Customer Edge Switching: A Security Framework for 5G 227
vulnerabilities in the end systems using the operator or company CES. For example,
when it is known that a consumer has deployed a vulnerable gadget such as an Internet
TV or a game‐box in its network, the operator can use its policy management and CES
to block all suspicious traffic to and from such gadgets. For this to be practical, ISPs
must have a way of earning revenue from better security services to the end systems.
One possibility could be that the national regulator will set a price for such a service.
The recent cases, where hackers built a botnet of nearly 10 million such gadgets and
targeted DDoS floods of a Terabit per second, motivates this kind of vulnerability patch‑
ing, as well as pricing mode. The problem stems from the fact that it is fully accepted to
sell the gadgets that require Internet connectivity to a consumer, without testing for
their security compliance or even their software update capability.
After this initial stage, the national CERT can decide to deploy dynamic trust management
for the national networks, and either runs the Global Trust Operator (GTO) function itself
or delegates that function to a firm. Homomorphic security is used in security incident
reporting and report aggregation. This will increase the willingness of companies to share
their security incidents. The earlier deployed CES nodes at ISPs, mobile operators and
companies then execute the black‐, grey‐ and whitelisting policies as instructed by GTO.
The adoption of GTO functions will be supported by national regulation that already
today sets the rules for ISP‐based network monitoring, so that the privacy of communica‑
tion is maintained. The regulator also mandates the security incident sharing obligations,
and as a result national infrastructure will benefit from GTO functions to improve their
robustness against the cyber warfare as well as hacking by criminals.
9.5.3.2 Security Benefits
When national GTO has been deployed and most customer networks are protected by
cooperative firewalls that automatically react to GTO authorized blacklists, DDoSing of
legitimate services will be much harder than before. The patching of vulnerable consumer
gadgets would lead to reduced Bot penetration at the national level, and contribute to
improved security of national infrastructures. Another possibility could be to use black‑
lists and build a national firewall against all cross‐border traffic, but this is rather costly
and perhaps will not be needed on all borders.
9.5.3.3 Scalability
The use of homomorphic encryption contributes to trust management at the national
level. We implemented this in [9]. The experiments show that the approach is feasible.
Stackable data plane nodes and cloud‐based control plane ensure CES level scalability.
9.5.3.4 Reliability
Even if the GTO is temporarily unavailable, the pre‐existing black‐, grey‐ and whitelists
can still contribute to protect attacks from known blacklists.
9.5.4 Use Case 4: Industrial Internet for Road Traffic and Transport
9.5.4.1 Deployment and Operations
For the data traffic that comes to and from vehicles, which will either have human driv‑
ers or be operated remotely by fleet control pilots, a 5G network slice is created for road
safety related data. Such a slice can span several countries. The resources for packet
vulnerabilities in the end systems using the operator or company CES. For example,
when it is known that a consumer has deployed a vulnerable gadget such as an Internet
TV or a game‐box in its network, the operator can use its policy management and CES
to block all suspicious traffic to and from such gadgets. For this to be practical, ISPs
must have a way of earning revenue from better security services to the end systems.
One possibility could be that the national regulator will set a price for such a service.
The recent cases, where hackers built a botnet of nearly 10 million such gadgets and
targeted DDoS floods of a Terabit per second, motivates this kind of vulnerability patch‑
ing, as well as pricing mode. The problem stems from the fact that it is fully accepted to
sell the gadgets that require Internet connectivity to a consumer, without testing for
their security compliance or even their software update capability.
After this initial stage, the national CERT can decide to deploy dynamic trust management
for the national networks, and either runs the Global Trust Operator (GTO) function itself
or delegates that function to a firm. Homomorphic security is used in security incident
reporting and report aggregation. This will increase the willingness of companies to share
their security incidents. The earlier deployed CES nodes at ISPs, mobile operators and
companies then execute the black‐, grey‐ and whitelisting policies as instructed by GTO.
The adoption of GTO functions will be supported by national regulation that already
today sets the rules for ISP‐based network monitoring, so that the privacy of communica‑
tion is maintained. The regulator also mandates the security incident sharing obligations,
and as a result national infrastructure will benefit from GTO functions to improve their
robustness against the cyber warfare as well as hacking by criminals.
9.5.3.2 Security Benefits
When national GTO has been deployed and most customer networks are protected by
cooperative firewalls that automatically react to GTO authorized blacklists, DDoSing of
legitimate services will be much harder than before. The patching of vulnerable consumer
gadgets would lead to reduced Bot penetration at the national level, and contribute to
improved security of national infrastructures. Another possibility could be to use black‑
lists and build a national firewall against all cross‐border traffic, but this is rather costly
and perhaps will not be needed on all borders.
9.5.3.3 Scalability
The use of homomorphic encryption contributes to trust management at the national
level. We implemented this in [9]. The experiments show that the approach is feasible.
Stackable data plane nodes and cloud‐based control plane ensure CES level scalability.
9.5.3.4 Reliability
Even if the GTO is temporarily unavailable, the pre‐existing black‐, grey‐ and whitelists
can still contribute to protect attacks from known blacklists.
9.5.4 Use Case 4: Industrial Internet for Road Traffic and Transport
9.5.4.1 Deployment and Operations
For the data traffic that comes to and from vehicles, which will either have human driv‑
ers or be operated remotely by fleet control pilots, a 5G network slice is created for road
safety related data. Such a slice can span several countries. The resources for packet
