论文标题
迈向基于信任网络切片的虚拟基础架构的最终服务
Towards a Trust Aware Network Slice based End to End Services for Virtualised Infrastructures
论文作者
论文摘要
未来的通信网络(例如5G)有望支持几个具有不同要求的垂直市场的服务端到端交付。网络切片是一种关键构造,用于提供在共同的虚拟基础结构上运行的端到端逻辑虚拟网络,该网络是相互隔离的。在相同的5G基础架构上运行不同的网络切片在安全性和信任方面构成了一些挑战。本文讨论了网络切片信任的基本问题。它提出了一种基于信任模型和基于属性的信任证明机制,可用于评估组成网络切片的虚拟网络函数的信任。所提出的模型有助于确定虚拟网络功能的信任以及由虚拟平台(启动和运行时间)所满足的属性,这些属性部署了这些网络功能,以使其受到信任。我们提出了一种基于逻辑的语言,该语言为属性规范定义了简单的规则,以及评估这些属性的条件以满足可信赖的虚拟平台。提出的信任模型和机制使服务提供商能够确定网络服务的可信度以及用户开发值得信赖的应用程序。 。
Future communication networks such as 5G are expected to support end-to-end delivery of services for several vertical markets with diverging requirements. Network slicing is a key construct that is used to provide end to end logical virtual networks running on a common virtualised infrastructure, which are mutually isolated. Having different network slices operating over the same 5G infrastructure creates several challenges in security and trust. This paper addresses the fundamental issue of trust of a network slice. It presents a trust model and property-based trust attestation mechanisms which can be used to evaluate the trust of the virtual network functions that compose the network slice. The proposed model helps to determine the trust of the virtual network functions as well as the properties that should be satisfied by the virtual platforms (both at boot and run time) on which these network functions are deployed for them to be trusted. We present a logic-based language that defines simple rules for the specification of properties and the conditions under which these properties are evaluated to be satisfied for trusted virtualised platforms. The proposed trust model and mechanisms enable the service providers to determine the trustworthiness of the network services as well as the users to develop trustworthy applications. .