Back to results
Bibliographic record · Consultation and access
Artículo de revista

XenFlow: An XDP/eBPF-Based Multi-Tenant NFV Framework Considering System Security and High-Performance

Soki Koizumi et al · IEEE · 2026

Open access available
Quick overview. Review the resource’s basic details, then access the content using the main button. This page shows only the information needed to identify, cite, and open the work.
Serial publication

3PS-RAN: A Real-Time Framework for Securing the O-RAN RACH Against DDoS Attacks Toward NextG

This serial publication contains 172 related contents.

Resource access

Open the content from the main option or choose another available source.

DOAJ DOAJ Articles
Entrar por DOAJ
Main access

Open access available

Recurso identificado como acceso abierto, sin confirmar automáticamente si es texto completo directo.
Open resource

Summary

Descripción general del contenido del recurso.

Network Function Virtualization (NFV) offers flexibility but poses a critical challenge in multi-tenant environments: ensuring fairness (resource usage limits) and system security (memory/packet isolation) for each tenant. Existing NFV frameworks commonly rely on kernel bypass technologies, achieving high performance by sacrificing the kernel’s essential fairness and system security guarantees needed for a safe multi-tenant environment. This paper proposes XenFlow, an NFV framework designed to resolve the conflict between performance and both fairness and system security. By leveraging the eXpress Data Path (XDP), XenFlow places Network Functions (NFs) in both the kernel and user spaces and operates without bypassing the kernel. To provide fairness and system security to tenants, XenFlow leverages the verification mechanism of XDP in the kernel space and uses containers and intra-process memory isolation techniques in the user space. Within the fair and secure foundation described above, XenFlow achieves high performance by realizing packet zero-copy, a capability that existing NFV frameworks using XDP have not attained. Evaluation results show that XenFlow achieves 2.3-8.1 times higher throughput than existing NFV frameworks using XDP, thanks to packet zero-copy. Whereas the throughput of XenFlow is 62-84% of an NFV framework using kernel bypass technologies, this is a deliberate trade-off. XenFlow successfully prioritizes fairness and system security over peak performance, establishing a trustworthy multi-tenant environment that is fundamentally incompatible with performance-centric designs.

How to cite

Elegí el formato que necesitás y copiá la referencia al portapapeles.

APA 7

al, S. K. E. (2026). XenFlow: An XDP/eBPF-Based Multi-Tenant NFV Framework Considering System Security and High-Performance. https://doi.org/10.1109/ACCESS.2026.3687522

MLA

al, Soki Koizumi et. "XenFlow: An XDP/eBPF-Based Multi-Tenant NFV Framework Considering System Security and High-Performance." 2026. https://doi.org/10.1109/ACCESS.2026.3687522.

Chicago

al, Soki Koizumi et. 2026. "XenFlow: An XDP/eBPF-Based Multi-Tenant NFV Framework Considering System Security and High-Performance.". https://doi.org/10.1109/ACCESS.2026.3687522.

Harvard

al, S. K. E. 2026, XenFlow: An XDP/eBPF-Based Multi-Tenant NFV Framework Considering System Security and High-Performance, IEEE, available at: https://doi.org/10.1109/ACCESS.2026.3687522 [Accessed 7 Aug. 2026].

Share and print

Save the record, copy its permanent link, or print it as a PDF.

Export reference

You can export the record in common formats for use in a reference manager.

Resource details

Bibliographic information to help confirm that this is the correct material.

Title
XenFlow: An XDP/eBPF-Based Multi-Tenant NFV Framework Considering System Security and High-Performance
Author / contributors
Soki Koizumi et al
Publisher
IEEE
Publication year
2026
ISSN
2169-3536
ISSN
2169-3536
Language
English

Subjects

Explore related resources through these subjects.

Copied