 |
Work Item Reference |
ETSI Doc. Number |
STF |
Technical Body in Charge |
Standard Not Ready For Download
|
|
DGS/NFV-SEC026
|
GS NFV-SEC 026
|
|
NFV SEC
|
|
Current Status (Click to View Full Schedule) |
Latest Version
|
Cover Date |
Standstill |
Creation Date |
|
Final draft for approval (2025-03-31)
|
0.0.16 Draft
|
|
View Standstill Information
|
2020-01-23
|
|
Rapporteur |
Technical Officer |
Harmonised Standard |
|
|
Anne-Marie Praden
|
Antoine Mouquet
|
No
|
|
|
Title
|
Network Functions Virtualisation (NFV); Security; Isolation and trust domain specification Isolation and trust domain
|
Scope and Field of Application
|
This work item will define the requirements and solutions for the NFV System to enhance network functions and services isolation between tenants. This includes: o Analysis of the threat models o Trust domain separation (multi-tenant NFVI, traffic and resource separation, tenant-dependant resource management and access control..) o Memory protection and access control (protection against memory introspection, confidentiality of sensitive data and credentials), o Hypervisor trust partitioning o The Virtualization Container (e.g. Virtual Machine and OS container) Escape protection (e.g. protection against VNF compromizing its local host OS, taking control of the hypervisor and then gaining access to private and sensitive data of co-resident Virtualization Containers) . o Associated key management system for all above items. The WI will take into account the output of GR NFV-EVE018 WI concerning the multi-tenancy.
|
Supporting Organizations
|
Orange, THALES, TELEFONICA S.A., OTD, SPRINT Corporation, BT plc
|