Customer Edge Switching: A Security Framework for 5G 207
A policy is defined by three distinct sets: offer, requirement and available. Each of
these sets carries the policy elements, which collectively define a policy. The operation
field in the TLV encoding can take following values:
a) info to indicate the value of an offered policy element;
b) query to indicate the request for a policy element; and
c) response is an answer to a previous query from CES and could be empty if the policy
element is not available.
Outbound Policy for Host‐A (a.cesa):
Offer
= {id.fqdn, rloc.ipv4, rloc.ipv6, payload.ipv4}
Requirement = {id.fqdn, rloc.ipv4, rloc.ipv6, payload.ipv4}
Available
= {id.fqdn, rloc.ipv4, rloc.ipv6, payload.ipv4, id.hash}
Inbound Policy for Host‐B (b.cesb):
Requirement = {id.fqdn, rloc.ipv4, payload.ipv4}
Available
= {id.fqdn, rloc.ipv4, payload.ipv4}
Offer
= An inbound policy does not make any offer
Table 9.1 CETP policy elements organized into groups.
Group
Code
Description
CES
Pow
cesid
headersignature
caces
The proof‐of‐work computation
FQDN‐based ID of the CES node
Signature of the CETP packet
The CA address for CES validation
Control
Dstep
caep
terminate
warning
ack
ttl
ratelimit
FQDN‐based destination endpoint ID
The CA address for endpoint validation
Contains session terminating information
Contains the warning information
The acknowledgement number
The time to live for session
The rate limit for session
ID
Fqdn
maid
moc
msisdn
FQDN‐based ID of the sender
The Mobile Assured ID
The Mobile Operator Certificate
The MSISDN number of the host
RLOC
ipv4
ipv6
eth
An IPv4 address (RLOC) of the CES
An IPv6 address (RLOC) of the CES
An MAC address (RLOC) of the CES
Payload
ipv4
ipv6
eth
IPv4 encapsulation of the user payload
IPv6 encapsulation of the user payload
Eth encapsulation of the user payload
Précédent

- 249/483

Suivant