Kabir, Kantola, and Llorente Santos
228
transport in the slice could be obtained by contracts with a number of incumbent
operators. The company operating the slice will aim to provide a highly secure and
robust network. The slice will have its own core‐network control plane and uses CES
control/data plane nodes for interconnecting different segments. In addition, the fleet
control centres and other road transport related servers will be connected to the slice. A
fleet control centre may have a gateway to the Internet on application layer. The slice,
for example, can carry the telemetry from vehicles to fleet control: a vehicle will have
many cameras, and the video feed from any camera can be streamed through the slice
to the corresponding fleet control centre at any time. The slice may have edge comput‑
ing servers for the purpose of collecting locally relevant information from the vehicles
or delivering the locally relevant information. Edge computing infrastructure can, for
example, be rented from the incumbent mobile operators. By allowing only security
certified devices to connect to the slice, the security can be further hardened.
9.5.4.2 Security Benefits
By re‐using 5G technology and choosing CES to control ‐access to the wireless seg‑
ments, as well as to the data centres, we create an isolated secure network where all
traffic may be encrypted and carried edge‐to‐edge after mutual authentication.
9.5.4.3 Scalability
Clearly, all the values here reside in the end devices and the network edge. Naturally, the
services are available in the coverage area of the underlying mobile networks. The
allocated transport resources do not need to be static. The orchestration functions in
the slice and the underlying mobile network controller may have an on‐line interface for
requesting additional transport capacity to and from particular base stations, where
more vehicles are arriving as well as releasing capacity that is no longer needed.
9.5.4.4 Reliability
By sufficiently generous dimensioning of the resources and an online link to the
controller of the underlying mobile networks, the slice can deliver high reliability
of services. Each fleet data centre runs on a high availability platform and can have
multiple CES nodes for the interconnection to the slice.
9.6 Conclusion
This chapter identifies the security challenges faced by state‐of‐the‐art in mobile
networks and introduces CES as a framework that can address the classical weak‑
nesses of the Internet, and provides means to protect Internet networks, such as
mobile networks, against a constantly evolving threat landscape. Compared to best‐
effort nature of the Internet that solely attends to the interests of the sender, and is
often abused by hackers, the policy‐based communication in CES allows negotiating
the interests of the sender with the receiver interests and thus filters the unwanted
traffic. The adoption of CES allows individual users, hosts or application to express
their interests in terms of a policy and hence control the traffic they deem interesting.
A policy can specify the set of requirements for establishing a communication.
A CES node is deployed at the network edge, where it replaces NATs, and acts as a
228
transport in the slice could be obtained by contracts with a number of incumbent
operators. The company operating the slice will aim to provide a highly secure and
robust network. The slice will have its own core‐network control plane and uses CES
control/data plane nodes for interconnecting different segments. In addition, the fleet
control centres and other road transport related servers will be connected to the slice. A
fleet control centre may have a gateway to the Internet on application layer. The slice,
for example, can carry the telemetry from vehicles to fleet control: a vehicle will have
many cameras, and the video feed from any camera can be streamed through the slice
to the corresponding fleet control centre at any time. The slice may have edge comput‑
ing servers for the purpose of collecting locally relevant information from the vehicles
or delivering the locally relevant information. Edge computing infrastructure can, for
example, be rented from the incumbent mobile operators. By allowing only security
certified devices to connect to the slice, the security can be further hardened.
9.5.4.2 Security Benefits
By re‐using 5G technology and choosing CES to control ‐access to the wireless seg‑
ments, as well as to the data centres, we create an isolated secure network where all
traffic may be encrypted and carried edge‐to‐edge after mutual authentication.
9.5.4.3 Scalability
Clearly, all the values here reside in the end devices and the network edge. Naturally, the
services are available in the coverage area of the underlying mobile networks. The
allocated transport resources do not need to be static. The orchestration functions in
the slice and the underlying mobile network controller may have an on‐line interface for
requesting additional transport capacity to and from particular base stations, where
more vehicles are arriving as well as releasing capacity that is no longer needed.
9.5.4.4 Reliability
By sufficiently generous dimensioning of the resources and an online link to the
controller of the underlying mobile networks, the slice can deliver high reliability
of services. Each fleet data centre runs on a high availability platform and can have
multiple CES nodes for the interconnection to the slice.
9.6 Conclusion
This chapter identifies the security challenges faced by state‐of‐the‐art in mobile
networks and introduces CES as a framework that can address the classical weak‑
nesses of the Internet, and provides means to protect Internet networks, such as
mobile networks, against a constantly evolving threat landscape. Compared to best‐
effort nature of the Internet that solely attends to the interests of the sender, and is
often abused by hackers, the policy‐based communication in CES allows negotiating
the interests of the sender with the receiver interests and thus filters the unwanted
traffic. The adoption of CES allows individual users, hosts or application to express
their interests in terms of a policy and hence control the traffic they deem interesting.
A policy can specify the set of requirements for establishing a communication.
A CES node is deployed at the network edge, where it replaces NATs, and acts as a
