NFV and NFV-based Security Services 351
As we will stress in this chapter, NFV should also be viewed as a step towards a service
provider cloud, with all the benefits of cloud computing. This includes business model
innovations, for example, Infrastructure as a Service (IaaS), Platform as a Service (PaaS),
and Software as a Service (SaaS), adopted in the telecom world. These models of service
deployment (collectively abbreviated as XaaS) bring up multi‐tenancy‐related security
questions, as well as issues related to trust relationships and roles between different
levels of service providers.
All of these NFV‐based technology enablers promise a new generation of security
products and services that will go far beyond what the industry has been accustomed to.
Many researchers in academic and industry, as well as innovative entrepreneurs, have
been actively working in this area and are bringing them to market in some cases. In
Section 15.7, we will survey some of the work to illustrate the huge potential that NFV
and the telco cloud bring to 5G and future networks.
Figure 15.3 summarizes the relationship between 5G security and NFV. The two
significantly overlap; NFV brings new challenges related to security as well as new
opportunities that can solve many security requirements in 5G and beyond.
Next, let us devote a short section to better clarify the overlap and differences between
three terms that some use interchangeably but that others separate for various
(and good) reasons; while many simply use the combination “NFV/SDN” to avoid this
question. Our short discussion here is not motivated to sway opinions in any direction,
but rather only to clarify and to avoid any confusion for the rest of the chapter.
15.4 NFV, SDN, and a Telco Cloud
Software Defined Networking (SDN) started as a proposal to separate a network switch’s
control plane from its data plane, and centralize the control plane in a software entity
called a Controller, where new behaviors can be programmed in a relatively easy fashion
without modifying the switch itself. It is also commonly associated with the protocol
that the proponents proposed to realize such a design: OpenFlow [5]. Open Network
Foundation (ONF) [6] was later formed to develop this vision further.
As with many good things in life, the basic concept of SDN has been stretched in all
directions since its origin, and it can be difficult to tell when someone is referring to
5G security
NFV security
NFV-based
solutions that
enhance 5G
security
Figure 15.3 5G Security and NFV.
As we will stress in this chapter, NFV should also be viewed as a step towards a service
provider cloud, with all the benefits of cloud computing. This includes business model
innovations, for example, Infrastructure as a Service (IaaS), Platform as a Service (PaaS),
and Software as a Service (SaaS), adopted in the telecom world. These models of service
deployment (collectively abbreviated as XaaS) bring up multi‐tenancy‐related security
questions, as well as issues related to trust relationships and roles between different
levels of service providers.
All of these NFV‐based technology enablers promise a new generation of security
products and services that will go far beyond what the industry has been accustomed to.
Many researchers in academic and industry, as well as innovative entrepreneurs, have
been actively working in this area and are bringing them to market in some cases. In
Section 15.7, we will survey some of the work to illustrate the huge potential that NFV
and the telco cloud bring to 5G and future networks.
Figure 15.3 summarizes the relationship between 5G security and NFV. The two
significantly overlap; NFV brings new challenges related to security as well as new
opportunities that can solve many security requirements in 5G and beyond.
Next, let us devote a short section to better clarify the overlap and differences between
three terms that some use interchangeably but that others separate for various
(and good) reasons; while many simply use the combination “NFV/SDN” to avoid this
question. Our short discussion here is not motivated to sway opinions in any direction,
but rather only to clarify and to avoid any confusion for the rest of the chapter.
15.4 NFV, SDN, and a Telco Cloud
Software Defined Networking (SDN) started as a proposal to separate a network switch’s
control plane from its data plane, and centralize the control plane in a software entity
called a Controller, where new behaviors can be programmed in a relatively easy fashion
without modifying the switch itself. It is also commonly associated with the protocol
that the proponents proposed to realize such a design: OpenFlow [5]. Open Network
Foundation (ONF) [6] was later formed to develop this vision further.
As with many good things in life, the basic concept of SDN has been stretched in all
directions since its origin, and it can be difficult to tell when someone is referring to
5G security
NFV security
NFV-based
solutions that
enhance 5G
security
Figure 15.3 5G Security and NFV.
