Design Principles for 5G Security 89
between users but between devices carrying sensitive information such as data of health
care systems and other critical infrastructures. Therefore, new mechanisms are needed
to secure the data communication between users and devices. The OpenFlow protocol
supports Transport Layer Security (TLS) and Datagram Transport Layer Security
(DTLS). TLS is used to provide privacy and data integrity for the communication between
users. DTLS is used to secure data between communicating applications, mainly
UDP traffic. These technologies use symmetric cryptography for data encryption. The
TLS protocol is composed of two layers, that is, the TLS record protocol and the TLS
handshake protocol. The Record Protocol guarantees connection privacy and reliability
by means of data encryption. The TLS Handshake protocol authenticates the communicating parties with each other and negotiates the encryption algorithm and cryptographic
keys before transmitting the first packet of an application.
Besides the use of TLS and DTLS, virtual networking or network slicing can be used
to provide private communication channels for both data and control information, as
shown in Figure 4.4. Slicing can also provide isolation‐based data integrity and privacy. Slices of individual users can be separated by a networking hypervisor such as
the FlowVisor [11]. Traffic isolation can be used to protect one type of traffic from
another to strengthen the confidentiality and integrity of user traffic [43]. Hence, the
Open vSwitch platform provides isolation in multi‐tenant environments and during
mobility across multiple subnets [44]. The OpenFlow Random Host Mutation (OF‐
RHM) [45] technique is proposed to avoid scanning attacks on end‐hosts. Using the
moving target defense (MTD) technique, the OF‐RHM mutates IP addresses of end‐
hosts to avoid scanning attacks. The VAVE [14] platform validates the source addresses
of all incoming packets to prevent data from being spoofed or forged through the
OpenFlow interface attached to legacy devices.
4.4.2 Control Channels Security
Control channels carry the important control information between user and network,
and among network entities.
Private slices
End-to-End tunnel
A common network platform with dynamic and
secure network slices
Figure 4.4 Secure network slices for different services.
Précédent

- 131/483

Suivant