1 Orange
Moon
Security Management
System for OPNFV
Jamil Chawki & Ruan HE
Orange
OPNFV Summit
12/11/2015
2 Orange
Agenda
1 Introduction of OPNFV Security
2 Moon’s Functional Evolution
3 Moon’s Future Roadmap
3 Orange
Challenges for OPNFV Security
- Whole Cloud and SDN
(architecture, resources,
services) is dynamic
 Protection should adapt to
the dynamicity
Dynamic Control Programmable
Security
Extensible
Enforcement
End-to-end
Protection
- Resource pool of cloud
becomes flexible
 Security management system
should be reconfigurable
- Enforcements (PEP) are
heterogeneous and widely
deployed
 Security management should
cover all these mechanisms
- Security architecture and
security policy for user
requirements
 Handle deployment, installation,
configuration, destruction
4 Orange
Moon
Tenant Security Manager Infra Security ManagerSecurity Orchestrator Tenant Security Manager
Tenant
storage
vm
Tenant
vm
vm
Network Security Manager
NFV Protection Scenario
5 Orange
Moon Functional Architecture
Security Orchestrator
Cloud Infrastructure
AuthenticationMgr
AuthorizationMgr
MonitoringMgr
???Mgr
???Mgr
???Mgr
???Mgr
...
PEP PEP
PEP
??PEP ??PEP ??PEP
??PEP
Security Orchestrator
SDN Controller
AuthenticationMgr
AuthorizationMgr
MonitoringMgr
???Mgr
???Mgr
???Mgr
???Mgr
...
PEP PEP
PEP
??PEP ??PEP ??PEP
??PEP
6 Orange
Moon: Security
Management System
Cloud OpenStack
Swift NeutronNova …
Cloud
NFV
SDN Controller
OpenDaylight
Intra-tenant
Authorization
Intra-tenant
Admin
Attribute-
based
Encryption
Inter-tenant
Authorization
Monitoring
Moon: Security Management
System
Inter-tenant
Admin
Multi-side
Id Federation
OpenDaylight
Id Federation
OpenDaylight
Authorization
Federation
Moon Functional Evolution
7 Orange
Finished Version
Future Version
Q1 Q2Q3 Q4
2013 2014 2015 2016
Version1
Version 2
Version 3
Q4 Q1 Q2 Q3 Q4Q3 Q1Q1 Q2 Q3 Q4 Q1Q1 Q2 Q3 Q4
Moon Version Plan
Moon OPNFV Project
8 Orange
Achieved task
Future task
Q4 Q2
Moon for
OPNFV
Q1 Q2Q3
2014 2015 2016
Q1 Q2 Q3 Q4 Q1Q1 Q2 Q3 Q4 Q1Q1 Q2 Q3 Q4
Moon version 1
Project
approuved
by OPNFV
TSC
OPNFV
Project
Tickoff
Moon V2 in
OPNFV Rel C
Demo IdF for
OpenStack-
OpenDayligh
through Moon
Industralization Roadmap
OPNFV
Project
Session
Moon version 2 Moon version 3
9 Orangetitre de la présentation
merciThank you
For any question: ruan.he@orange.com

'Moon' Security Management System for OPNFV

  • 1.
    1 Orange Moon Security Management Systemfor OPNFV Jamil Chawki & Ruan HE Orange OPNFV Summit 12/11/2015
  • 2.
    2 Orange Agenda 1 Introductionof OPNFV Security 2 Moon’s Functional Evolution 3 Moon’s Future Roadmap
  • 3.
    3 Orange Challenges forOPNFV Security - Whole Cloud and SDN (architecture, resources, services) is dynamic  Protection should adapt to the dynamicity Dynamic Control Programmable Security Extensible Enforcement End-to-end Protection - Resource pool of cloud becomes flexible  Security management system should be reconfigurable - Enforcements (PEP) are heterogeneous and widely deployed  Security management should cover all these mechanisms - Security architecture and security policy for user requirements  Handle deployment, installation, configuration, destruction
  • 4.
    4 Orange Moon Tenant SecurityManager Infra Security ManagerSecurity Orchestrator Tenant Security Manager Tenant storage vm Tenant vm vm Network Security Manager NFV Protection Scenario
  • 5.
    5 Orange Moon FunctionalArchitecture Security Orchestrator Cloud Infrastructure AuthenticationMgr AuthorizationMgr MonitoringMgr ???Mgr ???Mgr ???Mgr ???Mgr ... PEP PEP PEP ??PEP ??PEP ??PEP ??PEP Security Orchestrator SDN Controller AuthenticationMgr AuthorizationMgr MonitoringMgr ???Mgr ???Mgr ???Mgr ???Mgr ... PEP PEP PEP ??PEP ??PEP ??PEP ??PEP
  • 6.
    6 Orange Moon: Security ManagementSystem Cloud OpenStack Swift NeutronNova … Cloud NFV SDN Controller OpenDaylight Intra-tenant Authorization Intra-tenant Admin Attribute- based Encryption Inter-tenant Authorization Monitoring Moon: Security Management System Inter-tenant Admin Multi-side Id Federation OpenDaylight Id Federation OpenDaylight Authorization Federation Moon Functional Evolution
  • 7.
    7 Orange Finished Version FutureVersion Q1 Q2Q3 Q4 2013 2014 2015 2016 Version1 Version 2 Version 3 Q4 Q1 Q2 Q3 Q4Q3 Q1Q1 Q2 Q3 Q4 Q1Q1 Q2 Q3 Q4 Moon Version Plan Moon OPNFV Project
  • 8.
    8 Orange Achieved task Futuretask Q4 Q2 Moon for OPNFV Q1 Q2Q3 2014 2015 2016 Q1 Q2 Q3 Q4 Q1Q1 Q2 Q3 Q4 Q1Q1 Q2 Q3 Q4 Moon version 1 Project approuved by OPNFV TSC OPNFV Project Tickoff Moon V2 in OPNFV Rel C Demo IdF for OpenStack- OpenDayligh through Moon Industralization Roadmap OPNFV Project Session Moon version 2 Moon version 3
  • 9.
    9 Orangetitre dela présentation merciThank you For any question: ruan.he@orange.com