Aug 2026· Global academic journal of economics and business· Vol 8, pp. 952-961· 0 citations
TL;DR
This review examines how Ethernet Virtual Private Network and Virtual Extensible LAN overlays, operating across routed leaf-spine IP fabrics, can provide a resilient segmentation foundation for that requirement and concludes that EVPN-VXLAN should be treated as a programmable enforcement substrate rather than a security product.
Abstract
Saudi critical data centres are becoming strategic platforms for digital government, industrial automation, cloud services and data-intensive national programmes. Their network architecture must therefore sustain service continuity while constraining lateral movement, isolating failures and producing auditable evidence of policy enforcement. This review examines how Ethernet Virtual Private Network and Virtual Extensible LAN overlays, operating across routed leaf-spine IP fabrics, can provide a resilient segmentation foundation for that requirement. It synthesises protocol standards, security guidance and Saudi regulatory controls published between 2020 and 2025. The analysis distinguishes transport resilience from security isolation, showing that neither equal-cost forwarding nor a large overlay namespace is sufficient without explicit policy, controlled route propagation, authenticated infrastructure, service insertion and tested recovery procedures. It identifies four design principles: keep the underlay simple and failure-bounded; express tenant, application and trust boundaries in separate virtual routing domains; use control-plane learning and suppression mechanisms to reduce unnecessary flooding; and connect segmentation intent to operational telemetry, configuration assurance and incident response. A Saudi-oriented reference architecture is proposed for active-active critical sites, with distributed anycast gateways, multihoming, rapid designated-forwarder recovery, policy groups, controlled inter-site exchange and independent management-plane protection. The review concludes that EVPN-VXLAN should be treated as a programmable enforcement substrate rather than a security product. Its contribution to Vision 2030 depends on governance that links each segment, route and exception to data classification, criticality, recovery objectives and accountable ownership.
Large-scale data center migration within Saudi critical infrastructure is not a conventional relocation of servers and applications. It is a time-bounded transformation of trust boundaries, routing domains, identity dependencies, recovery mechanisms, and operational accountability. During coexistence, legacy and target environments remain interconnected, which expands the attack surface precisely when configuration volume, change velocity, and service uncertainty are highest. This review examines how cyber resilience can be engineered into migration programmes through secure IP fabric segmentation, evidence-led threat containment, and continuity controls aligned with Saudi Vision 2030. An integrative review of peer-reviewed studies, standards, and regulatory documents published from 2020 to 2025 was undertaken. Evidence was synthesised around five analytical themes: migration risk, EVPN-VXLAN segmentation, zero-trust enforcement, containment and recovery, and governance. The review finds that resilient migration depends less on a single security product than on coordinated design decisions. These include separating management, replication, user, backup, security, and operational-technology flows; replacing inherited network trust with identity- and workload-aware policy; constraining migration corridors; maintaining cryptographically protected recovery copies; and releasing each migration wave only after observable technical and business evidence has been obtained. A reference operating model is proposed in which dual-running environments are governed through explicit security zones, continuous telemetry, policy-as-code, tested rollback, and service-level recovery objectives. The principal contribution is a practical review framework that treats migration as a sequence of reversible resilience decisions rather than a one-time cutover.
Zakiuddin Mohammed· Veredas do Direito· 0 citations
This article argues that 6G should reverse that trajectory by reordering five priorities: control first; customer outcomes before peak rates; business guarantees before megabytes; software-driven operations with governed agentic artificial intelligence; and technology in service of those priorities.
David Soldani, P. Nahi, Awn Muhammad et al.· 0 citations
Remote management of virtualized infrastructure introduces security risk when management services are exposed directly to the public internet. This risk is amplified when testbeds are intended to support sovereign edge computing workloads that require secure, isolated infrastructure. This study designs and evaluates a secure remote management architecture for a Proxmox VE node using a Tailscale overlay network and interface-specific firewall hardening, establishing a foundational infrastructure baseline for sovereign edge computing. The research follows Design Science Research supported by a network engineering evaluation procedure. The artefact was developed through problem identification, topology design, implementation, measurement, and evaluation. Data were collected from Tailscale status checks, Proxmox VE observation, ping latency testing, relay netcheck output, iptables verification, and external port scanning before and after firewall hardening. The Tailscale path achieved an average round-trip time of 0.434 milliseconds with zero packet loss, comparable to the public Internet Protocol path at 0.540 milliseconds with zero packet loss. Before hardening, public scanning detected management ports 22, 2222, and 8006. After applying interface-specific firewall rules, the external scan reported no open ports among the top 1000 ports, while private access to Proxmox VE through the Tailscale interface remained available. The proposed architecture demonstrates that overlay networking must be combined with firewall hardening to remove public management exposure without disrupting authorized remote administration. The result establishes a replicable foundational infrastructure baseline for sovereign edge computing, providing the first stage toward deployment of secure edge computing systems in resource-limited environments.
Network slicing is a foundational capability of Fifth Generation (5G)-Advanced and emerging Sixth Generation (6G) networks, yet practical support for seamless runtime slice transitions remains limited. Standard cloud-native 5G architectures lack native support for stateful inter/intra-slice session migration, relying instead on high-overhead Non-Access Stratum (NAS) re-registrations, container redeployment etc., which disrupt userplane traffic for up to 245.50 ms. To address this limitation, we present Orchra, an intelligent orchestrator for stateful, low-latency context transfer. By externalizing critical user equipment state-including NAS context, security keys, and Protocol Data Unit (PDU) session information-into a transient staging layer, Orchra preserves session continuity across slice boundaries without requiring full re-registration. Experimental evaluation shows that Orchra reduces this userplane interruption by more than twice in comparison to conventional Third Generation Partnership Project (3GPP)-based approaches while incurring negligible security overhead. These results demonstrate a practical and reproducible approach for enabling seamless, state-preserving slice transitions in cloud-native 5G-Advanced networks.
Anthony Kiggundu, Bin Han, H. Schotten· 0 citations
A novel Multi-Armed Bandit (MAB) approach is applied to optimize dynamic bandwidth allocation at the ONU layer, enabling increased user density without inducing latency burdens at the OLT and establishes a fault-resilient infrastructure suitable for next-generation converged optical networks.
K.Tara Phani, K. Kumari· Journal of optical communica...· 0 citations
Modern network infrastructures are undergoing a major transformation driven by Software Defined Networking (SDN). However, migration from legacy hardware to fully programmable architectures is typically incremental, resulting in hybrid environments where legacy routing protocols and centralized SDN controllers coexist. Managing these heterogeneous networks requires coordinated optimization across the physical infrastructure, control plane, and data plane. This thesis presents a multi-layer optimization framework for planning, deploying, and operating homogeneous and hybrid SDN environments. At the infrastructure layer, the Controller Placement Problem (CPP) is formulated as a multi-objective Integer Linear Programming (ILP) model and solved using exact ILP solvers and a localized Tabu Search approach. The framework determines controller placement and quantity to maximize network centrality and throughput while minimizing deployment cost and propagation delay. The ILP model reduces propagation delay by 16.4\% and 24.1\%, while the localized Tabu Search further improves transmitted data by 15.6\% and 26.2\% for the selected topology. At the control-plane layer, the thesis addresses protocol heterogeneity and route redistribution across administrative boundaries. Five routing protocols---BGP, EIGRP, IS-IS, OSPF, and RIP---are evaluated in terms of round-trip time (RTT), convergence delay, and a redistribution feasibility index(capturing topology compatibility, load sensitivity, and link stability). The optimization results show that while EIGRP provides strong proprietary performance, IS-IS emerges as the most resilient open-standard protocol for hybrid control planes. At the data-plane layer, the thesis develops two port-state-aware Fast Reroute (FRR) mechanisms for unpredictable link failures: PSA-FRR, a proactive rule-based approach for homogeneous networks, and PSAR-FRR, an automated deep neural network approach for hybrid environments. The neural model maps real-time interface status (port status) directly to backup egress paths using a formulated traffic engineering dataset. Experiments on the Abilene topology using Mininet, Ryu, OpenDaylight, and GNS3 show that both approaches restore traffic within 30--100~ms. PSAR-FRR achieves a data-plane switching latency of 0.123~ms, more than 70\% lower than PSA-FRR lookup latency and faster than the other evaluated machine learning methods. Overall, this thesis provides an end-to-end mathematical and machine learning framework for designing dependable, low-latency, and scalable SDN infrastructures.