Customer Edge Switching: A Security Framework for 5G 225
more device security software vendors. The mobile operator could also itself cooperate
with security software vendors in the area of virus detection, and sell to its customers
the improved security services based on application level security processing in its
edge cloud.
9.5.1.3 Scalability
A CES in its basic architecture is composed of a separate data‐plane node and a data‐cen‑
tre hosted control plane. The data‐plane node is stackable; the operator buys more boxes
or blades as a function of the number of subscribers and traffic volume per subscriber.
The scalability of policy services can be achieved by a suitable grouping of subscribers
into classes or packages, where each class has the same policy for all subscribers. Such
grouping will also make it easier to sell mobile services to consumers who are unwilling
to be bothered with too much detail.
Using the same addressing principle as current mobile networks, each mobile device
resides in its own private address space. Device‐to‐device communication takes place
through CES nodes. The number of CES RLOCs depends on the type of outbound
interfaces supported in one or more CES data‐plane nodes, for example on 1 Gbit/s
levels to 100 Gbit/s levels.
9.5.1.4 Reliability
Each served mobile device will be able to reach another mobile or Internet host
through the mobile backhaul and core network. In case a CES DP node fails, the
virtualized SDN orchestration will move the users served by the failed DP node to
other DP nodes. The failure disables the use of failed DP routing locators for any
following use. Correspondingly, CES will start advertising new priorities for its rout‑
ing locators (RLOCs) to remote systems. To what extent it makes sense to develop
CES‐to‐CES recovery operations as compared to end‐to‐end recovery operations is
for further research.
9.5.2 Use Case 2: Corporate Gateway
9.5.2.1 Deployment and Operations
A corporation decides to pursue CES deployment. Arguably, the first to deploy CES as
a corporate network gateway are the companies with multiple sites and a need for
secure extranet connectivity. Since CES uses centralized policy management, the
company may also deploy a framework to manage policies in the centralized policy
database. To maintain a high level of security, the company will make contracts with
security software vendors who will support the company in policy creation and policy
constraints. Desktop management will link this with the policy management. The
company may optionally decide to share security incident information with a security
service provider, who may supply black‐, grey‐ and whitelists of remote networks in
return. Optionally, the company can have its own trust management. The adoption of
CES technology by many companies that cooperate with a security services provider
can also gradually lead to formation of a proper trust domain. An Internet service
provider would always be in a position to do network‐based monitoring in an efficient
manner. The company can either perform such monitoring itself or buy this function
as a service from its ISP.
more device security software vendors. The mobile operator could also itself cooperate
with security software vendors in the area of virus detection, and sell to its customers
the improved security services based on application level security processing in its
edge cloud.
9.5.1.3 Scalability
A CES in its basic architecture is composed of a separate data‐plane node and a data‐cen‑
tre hosted control plane. The data‐plane node is stackable; the operator buys more boxes
or blades as a function of the number of subscribers and traffic volume per subscriber.
The scalability of policy services can be achieved by a suitable grouping of subscribers
into classes or packages, where each class has the same policy for all subscribers. Such
grouping will also make it easier to sell mobile services to consumers who are unwilling
to be bothered with too much detail.
Using the same addressing principle as current mobile networks, each mobile device
resides in its own private address space. Device‐to‐device communication takes place
through CES nodes. The number of CES RLOCs depends on the type of outbound
interfaces supported in one or more CES data‐plane nodes, for example on 1 Gbit/s
levels to 100 Gbit/s levels.
9.5.1.4 Reliability
Each served mobile device will be able to reach another mobile or Internet host
through the mobile backhaul and core network. In case a CES DP node fails, the
virtualized SDN orchestration will move the users served by the failed DP node to
other DP nodes. The failure disables the use of failed DP routing locators for any
following use. Correspondingly, CES will start advertising new priorities for its rout‑
ing locators (RLOCs) to remote systems. To what extent it makes sense to develop
CES‐to‐CES recovery operations as compared to end‐to‐end recovery operations is
for further research.
9.5.2 Use Case 2: Corporate Gateway
9.5.2.1 Deployment and Operations
A corporation decides to pursue CES deployment. Arguably, the first to deploy CES as
a corporate network gateway are the companies with multiple sites and a need for
secure extranet connectivity. Since CES uses centralized policy management, the
company may also deploy a framework to manage policies in the centralized policy
database. To maintain a high level of security, the company will make contracts with
security software vendors who will support the company in policy creation and policy
constraints. Desktop management will link this with the policy management. The
company may optionally decide to share security incident information with a security
service provider, who may supply black‐, grey‐ and whitelists of remote networks in
return. Optionally, the company can have its own trust management. The adoption of
CES technology by many companies that cooperate with a security services provider
can also gradually lead to formation of a proper trust domain. An Internet service
provider would always be in a position to do network‐based monitoring in an efficient
manner. The company can either perform such monitoring itself or buy this function
as a service from its ISP.
