Kabir, Kantola, and Llorente Santos
226
9.5.2.2 Security Benefits
Besides the fact that policy management will be centralized, it is possible to have a uniform
policy across the whole company. Intranet traffic protection for a company’s site‐to‐site
connections is by default available using encrypted CES‐to‐CES tunnels. Using CES,
security will be an integrated feature for end‐ and network‐based systems. A company
can enter into extranet contracts with remote partners running CES networks, such that
some security rules are agreed and implemented by CES policy management and the
corresponding operational processes. For example, if a company is in manufacturing
(i.e. a paper mill) and has lots
1
of sensors and actuators served through 5G radio, these
devices would have been supplied by a number of vendors that also provide technical
maintenance for the manufacturing company. Each outsourcing contract would imply a
policy that gives vendor access to a set of wireless devices in the manufacturing company’s
network. Both parties of the outsourcing contract in this case would use CES nodes to
enforce the policies (agreed in the contract) for secure communication.
9.5.2.3 Scalability
The scalability challenge in this case is mostly a subset of the use‐case of mobile broad‑
band. It makes sense to connect each Ethernet level VLAN and the corresponding IP
subnet to CES for applying a consistent security policy in the intranet, for communica‑
tion between the subnets. Alternatively, legacy corporate‐network routers can be used
to connect the subnets in the corporate network, and then from the CES perspective, all
the hosts of a corporate network are not in different address spaces and thus CES can‑
not offer a means for controlling the intranet traffic across subnets. Naturally, outside
the scope of CES security, a company can have servers with globally unique IP addresses
providing services to the public.
9.5.2.4 Reliability
CES will support multi‐homing to several ISPs. It can choose to advertise different pri‑
orities of its RLOCs to different remote CES systems.
9.5.3 Use Case 3: National CERT Centric Trust Domain
9.5.3.1 Deployment and Operations
One or several ISPs or mobile operators with packet services deploy CES nodes for
providing security services to consumers, both mobile and wire‐line. The ISP can also
offer Carrier‐Grade Realm Gateway services, which allows its subscribers to run servers
on their hosts in a controlled manner. The ISP or mobile operator can host CES services
for companies offering the option of outsourced security services to other firms. In this
case, the ISP will cooperate with security software vendors for policy constraints, etc.
The individual corporations can opt to deploy their own CES services, but this will
cause reluctance to share security incident information because of the reason discussed
earlier. At this stage, the benefits of CES adoption come from allowing servers in private
address space, coherent and uniform policy management, and the possibility of patching
1 A paper mill would, e.g. have some 20 000 to 30 000 sensors for monitoring different aspects of the
production process.
226
9.5.2.2 Security Benefits
Besides the fact that policy management will be centralized, it is possible to have a uniform
policy across the whole company. Intranet traffic protection for a company’s site‐to‐site
connections is by default available using encrypted CES‐to‐CES tunnels. Using CES,
security will be an integrated feature for end‐ and network‐based systems. A company
can enter into extranet contracts with remote partners running CES networks, such that
some security rules are agreed and implemented by CES policy management and the
corresponding operational processes. For example, if a company is in manufacturing
(i.e. a paper mill) and has lots
1
of sensors and actuators served through 5G radio, these
devices would have been supplied by a number of vendors that also provide technical
maintenance for the manufacturing company. Each outsourcing contract would imply a
policy that gives vendor access to a set of wireless devices in the manufacturing company’s
network. Both parties of the outsourcing contract in this case would use CES nodes to
enforce the policies (agreed in the contract) for secure communication.
9.5.2.3 Scalability
The scalability challenge in this case is mostly a subset of the use‐case of mobile broad‑
band. It makes sense to connect each Ethernet level VLAN and the corresponding IP
subnet to CES for applying a consistent security policy in the intranet, for communica‑
tion between the subnets. Alternatively, legacy corporate‐network routers can be used
to connect the subnets in the corporate network, and then from the CES perspective, all
the hosts of a corporate network are not in different address spaces and thus CES can‑
not offer a means for controlling the intranet traffic across subnets. Naturally, outside
the scope of CES security, a company can have servers with globally unique IP addresses
providing services to the public.
9.5.2.4 Reliability
CES will support multi‐homing to several ISPs. It can choose to advertise different pri‑
orities of its RLOCs to different remote CES systems.
9.5.3 Use Case 3: National CERT Centric Trust Domain
9.5.3.1 Deployment and Operations
One or several ISPs or mobile operators with packet services deploy CES nodes for
providing security services to consumers, both mobile and wire‐line. The ISP can also
offer Carrier‐Grade Realm Gateway services, which allows its subscribers to run servers
on their hosts in a controlled manner. The ISP or mobile operator can host CES services
for companies offering the option of outsourced security services to other firms. In this
case, the ISP will cooperate with security software vendors for policy constraints, etc.
The individual corporations can opt to deploy their own CES services, but this will
cause reluctance to share security incident information because of the reason discussed
earlier. At this stage, the benefits of CES adoption come from allowing servers in private
address space, coherent and uniform policy management, and the possibility of patching
1 A paper mill would, e.g. have some 20 000 to 30 000 sensors for monitoring different aspects of the
production process.
