We now consider a scenario in which the service requirement is to
give better blocking/preemption performance to class 2 than to class
3, while maintaining class 1 performance at the same level as in the
previous scenario. (The use of minimum deterministic guarantee for
class 3 is to be considered in the next section.) So that the
specified class 2 performance objective can be met, class 2 BC is
increased appropriately. As an example, BCs (6, 9, 15) are now used
for MAM, and (6, 13, 15) for RDM. For both BCMs, as shown in Figures
1bis and 2bis, although class 1 performance remains unchanged, class
2 now receives better performance, at the expense of class 3. This is
of course due to the increased access of bandwidth by class 2 over
class 3. Under normal conditions, the performance of the two BCMs is
similar in terms of their blocking and preemption probabilities for
LSP setup requests, as shown in Table 2.
Table 2. Blocking and preemption probabilities
BCM PB1 PB2 PB3 PP2 PP3 PB2+PP2 PB3+PP3
MAM 0.03692 0.00658 0.02733 0 0.02709 0.00658 0.05441
RDM 0.03692 0.00449 0.02759 0.00272 0.02436 0.00721 0.05195
Under overload, the observations in Section 4.1 regarding the
difference in the general behavior between the two BCMs still apply,
as shown in Figures 1bis and 2bis.
The following are two frequently asked questions about the operation
of BCMs.
(1) For a link capacity of 15, would a class 1 BC of 6 and a class 2
BC of 9 in MAM result in the possibility of a total lockout for
class 3?
This will certainly be the case when there are 6 class 1 and 9 class
2 LSPs being established simultaneously. Such an offered load (with
6 class 1 and 9 class 2 LSP requests) will not cause a lockout of
class 3 with RDM having a BC of 13 for classes 1 and 2 combined, but
will result in class 2 LSPs being rejected. If class 2 traffic were
considered relatively more important than class 3 traffic, then RDM
would perform very poorly compared to MAM with BCs of (6, 9, 15).
(2) Should MAM with BCs of (6, 7, 15) be used instead so as to make
the performance of RDM look comparable?
The answer is that the above scenario is not very realistic when the
offered load is assumed to be (2.7, 3.5, 3.5) for the three classes,
as stated in Section 3.2. Treating an overload of (6, 9, x) as a
normal operating condition is incompatible with the engineering of
BCs according to needed bandwidth from different classes. It would
be rare for a given class to need so much more than its engineered
bandwidth level. But if the class did, the expectation based on
design and normal traffic fluctuations is that this class would
quickly release unneeded bandwidth toward its engineered level,
freeing up bandwidth for other classes.
Service providers engineer their networks based on traffic
projections to determine network configurations and needed capacity.
All BCMs should be designed to operate under realistic network
conditions. For any BCM to work properly, the selection of values
for different BCs must therefore be based on the projected bandwidth
needs of each class, as well as on the bandwidth allocation rules of
the BCM itself. This is to ensure that the BCM works as expected
under the intended design conditions. In operation, the actual load
may well turn out to be different from that of the design. Thus, an
assessment of the performance of a BCM under overload is essential to
see how well the BCM can cope with traffic surges or network
failures. Reflecting this view, the basis for comparison of two BCMs
is that they meet the same or similar performance requirements under
normal conditions, and how they withstand overload.
In operational practice, load measurement and forecast would be
useful to calibrate and fine-tune the BCs so that traffic from
different classes could be redistributed accordingly. Dynamic
adjustment of the Diffserv scheduler could also be used to minimize
QoS degradation.
4.3. Comparing Bandwidth Constraints of Different Models
As is pointed out in Section 3.2, the higher degree of sharing among
the different classes in RDM means that the numerical values of the
BCs could be relatively smaller than those for MAM. We now examine
this aspect in more detail by considering the following scenario. We
set the BCs so that (1) for both BCMs, the same value is used for
class 1, (2) the same minimum deterministic guarantee of bandwidth
for class 3 is offered by both BCMs, and (3) the blocking/preemption
probability is minimized for class 2. We want to emphasize that this
may not be the way service providers select BCs. It is done here to
investigate the statistical behavior of such a deterministic
mechanism.
For illustration, we use BCs (6, 7, 15) for MAM, and (6, 13, 15) for
RDM. In this case, both BCMs have 13 units of bandwidth for classes
1 and 2 together, and dedicate 2 units of bandwidth for use by class
3 only. The performance of the two BCMs under normal conditions is
shown in Table 3. It is clear that MAM with (6, 7, 15) gives fairly
comparable performance objectives across the three classes, whereas
RDM with (6, 13, 15) strongly favors class 2 at the expense of class
3. They therefore cater to different service requirements.
Table 3. Blocking and preemption probabilities
BCM PB1 PB2 PB3 PP2 PP3 PB2+PP2 PB3+PP3
MAM 0.03692 0.03961 0.02384 0 0.02275 0.03961 0.04659
RDM 0.03692 0.00449 0.02759 0.00272 0.02436 0.00721 0.05195
By comparing Figures 1 and 2bis, it can be seen that, when being
subjected to the same set of BCs, RDM gives class 2 much better
performance than MAM, with class 3 being only slightly worse.
This confirms the observation in Section 3.2 that, when the same
service requirements under normal conditions are to be met, the
numerical values of the BCs for RDM can be relatively smaller than
those for MAM. This should not be surprising in view of the hard
boundary (B3 = Nmax) in RDM versus the soft boundary (B1+B2+B3 >=
Nmax) in MAM. The strict ordering of BCs (B1 < B2 < B3) gives RDM
the advantage of a higher degree of sharing among the different
classes; i.e., the ability to reallocate the unused bandwidth of
higher-priority classes to lower-priority ones, if needed.
Consequently, this leads to better performance when an identical set
of BCs is used as exemplified above. Such a higher degree of sharing
may necessitate the use of minimum deterministic bandwidth guarantee
to offer some protection for lower-priority traffic from preemption.
The explicit lack of ordering of BCs in MAM and its soft boundary
imply that the use of minimum deterministic guarantees for lower-
priority classes may not need to be enforced when there is a lesser
degree of sharing. This is demonstrated by the example in Section
4.2 with BCs (6, 9, 15) for MAM.
For illustration, Table 4 shows the performance under normal
conditions of RDM with BCs (6, 15, 15).
Table 4. Blocking and preemption probabilities
BCM PB1 PB2 PB3 PP2 PP3 PB2+PP2 PB3+PP3
RDM 0.03692 0.00060 0.02800 0.00032 0.02740 0.00092 0.05540
Regardless of whether deterministic guarantees are used, both BCMs
are bounded by the same aggregate constraint of the link capacity.
Also, in both BCMs, bandwidth access guarantees are necessarily
achieved statistically because of traffic fluctuations, as explained
in Section 4.2. (As a result, service-level objectives are typically
specified as monthly averages, under the use of statistical
guarantees rather than deterministic guarantees.) Thus, given the
fundamentally different operating principles of the two BCMs
(ordering, hard versus soft boundary), the dimensions of one BCM
should not be adopted to design for the other. Rather, it is the
service requirements, and perhaps also the operational needs, of a
service provider that should be used to drive how the BCs of a BCM
are selected.
5. Performance under Partial Preemption
In the previous two sections, preemption is fully enabled in the
sense that class 1 can preempt class 3 or class 2 (in that order),
and class 2 can preempt class 3. That is, both classes 1 and 2 are
preemptor-enabled, whereas classes 2 and 3 are preemptable. A class
that is preemptor-enabled can preempt lower-priority classes
designated as preemptable. A class not designated as preemptable
cannot be preempted by any other classes, regardless of relative
priorities.
We now consider the three cases shown in Table 5, in which preemption
is only partially enabled.
Table 5. Partial preemption modes
preemption modes preemptor-enabled preemptable
"1+2 on 3" (Fig. 3, 6) class 1, class 2 class 3
"1 on 3" (Fig. 4, 7) class 1 class 3
"1 on 2+3" (Fig. 5, 8) class 1 class 3, class 2
In this section, we evaluate how these preemption modes affect the
performance of a particular BCM. Thus, we are comparing how a given
BCM performs when preemption is fully enabled versus how the same BCM
performs when preemption is partially enabled. The performance of
these preemption modes is shown in Figures 3 to 5 for RDM, and in
Figures 6 through 8 for MAM, respectively. In all of these figures,
the BCs of Section 3.2 are used for illustration; i.e., (6, 7, 15)
for MAM and (6, 11, 15) for RDM. However, the general behavior is
similar when the BCs are changed to those in Sections 4.2 and 4.3;
i.e., (6, 9, 15) and (6, 13, 15), respectively.
5.1. Russian Dolls Model
Let us first examine the performance under RDM. There are two sets
of results, depending on whether class 2 is preemptable: (1) Figures
3 and 4 for the two modes when only class 3 is preemptable, and (2)
Figure 2 in the previous section and Figure 5 for the two modes when
both classes 2 and 3 are preemptable. By comparing these two sets of
results, the following impacts can be observed. Specifically, when
class 2 is non-preemptable, the behavior of each class is as follows:
1. Class 1 generally sees a higher blocking probability. As the
class 1 space allocated by the class 1 BC is shared with class 2,
which is now non-preemptable, class 1 cannot reclaim any such
space occupied by class 2 when needed. Also, class 1 has less
opportunity to preempt, as it is able to preempt class 3 only.
2. Class 3 also sees higher blocking/preemption when its own load is
increased, as it is being preempted more frequently by class 1,
when class 1 cannot preempt class 2. (See the last set of four
points in the series for class 3 shown in Figures 3 and 4, when
comparing with Figures 2 and 5.)
3. Class 2 blocking/preemption is reduced even when its own load is
increased, since it is not being preempted by class 1. (See the
middle set of four points in the series for class 2 shown in
Figures 3 and 4, when comparing with Figures 2 and 5.)
Another two sets of results are related to whether class 2 is
preemptor-enabled. In this case, when class 2 is not preemptor-
enabled, class 2 blocking/preemption is increased when class 3 load
is increased. (See the last set of four points in the series for
class 2 shown in Figures 4 and 5, when comparing with Figures 2 and
3.) This is because both classes 2 and 3 are now competing
independently with each other for resources.
5.2. Maximum Allocation Model
Turning now to MAM, the significant impact appears to be only on
class 2, when it cannot preempt class 3, thereby causing its
blocking/preemption to increase in two situations.
1. When class 1 load is increased. (See the first set of four points
in the series for class 2 shown in Figures 7 and 8, when comparing
with Figures 1 and 6.)
2. When class 3 load is increased. (See the last set of four points
in the series for class 2 shown in Figures 7 and 8, when comparing
with Figures 1 and 6.) This is similar to RDM; i.e., class 2 and
class 3 are now competing with each other.
When Figure 1 (for the case of fully enabled preemption) is compared
to Figures 6 through 8 (for partially enabled preemption), it can be
seen that the performance of MAM is relatively insensitive to the
different preemption modes. This is because when each class has its
own bandwidth access limits, the degree of interference among the
different classes is reduced.
This is in contrast with RDM, whose behavior is more dependent on the
preemption mode in use.
6. Performance under Pure Blocking
This section covers the case in which preemption is completely
disabled. We continue with the numerical example used in the
previous sections, with the same link capacity and offered load.
6.1. Russian Dolls Model
For RDM, we consider two different settings:
"Russian Dolls (1)" BCs:
up to 6 simultaneous LSPs for class 1 by itself,
up to 11 simultaneous LSPs for classes 1 and 2 together, and
up to 15 simultaneous LSPs for all three classes together.
"Russian Dolls (2)" BCs:
up to 9 simultaneous LSPs for class 3 by itself,
up to 14 simultaneous LSPs for classes 3 and 2 together, and
up to 15 simultaneous LSPs for all three classes together.
Note that the "Russian Dolls (1)" set of BCs is the same as
previously with preemption enabled, whereas the "Russian Dolls (2)"
has the cascade of bandwidth arranged in reverse order of the
classes.
As observed in Section 4, the cascaded bandwidth arrangement is
intended to offer lower-priority traffic some protection from
preemption by higher-priority traffic. This is to avoid starvation.
In a pure blocking environment, such protection is no longer
necessary. As depicted in Figure 9, it actually produces the
opposite, undesirable effect: higher-priority traffic sees higher
blocking than lower-priority traffic. With no preemption, higher-
priority traffic should be protected instead to ensure that it could
get through when under high load. Indeed, when the reverse cascade
is used in "Russian Dolls (2)", the required performance of lower
blocking for higher-priority traffic is achieved, as shown in Figure
10. In this specific example, there is very little difference among
the performance of the three classes in the first eight data points
for each of the three series. However, the BCs can be tuned to get a
bigger differentiation.
6.2. Maximum Allocation Model
For MAM, we also consider two different settings:
"Exp. Max. Alloc. (1)" BCs:
up to 7 simultaneous LSPs for class 1,
up to 8 simultaneous LSPs for class 2, and
up to 8 simultaneous LSPs for class 3.
"Exp. Max. Alloc. (2)" BCs:
up to 7 simultaneous LSPs for class 1, with additional bandwidth for
1 LSP privately reserved
up to 8 simultaneous LSPs for class 2, and
up to 8 simultaneous LSPs for class 3.
These BCs are chosen so that, under normal conditions, the blocking
performance is similar to all the previous scenarios. The only
difference between these two sets of values is that the "Exp. Max.
Alloc. (2)" algorithm gives class 1 a private pool of 1 server for
class protection. As a result, class 1 has a relatively lower
blocking especially when its traffic is above normal, as can be seen
by comparing Figures 11 and 12. This comes, of course, with a slight
increase in the blocking of classes 2 and 3 traffic.
When comparing the "Russian Dolls (2)" in Figure 10 with MAM in
Figures 11 or 12, the difference between their behavior and the
associated explanation are again similar to the case when preemption
is used. The higher degree of sharing in the cascaded bandwidth
arrangement of RDM leads to a tighter coupling between the different
classes of traffic when under overload. Their performance therefore
tends to degrade together when the load of any one class is
increased. By imposing explicit maximum bandwidth usage on each
class individually, better class isolation is achieved. The trade-
off is that, generally, blocking performance in MAM is somewhat
higher than in RDM, because of reduced sharing.
The difference in the behavior of RDM with or without preemption has
already been discussed at the beginning of this section. For MAM,
some notable differences can also be observed from a comparison of
Figures 1 and 11. If preemption is used, higher-priority traffic
tends to be able to maintain its performance despite the overloading
of other classes. This is not so if preemption is not allowed. The
trade-off is that, generally, the overloaded class sees a relatively
higher blocking/preemption when preemption is enabled than there
would be if preemption is disabled.
7. Performance under Complete Sharing
As observed towards the end of Section 3, the partitioning of
bandwidth capacity for access by different traffic classes tends to
reduce the maximum link efficiency achievable. We now consider the
case where there is no such partitioning, thereby resulting in full
sharing of the total bandwidth among all the classes. This is
referred to as the Complete Sharing Model.
For MAM, this means that the BCs are such that up to 15 simultaneous
LSPs are allowed for any class.
Similarly, for RDM, the BCs are
up to 15 simultaneous LSPs for class 1 by itself,
up to 15 simultaneous LSPs for classes 1 and 2 together, and
up to 15 simultaneous LSPs for all three classes together.
Effectively, there is now no distinction between MAM and RDM. Figure
13 shows the performance when all classes have equal access to link
bandwidth under Complete Sharing.
With preemption being fully enabled, class 1 sees virtually no
blocking, regardless of the loading conditions of the link. Since
class 2 can only preempt class 3, class 2 sees some blocking and/or
preemption when either class 1 load or its own load is above normal;
otherwise, class 2 is unaffected by increases of class 3 load. As
higher priority classes always preempt class 3 when the link is full,
class 3 suffers the most, with high blocking/preemption when there is
any load increase from any class. A comparison of Figures 1, 2, and
13 shows that, although the performance of both classes 1 and 2 is
far superior under Complete Sharing, class 3 performance is much
better off under either MAM or RDM. In a sense, class 3 is starved
under overload as no protection of its traffic is being provided
under Complete Sharing.
8. Implications on Performance Criteria
Based on the previous results, a general theme is shown to be the
trade-off between bandwidth sharing and class protection/isolation.
To show this more concretely, let us compare the different BCMs in
terms of the overall loss probability. This quantity is defined as
the long-term proportion of LSP requests from all classes combined
that are lost as a result of either blocking or preemption, for a
given level of offered load.
As noted in the previous sections, although RDM has a higher degree
of sharing than MAM, both ultimately converge to the Complete Sharing
Model as the degree of sharing in each of them is increased. Figure
14 shows that, for a single link, the overall loss probability is the
smallest under Complete Sharing and the largest under MAM, with that
under RDM being intermediate. Expressed differently, Complete
Sharing yields the highest link efficiency and MAM the lowest. As a
matter of fact, the overall loss probability of Complete Sharing is
identical to the loss probability of a single class as computed by
the Erlang loss formula. Yet Complete Sharing has the poorest class
protection capability. (Note that, in a network with many links and
multiple-link routing paths, analysis in [6] showed that Complete
Sharing does not necessarily lead to maximum network-wide bandwidth
efficiency.)
Increasing the degree of bandwidth sharing among the different
traffic classes helps increase link efficiency. Such increase,
however, will lead to a tighter coupling between different classes.
Under normal loading conditions, proper dimensioning of the link so
that there is adequate capacity for each class can minimize the
effect of such coupling. Under overload conditions, when there is a
scarcity of capacity, such coupling will be unavoidable and can cause
severe degradation of service to the lower-priority classes. Thus,
the objective of maximizing link usage as stated in criterion (5) of
Section 1 must be exercised with care, with due consideration to the
effect of interactions among the different classes. Otherwise, use
of this criterion alone will lead to the selection of the Complete
Sharing Model, as shown in Figure 14.
The intention of criterion (2) in judging the effectiveness of
different BCMs is to evaluate how they help the network achieve the
expected performance. This can be expressed in terms of the blocking
and/or preemption behavior as seen by different classes under various
loading conditions. For example, the relative strength of a BCM can
be demonstrated by examining how many times the per-class blocking or
preemption probability under overload is worse than the corresponding
probability under normal load.
9. Conclusions
BCMs are used in DS-TE for path computation and admission control of
LSPs by enforcing different BCs for different classes of traffic so
that Diffserv QoS performance can be maximized. Therefore, it is of
interest to measure the performance of a BCM by the LSP
blocking/preemption probabilities under various operational
conditions. Based on this, the performance of RDM and MAM for LSP
establishment has been analyzed and compared. In particular, three
different scenarios have been examined: (1) all three classes have
comparable performance objectives in terms of LSP blocking/preemption
under normal conditions, (2) class 2 is given better performance at
the expense of class 3, and (3) class 3 receives some minimum
deterministic guarantee.
A general theme is the trade-off between bandwidth sharing to achieve
greater efficiency under normal conditions, and to achieve robust
class protection/isolation under overload. The general properties of
the two BCMs are as follows:
RDM
- allows greater sharing of bandwidth among different classes
- performs somewhat better under normal conditions
- works well when preemption is fully enabled; under partial
preemption, not all preemption modes work equally well
MAM
- does not depend on the use of preemption
- is relatively insensitive to the different preemption modes when
preemption is used
- provides more robust class isolation under overload
Generally, the use of preemption gives higher-priority traffic some
degree of immunity to the overloading of other classes. This results
in a higher blocking/preemption for the overloaded class than that in
a pure blocking environment.
10. Security Considerations
This document does not introduce additional security threats beyond
those described for Diffserv [10] and MPLS Traffic Engineering [11,
12, 13, 14], and the same security measures and procedures described
in those documents apply here. For example, the approach for defense
against theft- and denial-of-service attacks discussed in [10], which
consists of the combination of traffic conditioning at Diffserv
boundary nodes along with security and integrity of the network
infrastructure within a Diffserv domain, may be followed when DS-TE
is in use.
Also, as stated in [11], it is specifically important that
manipulation of administratively configurable parameters (such as