Ahmad, Liyanage, Shahabuddin, Ylianttila, and Gurtov
82
platforms instead of specialized function‐specific hardware. SDN, on the other hand,
separates the network control plane from the data forwarding plane to enable innovation
in network control systems. Therefore, NFV and SDN will be vital in providing foolproof
security in 5G systems. The basic diagram of the 5G network that provides connectivity
to all devices at all times, covering almost every aspect of the society, is presented in
Figure 4.2. The high level architectural diagram presented in the figure leverages the concepts of NFV and SDN to dynamically provide security in various network parameters, as
the need arises. Below we describe the security challenges existing in both technologies
and how these technologies can be used to increase the overall network security.
4.3.1 5G Security Leveraging NFV
Virtualization is used to decouple a system’s service model from its physical realization
and has been used in networking, for example for creating virtual links (tunnels) and
broadcast domains (VLANs). Through virtualization, logical instances of a physical
hardware can be used for different tasks, where the physical and logical instances are
mapped through a network hypervisor [8]. The concept has led to the development of
Mobile Virtual Network Operators (MVNOs). To minimize the investment in the infrastructure, MVNOs lease virtual resources including network resources from Mobile
Network Operators (MNOs), thus a physical mobile network can host several MVNOs.
MVNOs have their own operating and support systems and can offer independent services from the MNO. Therefore, NFV has a vital role, not only in the MVNO and MNO
ecosystem, but also in the overall networking ecosystem to utilize the hardware resources
in the most efficient manner possible.
NFV will enable function placement in different network perimeters without requiring
function specific hardware but based on the need of the function or service at that location and time. Telecom networks will expose Application Programming Interfaces (APIs)
on their hardware platform to users and third‐party software providers to deploy their
Sec. DRA
LB
Mon.
Operator-Specific Network
Functions/Applications
PCRF
AAA
MME
H SS
S/P-GW
EPC Elements
Orchestration
Interface
Interface
Interface
Non-3GPP Elements
Trusted-Non
3GPP
Non-TrustedNon 3GPP
Core Network/Operator/
Business Services
Northbound Interface
Northbound Interface
Backhaul
Network
Access Network
Users
Users
Users
Users
Users
Southbound Interface
Interface
Backhaul Network
Control
Service Control
Access Control
Network Management
Cellular
Network
Access Network
Control/MEC
Servers
VLC
Network
Satellite
Network
WiFi
Network
Figure 4.2 High‐Level 5G architecture integrating multiple access technologies.
82
platforms instead of specialized function‐specific hardware. SDN, on the other hand,
separates the network control plane from the data forwarding plane to enable innovation
in network control systems. Therefore, NFV and SDN will be vital in providing foolproof
security in 5G systems. The basic diagram of the 5G network that provides connectivity
to all devices at all times, covering almost every aspect of the society, is presented in
Figure 4.2. The high level architectural diagram presented in the figure leverages the concepts of NFV and SDN to dynamically provide security in various network parameters, as
the need arises. Below we describe the security challenges existing in both technologies
and how these technologies can be used to increase the overall network security.
4.3.1 5G Security Leveraging NFV
Virtualization is used to decouple a system’s service model from its physical realization
and has been used in networking, for example for creating virtual links (tunnels) and
broadcast domains (VLANs). Through virtualization, logical instances of a physical
hardware can be used for different tasks, where the physical and logical instances are
mapped through a network hypervisor [8]. The concept has led to the development of
Mobile Virtual Network Operators (MVNOs). To minimize the investment in the infrastructure, MVNOs lease virtual resources including network resources from Mobile
Network Operators (MNOs), thus a physical mobile network can host several MVNOs.
MVNOs have their own operating and support systems and can offer independent services from the MNO. Therefore, NFV has a vital role, not only in the MVNO and MNO
ecosystem, but also in the overall networking ecosystem to utilize the hardware resources
in the most efficient manner possible.
NFV will enable function placement in different network perimeters without requiring
function specific hardware but based on the need of the function or service at that location and time. Telecom networks will expose Application Programming Interfaces (APIs)
on their hardware platform to users and third‐party software providers to deploy their
Sec. DRA
LB
Mon.
Operator-Specific Network
Functions/Applications
PCRF
AAA
MME
H SS
S/P-GW
EPC Elements
Orchestration
Interface
Interface
Interface
Non-3GPP Elements
Trusted-Non
3GPP
Non-TrustedNon 3GPP
Core Network/Operator/
Business Services
Northbound Interface
Northbound Interface
Backhaul
Network
Access Network
Users
Users
Users
Users
Users
Southbound Interface
Interface
Backhaul Network
Control
Service Control
Access Control
Network Management
Cellular
Network
Access Network
Control/MEC
Servers
VLC
Network
Satellite
Network
WiFi
Network
Figure 4.2 High‐Level 5G architecture integrating multiple access technologies.
