This description was written by a machine and published without a person checking it. It is what the agent made of this grouping, and not a statement anybody has stood behind.

The control plane, removed

A subject the papers are about. The loosest grouping, and the one to reach for last.

What happens to a network when the control plane is lifted out of the boxes that forward packets. The set runs from the argument that policy and mechanism were tangled in the first place, through the state that a switch then no longer has to keep, to what a single programmable controller is worth as a target.

OpenFlow is the hinge and everything sorts around it. Before it: Livermore on controlling an adaptive flat network in 1998, and the MPLS control-plane security report, which is the previous generation's version of the same worry. Griffioen states the separation argument directly. After it, Kreutz's survey is the standard orientation and Hari is the concrete payoff -- path switching, where knowing the path lets a switch stop keeping per-flow state, which is the set's title as an engineering result rather than an architecture diagram.

The deployments are the part most worth reading and the part most often skipped. Faucet is a production controller; Gupta's industrial-scale software-defined exchange and Bruyere's rethinking of the IXP are the same idea applied where it pays best. Those two connect this set to the IXP thread in `who-the-internet-depends-on`: an exchange point is where centralised control has the clearest business case, because the policy being expressed is between parties rather than inside one.

Security is the largest single thread here, and that follows from the premise rather than being a separate topic. Lakshminarayanan, the Scott-Hayward survey, Black on mitigations and the NCSC guidance all exist because moving control into one programmable place creates something that was not previously there to attack.

Two records answer the question differently. SCION does not centralise control; it makes the path explicit to the sender, which is the path-aware alternative to a controller. Vemuganti carries source routing into LEO satellite constellations, where a central controller is least plausible.

Hall's *Collaborating with the enemy on network management* has a companion transcript-of-discussion record in the corpus that is not in this set.

17 references

Technology Considerations: SCION
National Cyber Security Centre (2025) · National Cyber Security Centre (NCSC), Federal Department of Defence, Civil Protection and Sport, Switzerland
Where is My Route? Enabling Source Routing in LEO Satellite Networks
Satvik Vemuganti and others (2024) · 2024 IEEE 99th Vehicular Technology Conference (VTC2024-Spring) · IEEE
Mitigating data plane device compromise in programmable networks
Conor Black (2023)
The Complete Guide to SCION
Laurent Chuat and others (2022) · Springer
A review on software defined network security risks and challenges
Tsehay Admassu Assegie and others (2019) · TELKOMNIKA (Telecommunication Computing Electronics and Control) · Ahmad Dahlan University
Rethinking IXPs' Architecture in the Age of SDN
Marc Bruyere and others (2018) · IEEE Journal on Selected Areas in Communications · Institute of Electrical and Electronics Engineers
An Industrial-Scale Software Defined Internet Exchange Point
Arpit Gupta and others (2016) · 13th USENIX Symposium on Networked Systems Design and Implementation (NSDI '16) · USENIX Association
A survey of security in software defined networks
Sandra Scott-Hayward and others (2016) · IEEE Communications Surveys & Tutorials · IEEE
Path switching: Reduced-state flow handling in SDN using path information
Adiseshu Hari and others (2015) · Proceedings of the 11th ACM Conference on Emerging Networking Experiments and Technologies
Software-Defined Networking: A Comprehensive Survey
Diego Kreutz and others (2015) · Proceedings of the IEEE · Institute of Electrical and Electronics Engineers (IEEE)
Collaborating with the enemy on network management
Chris Hall and others (2014) · Security Protocols XXII · Springer
Virtualization and Distribution of the BGP Control Plane
Mihaela Iuniana Oprescu (2012)
Separating routing policy from mechanism in the network layer
James Griffioen and others (2011) · Next-Generation Internet · Cambridge University Press
OpenFlow: enabling innovation in campus networks
Nick McKeown and others (2008) · ACM SIGCOMM Computer Communication Review · Association for Computing Machinery (ACM)
Securing User-controlled Routing Infrastructures
Karthik Lakshminarayanan and others (2007) · Electrical Engineering and Computer Sciences, University of California at Berkeley
Final Report for the Multiprotocol Label Switching (MPLS) Control Plane Security LDRD Project
Thomas D. Tarman and others (2003) · Sandia National Laboratories
Architecture and control of an adaptive high capacity flat network
Eric Livermore and others (1998) · IEEE Communications Magazine