2B Blog Post Formats
The Six Highest Performing B2B Blog Post Formats
 
The Outcome Economy
The Outcome EconomyThe Outcome Economy
The Outcome Economy
 

Ähnlich wie Network Infrastructure for Academic IC CAD Environments

Developing Web-based Interactive Teaching System for Core Network Technology ...
Developing Web-based Interactive Teaching System for Core Network Technology ...Developing Web-based Interactive Teaching System for Core Network Technology ...
Developing Web-based Interactive Teaching System for Core Network Technology ...drboon
 
Baltimore NAF Vision
Baltimore NAF VisionBaltimore NAF Vision
Baltimore NAF Visiongerrymark
 
IAAS Implementation to provide OS through Web interface
IAAS Implementation to provide OS through Web interfaceIAAS Implementation to provide OS through Web interface
IAAS Implementation to provide OS through Web interfaceSagar Patel
 
Challenges in cloud computing to enable future internet of things v0.3
Challenges in cloud computing to enable future internet of things v0.3Challenges in cloud computing to enable future internet of things v0.3
Challenges in cloud computing to enable future internet of things v0.3Ignacio M. Llorente
 
Resume: Research Engineer
Resume: Research Engineer Resume: Research Engineer
Resume: Research Engineer Abhishek Singh
 
e-Clouds: a SaaS Marketplace for Scientific Computing
e-Clouds: a SaaS Marketplace for Scientific Computinge-Clouds: a SaaS Marketplace for Scientific Computing
e-Clouds: a SaaS Marketplace for Scientific ComputingMario Jose Villamizar Cano
 
CLOUD ENABLING TECHNOLOGIES.pptx
 CLOUD ENABLING TECHNOLOGIES.pptx CLOUD ENABLING TECHNOLOGIES.pptx
CLOUD ENABLING TECHNOLOGIES.pptxDr Geetha Mohan
 
YonghyunHwang_resume..
YonghyunHwang_resume..YonghyunHwang_resume..
YonghyunHwang_resume..Videoguy
 
Testbed for Heterogeneous Cloud
Testbed for Heterogeneous CloudTestbed for Heterogeneous Cloud
Testbed for Heterogeneous CloudCloudLightning
 
Redesigning the LTE Packet Core
Redesigning the LTE Packet CoreRedesigning the LTE Packet Core
Redesigning the LTE Packet CoreMichelle Holley
 
COM526_Lecture 1.pdf
COM526_Lecture 1.pdfCOM526_Lecture 1.pdf
COM526_Lecture 1.pdfSherefHesham
 
Advanced computer network
Advanced computer networkAdvanced computer network
Advanced computer networkTrinity Dwarka
 

Ähnlich wie Network Infrastructure for Academic IC CAD Environments (20)

Developing Web-based Interactive Teaching System for Core Network Technology ...
Developing Web-based Interactive Teaching System for Core Network Technology ...Developing Web-based Interactive Teaching System for Core Network Technology ...
Developing Web-based Interactive Teaching System for Core Network Technology ...
 
Baltimore NAF Vision
Baltimore NAF VisionBaltimore NAF Vision
Baltimore NAF Vision
 
Resume
ResumeResume
Resume
 
IAAS Implementation to provide OS through Web interface
IAAS Implementation to provide OS through Web interfaceIAAS Implementation to provide OS through Web interface
IAAS Implementation to provide OS through Web interface
 
University of Cagliari
University of CagliariUniversity of Cagliari
University of Cagliari
 
main_phase1 _3.pptx
main_phase1 _3.pptxmain_phase1 _3.pptx
main_phase1 _3.pptx
 
Challenges in cloud computing to enable future internet of things v0.3
Challenges in cloud computing to enable future internet of things v0.3Challenges in cloud computing to enable future internet of things v0.3
Challenges in cloud computing to enable future internet of things v0.3
 
Resume: Research Engineer
Resume: Research Engineer Resume: Research Engineer
Resume: Research Engineer
 
e-Clouds: a SaaS Marketplace for Scientific Computing
e-Clouds: a SaaS Marketplace for Scientific Computinge-Clouds: a SaaS Marketplace for Scientific Computing
e-Clouds: a SaaS Marketplace for Scientific Computing
 
CLOUD ENABLING TECHNOLOGIES.pptx
 CLOUD ENABLING TECHNOLOGIES.pptx CLOUD ENABLING TECHNOLOGIES.pptx
CLOUD ENABLING TECHNOLOGIES.pptx
 
Slideshare
SlideshareSlideshare
Slideshare
 
YonghyunHwang_resume..
YonghyunHwang_resume..YonghyunHwang_resume..
YonghyunHwang_resume..
 
01-06 OCRE Test Suite - Fernandes.pdf
01-06 OCRE Test Suite - Fernandes.pdf01-06 OCRE Test Suite - Fernandes.pdf
01-06 OCRE Test Suite - Fernandes.pdf
 
HARIS NCSU_Resume
HARIS NCSU_ResumeHARIS NCSU_Resume
HARIS NCSU_Resume
 
Feec telecom-nw-softwarization-aug-2015
Feec telecom-nw-softwarization-aug-2015Feec telecom-nw-softwarization-aug-2015
Feec telecom-nw-softwarization-aug-2015
 
Testbed for Heterogeneous Cloud
Testbed for Heterogeneous CloudTestbed for Heterogeneous Cloud
Testbed for Heterogeneous Cloud
 
Redesigning the LTE Packet Core
Redesigning the LTE Packet CoreRedesigning the LTE Packet Core
Redesigning the LTE Packet Core
 
COM526_Lecture 1.pdf
COM526_Lecture 1.pdfCOM526_Lecture 1.pdf
COM526_Lecture 1.pdf
 
ARVIND_BALAKUMAR_Resume
ARVIND_BALAKUMAR_ResumeARVIND_BALAKUMAR_Resume
ARVIND_BALAKUMAR_Resume
 
Advanced computer network
Advanced computer networkAdvanced computer network
Advanced computer network
 

Kürzlich hochgeladen

Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...DianaGray10
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...apidays
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Miguel Araújo
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processorsdebabhi2
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfsudhanshuwaghmare1
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...apidays
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProduct Anonymous
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityPrincipled Technologies
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FMESafe Software
 
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsTop 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsRoshan Dwivedi
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUK Journal
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoffsammart93
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...Martijn de Jong
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesBoston Institute of Analytics
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdflior mazor
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsJoaquim Jorge
 
Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024The Digital Insurer
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...Neo4j
 

Kürzlich hochgeladen (20)

Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsTop 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation Strategies
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 

Network Infrastructure for Academic IC CAD Environments

  • 1. Network Infrastructure for Academic IC CAD Environments EUROCON 2011 - E-Learning II Network Infrastructure for Academic IC CAD Environments Pedro Coke, Cândido Duarte, André Cardoso, Vítor Grade Tavares, Pedro Guedes de Oliveira April 29, 2011 Microelectronics Students’ Group DEEC - Departamento de Engenharia Electrotécnica e de Computadores FEUP - Faculdade de Engenharia, Universidade do Porto Rua Dr. Roberto Frias, s/n, 4200-465 Porto, Portugal Sala I325, Telephone: 225574199 - Ext 3230 web: usgroup.eu e-mail: info@usgroup.eu April 29, 2011 1/14
  • 2. Network Infrastructure for Academic IC CAD Environments Introduction At the Microelectronics Students’ Group, students are able to take part in the development of IC projects The group provides a well-suited working environment for IC CAD design Over time, however, more complex projects demanded a more reliable and secure computer network infrastructure. April 29, 2011 2/14
  • 3. Network Infrastructure for Academic IC CAD Environments Introduction This need was approached through an extracurricular activity The project gathered students in Computer Sciences and Electronics and Computers Engineering, interested in developing knowledge on network security, allowing them to: · Pursue their own topics of interest · Autonomously explore solutions to fulfil requirements · Consolidate knowledge through hands-on experience April 29, 2011 3/14
  • 4. Network Infrastructure for Academic IC CAD Environments Project Kick-off The students started by reviewing the current solution in order to identify existing problems · Maintaining software copies on many machines · More users than machines available · Sensitive information transmitted on public network April 29, 2011 4/14
  • 5. Network Infrastructure for Academic IC CAD Environments Project Requirements Following this analysis, the project requirements were defined · Centralized user authentication · Filesystem distribution throughout the network · User storage · IC-CAD software · Secure infrastructure on insecure network April 29, 2011 5/14
  • 6. Network Infrastructure for Academic IC CAD Environments Core Services Authentication The Kerberos protocol allows secure authentication over a non-secure network It relies on symmetric key cryptography to provide authentication for users and services. · MIT Kerberos V · All core network services rely on Kerberos for authentication April 29, 2011 6/14
  • 7. Network Infrastructure for Academic IC CAD Environments Core Services Directory Service LDAP is an application protocol for querying and modifying directory services on the network Used by host machines to query for users and groups. · OpenLDAP server · Stores user and group information · Secured using Kerberos V April 29, 2011 7/14
  • 8. Network Infrastructure for Academic IC CAD Environments Core Services Storage AFS is a networked filesystem that provides a location-transparent file name space · OpenAFS server · Stores IC-CAD software and users’ homes · Uses Kerberos authentication · Access control lists (ACL) allow flexible permissions · Flexible volume management system with load-balancing April 29, 2011 8/14
  • 9. Network Infrastructure for Academic IC CAD Environments Single Sign-On SSO mechanisms allow users to seamlessly authenticate on all core services Upon first authentication request, Kerberos issues a Ticket-Granting-Ticket, which can be used for authentication to other services without re-entering credentials. PAM and NSS are used to integrate Kerberos, LDAP and OpenAFS at login time. April 29, 2011 9/14
  • 10. Network Infrastructure for Academic IC CAD Environments OS Deployment Automated installation mechanisms allow for non-interactive OS deployment. The used operating system is CentOS, and Anaconda kickstart files allow for fully automatic installation. · Host boots from network · Configuration files are copied over the network via SSH · Custom profile system to differentiate between hosts · Local package mirror to speed up install · Host is fully usable at first boot April 29, 2011 10/14
  • 11. Network Infrastructure for Academic IC CAD Environments Network Topology All hosts are connected via a Gigabit Ethernet switch to avoid performance losses A single computer runs all network services, and is connected via a 2Gb connection through NIC bonding to further reduce bottlenecks. Redundancy through several servers was considered, but due the lab’s already limited resources only one server was deployed. April 29, 2011 11/14
  • 12. Network Infrastructure for Academic IC CAD Environments Conclusion The implemented infrastructure was deployed in the Microelectronics Students’ Group laboratory network Running in production environment for several months without significant issues, providing a well suited environment for IC design. A simple security assessment was done using the Nessus vulnerability scanner, which revealed no faults. April 29, 2011 12/14
  • 13. Network Infrastructure for Academic IC CAD Environments Conclusion All the defined project requirements were fulfilled The team was able to meet the goal of designing and implementing a network service infrastructure from scratch. It allowed students to develop knowledge on areas not always thoroughly explored during courses, with complete autonomy. April 29, 2011 13/14
  • 14. Network Infrastructure for Academic IC CAD Environments Thank you. DEEC - Departamento de Engenharia Electrotécnica e de Computadores FEUP - Faculdade de Engenharia, Universidade do Porto Rua Dr. Roberto Frias, s/n, 4200-465 Porto, Portugal Sala I325, Telephone: 225574199 - Ext: 3230 web: usgroup.eu e-mail: info@usgroup.eu April 29, 2011 14/14