3. 3 Orange
Challenges for OPNFV Security
- Whole Cloud and SDN
(architecture, resources,
services) is dynamic
Protection should adapt to
the dynamicity
Dynamic Control Programmable
Security
Extensible
Enforcement
End-to-end
Protection
- Resource pool of cloud
becomes flexible
Security management system
should be reconfigurable
- Enforcements (PEP) are
heterogeneous and widely
deployed
Security management should
cover all these mechanisms
- Security architecture and
security policy for user
requirements
Handle deployment, installation,
configuration, destruction
4. 4 Orange
Moon
Tenant Security Manager Infra Security ManagerSecurity Orchestrator Tenant Security Manager
Tenant
storage
vm
Tenant
vm
vm
Network Security Manager
NFV Protection Scenario
5. 5 Orange
Moon Functional Architecture
Security Orchestrator
Cloud Infrastructure
AuthenticationMgr
AuthorizationMgr
MonitoringMgr
???Mgr
???Mgr
???Mgr
???Mgr
...
PEP PEP
PEP
??PEP ??PEP ??PEP
??PEP
Security Orchestrator
SDN Controller
AuthenticationMgr
AuthorizationMgr
MonitoringMgr
???Mgr
???Mgr
???Mgr
???Mgr
...
PEP PEP
PEP
??PEP ??PEP ??PEP
??PEP
6. 6 Orange
Moon: Security
Management System
Cloud OpenStack
Swift NeutronNova …
Cloud
NFV
SDN Controller
OpenDaylight
Intra-tenant
Authorization
Intra-tenant
Admin
Attribute-
based
Encryption
Inter-tenant
Authorization
Monitoring
Moon: Security Management
System
Inter-tenant
Admin
Multi-side
Id Federation
OpenDaylight
Id Federation
OpenDaylight
Authorization
Federation
Moon Functional Evolution
7. 7 Orange
Finished Version
Future Version
Q1 Q2Q3 Q4
2013 2014 2015 2016
Version1
Version 2
Version 3
Q4 Q1 Q2 Q3 Q4Q3 Q1Q1 Q2 Q3 Q4 Q1Q1 Q2 Q3 Q4
Moon Version Plan
Moon OPNFV Project
8. 8 Orange
Achieved task
Future task
Q4 Q2
Moon for
OPNFV
Q1 Q2Q3
2014 2015 2016
Q1 Q2 Q3 Q4 Q1Q1 Q2 Q3 Q4 Q1Q1 Q2 Q3 Q4
Moon version 1
Project
approuved
by OPNFV
TSC
OPNFV
Project
Tickoff
Moon V2 in
OPNFV Rel C
Demo IdF for
OpenStack-
OpenDayligh
through Moon
Industralization Roadmap
OPNFV
Project
Session
Moon version 2 Moon version 3
9. 9 Orangetitre de la présentation
merciThank you
For any question: ruan.he@orange.com