Mobile Virtual Network Operators (MVNO) Security 327
(state transition) is an example of control plane signaling, which may introduce
delays in 5G security. The user enabled security feature is another aspect to be considered in 5G networks. In current mobile networks, it is MVNO who decide which
and when security mechanisms should be applied, while it would be more feasible if
the user could enable the security feature voluntarily, depending on the needs of the
application used [12].
In general, it is possible to build 5G security based on 4G security mechanisms considering their significant robustness. On the other hand, we cannot yet introduce a certain
security model for 5G, since its architecture has not been finalized. Therefore, in this
chapter, we concentrate on MVNO security for the cloud environment, regardless of the
generation (4G or 5G).
To fulfill security requirements such as availability, integrity and AAA, we need to
address TaaS vulnerabilities. We assume that these requirements will be applied in
some way also on 5G networks. In Figure 14.2, TaaS security issues are classified into
three main aspects:
1) Data Security;
2) Hypervisor and VM security, which covers SDN and NFV security; and
3) Application Security.
14.4.1 Data Security in TaaS
Mobile operators that act as cloud providers are responsible for their customer data
protection. The customers are either end users or other mobile operators. Herein we
define data vulnerabilities based on the security requirements:
1) Authentication, authorization and accounting: refers to the access control mechanism that is used against unauthorized access or privilege logging. In this scenario,
an attacker tries to modify, corrupt, steal and intercept the data of Control Plane
(CP) and User Plane (UP). In addition to account control, telecom operators that act
as a cloud provider should also consider other aspects of data protection;
Integrity
AAA
Availability
SDN and NFV
security
Hypervisor and
VM security
OPNFV security
Application
security
Data security
Figure 14.2 TaaS security classification.
(state transition) is an example of control plane signaling, which may introduce
delays in 5G security. The user enabled security feature is another aspect to be considered in 5G networks. In current mobile networks, it is MVNO who decide which
and when security mechanisms should be applied, while it would be more feasible if
the user could enable the security feature voluntarily, depending on the needs of the
application used [12].
In general, it is possible to build 5G security based on 4G security mechanisms considering their significant robustness. On the other hand, we cannot yet introduce a certain
security model for 5G, since its architecture has not been finalized. Therefore, in this
chapter, we concentrate on MVNO security for the cloud environment, regardless of the
generation (4G or 5G).
To fulfill security requirements such as availability, integrity and AAA, we need to
address TaaS vulnerabilities. We assume that these requirements will be applied in
some way also on 5G networks. In Figure 14.2, TaaS security issues are classified into
three main aspects:
1) Data Security;
2) Hypervisor and VM security, which covers SDN and NFV security; and
3) Application Security.
14.4.1 Data Security in TaaS
Mobile operators that act as cloud providers are responsible for their customer data
protection. The customers are either end users or other mobile operators. Herein we
define data vulnerabilities based on the security requirements:
1) Authentication, authorization and accounting: refers to the access control mechanism that is used against unauthorized access or privilege logging. In this scenario,
an attacker tries to modify, corrupt, steal and intercept the data of Control Plane
(CP) and User Plane (UP). In addition to account control, telecom operators that act
as a cloud provider should also consider other aspects of data protection;
Integrity
AAA
Availability
SDN and NFV
security
Hypervisor and
VM security
OPNFV security
Application
security
Data security
Figure 14.2 TaaS security classification.
