Towards a 5G Security Architecture: Articulating Software-Defined Security and Security as a Service

被引:5
|
作者
Blanc, Gregory [1 ]
Kheir, Nizar [2 ]
Ayed, Dhouha [2 ]
Lefebvre, Vincent [3 ]
de Oca, Edgardo Montes [4 ]
Bisson, Pascal [2 ]
机构
[1] Telecom SudParis, CNRS, SAMOVAR, Evry, France
[2] Thales Grp, Paris, France
[3] Tages SAS, Le Cannet, France
[4] Montimage, Paris, France
关键词
Network Slicing; Software-Defined Security; Security as a Service;
D O I
10.1145/3230833.3233251
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
5G is envisioned as a transformation of the communications architecture towards multi-tenant, scalable and flexible infrastructure, which heavily relies on virtualised network functions and programmable networks. In particular, orchestration will advance one step further in blending both compute and data resources, usually dedicated to virtualisation technologies, and network resources into so-called slices. Although 5G security is being developed in current working groups, slice security is seldom addressed. In this work, we propose to integrate security in the slice life cycle, impacting its management and orchestration that relies on the virtualization/ softwarisation infrastructure. The proposed security architecture connects the demands specified by the tenants through as-a-service mechanisms with built-in security functions relying on the ability to combine enforcement and monitoring functions within the software-defined network infrastructure. The architecture exhibits desirable properties such as isolating slices down to the hardware resources or monitoring service-level performance.
引用
收藏
页数:8
相关论文
共 50 条
  • [1] Security Awareness in Software-Defined Multi-Domain 5G Networks
    Suomalainen, Jani
    Ahola, Kimmo
    Majanen, Mikko
    Mammela, Olli
    Ruuska, Pekka
    FUTURE INTERNET, 2018, 10 (03)
  • [2] SDSA: A Framework of a Software-Defined Security Architecture
    Liu Yanbing
    Lu Xingyu
    Jian Yi
    Xiao Yunpeng
    CHINA COMMUNICATIONS, 2016, 13 (02) : 178 - 188
  • [3] A Software-Defined Networking Security Controller Architecture
    Shang, Fengjun
    Fu, Qiang
    PROCEEDINGS OF THE 2016 4TH INTERNATIONAL CONFERENCE ON MACHINERY, MATERIALS AND COMPUTING TECHNOLOGY, 2016, 60 : 229 - 234
  • [4] A SOFTWARE DEFINED SECURITY ARCHITECTURE FOR SDN-BASED 5G NETWORK
    Liang, Xiaodong
    Qiu, Xiaofeng
    PROCEEDINGS OF 2016 5TH IEEE INTERNATIONAL CONFERENCE ON NETWORK INFRASTRUCTURE AND DIGITAL CONTENT (IEEE IC-NIDC 2016), 2016, : 17 - 21
  • [5] Security Analysis as Software-defined Security for SDN Environment
    El Moussaid, Nadya
    Toumanari, Ahmed
    El Azhari, Maryam
    2017 FOURTH INTERNATIONAL CONFERENCE ON SOFTWARE DEFINED SYSTEMS (SDS), 2017, : 87 - 92
  • [6] On the Security of Software-Defined Networks
    Prasad, Abhinandan S.
    Koll, David
    Fu, Xiaoming
    2015 FOURTH EUROPEAN WORKSHOP ON SOFTWARE DEFINED NETWORKS - EWSDN 2015, 2015, : 105 - 106
  • [7] Towards 5G Security
    Horn, Guenther
    Schneider, Peter
    2015 IEEE TRUSTCOM/BIGDATASE/ISPA, VOL 1, 2015, : 1165 - 1170
  • [8] Scheduling of Security Resources in Software Defined Security Architecture
    Zhang, Gang
    Qiu, Xiaofeng
    Chang, Wei
    2017 INTERNATIONAL CONFERENCE ON CYBER-ENABLED DISTRIBUTED COMPUTING AND KNOWLEDGE DISCOVERY (CYBERC), 2017, : 494 - 503
  • [9] Design and Implementation of a Security Control Architecture for Software-Defined Networking
    Liu, Tie-jun
    Lin, Zhao-wen
    Xu, Jie
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON COMPUTER NETWORKS AND COMMUNICATION TECHNOLOGY (CNCT 2016), 2016, 54 : 779 - 785
  • [10] A Security-aware Software-defined IoT Network Architecture
    Zuo, Xinbin
    Pang, Xue
    Zhang, Pengping
    Zhang, Junsan
    Dong, Tao
    Zhang, Peiying
    2020 IEEE COMPUTING, COMMUNICATIONS AND IOT APPLICATIONS (COMCOMAP), 2021,