NFV and NFV-based Security Services 355
Whether the consumable functions are at the infrastructure level, Infrastructure‐as‐a‐
Service (IaaS), platform level (PaaS) or the software level (SaaS), or anything in between
or in combinations, the flexibility and on‐demand nature of these services open up a
vibrant ecosystem of innovative partners who come up with a vast variety of ways to
consume the shared infrastructure and create value. This type of ecosystem is a must for
5G network builders to fully leverage and monetize their expensive investment. Operators
can also leverage each other’s investments and provide better services to their customers.
Monetizing fully the operators’ (and vendors’ , and partners’) collective investment is one
of the most strategically important factors in the success of 5G.
15.5.7 One Cloud
We have talked about the telco cloud as powered by NFV and related technologies so far.
But is there any fundamental reason that the telco cloud needs to be distinct from any IT
cloud? If we look at the long horizon (or even if one looks back in history), the answer is
no. Communication, as distinctive as it is, is closely intertwined with computing; future
applications, as envisioned in 5G and in IT industries, predominantly require both computing and communication. Therefore, it is a fair question to ask: Is there a One Cloud
into which we will eventually converge, regardless of IT or CT? It means that we are all
competing towards the same technology foundation that will one day meet many, if not
all, of our IT and CT needs. That day is already here in many market segments, and we
may see the contour of what it looks like and make decisions to better prepare for the
future. NFV is a major pillar in the foundation that will enable the networking industry
to turn its expertise into advantages in the converged one cloud.
15.6 NFV Security: Challenges and Opportunities
Because of the dynamic and loosely‐coupled nature of NFV, security – from solutions
to processes – must be embedded into it from day one as a basic fabric. This security
infrastructure, in identity services and role‐based access control (RBAC) for example,
has been developed and matured in the cloud computing space and is being adopted in
NFV. In this section, we will focus on new challenges and new opportunities brought
forth by NFV.
15.6.1 VNF Security Lifecycle and Trust
When a physical network device is introduced into an operational network, there is
established trust of this device due to the fact that this device was installed and configured by a trusted employee, delivered to a secured location by a trusted courier, and
developed and manufactured by a trusted vendor with a contract or a certification, and
so on. For VNFs, this chain of trust relationships needs to be created and maintained in
a NFV environment throughout its lifecycle.
A VNF’s lifecycle is illustrated in Figure 15.5.
A VNF has several important trust relationships, as shown in Figure 15.6.
In a private NFV environment, as in a private cloud – where NFV infrastructure,
MANO and OSS/BSS are in the hands of one administrator and all VNFs are managed
Whether the consumable functions are at the infrastructure level, Infrastructure‐as‐a‐
Service (IaaS), platform level (PaaS) or the software level (SaaS), or anything in between
or in combinations, the flexibility and on‐demand nature of these services open up a
vibrant ecosystem of innovative partners who come up with a vast variety of ways to
consume the shared infrastructure and create value. This type of ecosystem is a must for
5G network builders to fully leverage and monetize their expensive investment. Operators
can also leverage each other’s investments and provide better services to their customers.
Monetizing fully the operators’ (and vendors’ , and partners’) collective investment is one
of the most strategically important factors in the success of 5G.
15.5.7 One Cloud
We have talked about the telco cloud as powered by NFV and related technologies so far.
But is there any fundamental reason that the telco cloud needs to be distinct from any IT
cloud? If we look at the long horizon (or even if one looks back in history), the answer is
no. Communication, as distinctive as it is, is closely intertwined with computing; future
applications, as envisioned in 5G and in IT industries, predominantly require both computing and communication. Therefore, it is a fair question to ask: Is there a One Cloud
into which we will eventually converge, regardless of IT or CT? It means that we are all
competing towards the same technology foundation that will one day meet many, if not
all, of our IT and CT needs. That day is already here in many market segments, and we
may see the contour of what it looks like and make decisions to better prepare for the
future. NFV is a major pillar in the foundation that will enable the networking industry
to turn its expertise into advantages in the converged one cloud.
15.6 NFV Security: Challenges and Opportunities
Because of the dynamic and loosely‐coupled nature of NFV, security – from solutions
to processes – must be embedded into it from day one as a basic fabric. This security
infrastructure, in identity services and role‐based access control (RBAC) for example,
has been developed and matured in the cloud computing space and is being adopted in
NFV. In this section, we will focus on new challenges and new opportunities brought
forth by NFV.
15.6.1 VNF Security Lifecycle and Trust
When a physical network device is introduced into an operational network, there is
established trust of this device due to the fact that this device was installed and configured by a trusted employee, delivered to a secured location by a trusted courier, and
developed and manufactured by a trusted vendor with a contract or a certification, and
so on. For VNFs, this chain of trust relationships needs to be created and maintained in
a NFV environment throughout its lifecycle.
A VNF’s lifecycle is illustrated in Figure 15.5.
A VNF has several important trust relationships, as shown in Figure 15.6.
In a private NFV environment, as in a private cloud – where NFV infrastructure,
MANO and OSS/BSS are in the hands of one administrator and all VNFs are managed
