SlideShare a Scribd company logo
© 2014 Stoke
Securing the LTE Core – the Road
to NFV
| Proprietary and Confidential
Dilip Pillaipakam
Vice President, Product Management and Marketing
© 2014 Stoke
The LTE Security Framework
2
S9
S1-C
Internet
S1-U S5/S8
S6A
Gx
Gz/Gy
Other LTE
Network
S11
RAN-Core
Border
SEG
The border between RAN and Core (S1) requires protection against specific risks to
critical infrastructure at that interface
Control Plane Functions
-  IKE
-  AAA
-  Routing
DRA
SBC
IMS
Core
SGW
MME
CSCF
Internet Border
Policy / Charging
Control
SGi
Data Plane Functions
-  Forwarding
-  QoS
-  ACL
-  Packet Inspection
Device and
Application
© 2014 Stoke
LTE Security at the S1 Link –
Emerging Trends
3
Challenge Requirements
Stronger Security
•  2048 bit key length
•  PKI
Signaling Protection -
New Threat Vectors
•  Protect core - exponential transaction increase
•  S1 protocol/state validation
VoLTE Rollout
•  Low latency transport
•  Sub-1 second recovery
Elastic Deployment
•  Virtualized security gateway on COTS
•  SDN integration
Scalable Small Cell
Deployments
•  Dense session aggregation
•  Intelligent load balancing
© 2014 Stoke
Use Case: Macro and Small Cell
Security
4
»  Unsecured backhaul
»  Rapidly increasing throughput
»  High tunnel density
»  Ultra-low latency
»  Directly impacts subscriber QoE
44
MME
SGW
Office
Home
Outdoor
Metrocell
Small
Cells
4G LTE
EPC
Millions of
Tunnels
MME
SGW
EPC
E2E Latency Budget = 100 ms
VoLTE:
Low Latency
Small Packets
High Bandwidth
© 2014 Stoke
Office
Home
Outdoor
Metrocell
Small
Cells
Use Case: Signaling Overload
»  Signaling Overload Threats
»  Application initiated
»  Compromised eNodeBs
»  Natural disasters
»  Prioritized Traffic
»  Already connected subscribers
»  Specific eNodeBs
SGW
4G LTE
EPCMillions of
Service
Requests
MME
Application
Update
Server
QoE: Prioritize
5
© 2014 Stoke
The LTE Security Framework
vSEG Phase 1
6
S9
Internet
S5/S8
S6A
Gx
Gz/Gy
Other LTE
Network
S11
RAN-Core Border
Control Plane Functions
-  IKE
-  AAA
-  Routing
DRA
SBC
IMS
Core
SGW
MME
CSCF
Internet Border
Policy / Charging
Control
SGi
Data Plane Functions
-  Forwarding
-  QoS
-  ACL
-  Inspections
Device and
Application
»  vSEG on COTS hardware on
Linux
»  Similar deployment and
operational model as today
»  Benefits:
»  Removes restriction of physical
chassis
»  scale to very large number of line
cards
SEG
v-SEG
(DP)
v-SEG
(CP)
© 2014 Stoke
The LTE Security Framework
vSEG Phase 2
7
Other LTE
Network
SGW
MME
DRA
SBC
CSCF
Internet Border
Policy / Charging Control
Internet
S1-C
S1-U
Internet
V-EPC
RAN-Core Border
v-SEG
(DP)
v-SEG
(CP)
Security
Gateway Cloud
QoS InspectionACLs
IKE AAA Routing
SEG Controller
SDN
Controller
»  Disaggregate control plane and
data plane functions to scale each
function independently.
»  Can be integrated with Operator's
SDN infrastructure
»  Benefits
»  Fully elastic on-demand
deployment
»  Capacity can be added dynamically
by adding more service nodes
»  Scale some functions
disproportionately
© 2014 Stoke
Conclusions
8
»  Each domain of the LTE Security Framework provides
protection against specific threats and therefore has unique
functional and performance requirements
»  S1 Link has stringent performance and latency requirements
»  Purpose built platforms will remain the mainstay for next few
years
»  Virtualization has benefits, but is not the answer for all use
cases
| Proprietary and Confidential

More Related Content

What's hot

What's hot (20)

Network Slicing overview_v6
Network Slicing overview_v6Network Slicing overview_v6
Network Slicing overview_v6
 
Realising the Immediate Benefits of SDN and NFV
Realising the Immediate Benefits of SDN and NFVRealising the Immediate Benefits of SDN and NFV
Realising the Immediate Benefits of SDN and NFV
 
PLNOG22 - Avi Alkobi - Network Telemetry, Visibility and all in between, can ...
PLNOG22 - Avi Alkobi - Network Telemetry, Visibility and all in between, can ...PLNOG22 - Avi Alkobi - Network Telemetry, Visibility and all in between, can ...
PLNOG22 - Avi Alkobi - Network Telemetry, Visibility and all in between, can ...
 
NovoNet Vision and Operators' Perspective for ONAP
NovoNet Vision and Operators' Perspective for ONAPNovoNet Vision and Operators' Perspective for ONAP
NovoNet Vision and Operators' Perspective for ONAP
 
5G Microservices
5G Microservices5G Microservices
5G Microservices
 
Aci presentation
Aci presentationAci presentation
Aci presentation
 
Introduction to Tungsten Fabric and the vRouter
Introduction to Tungsten Fabric and the vRouterIntroduction to Tungsten Fabric and the vRouter
Introduction to Tungsten Fabric and the vRouter
 
Fostering the Evolution of Network Based Cloud Service Providers.
Fostering the Evolution of Network Based Cloud Service Providers.Fostering the Evolution of Network Based Cloud Service Providers.
Fostering the Evolution of Network Based Cloud Service Providers.
 
SDN/NFV architecture vision and reality
SDN/NFV architecture vision and reality SDN/NFV architecture vision and reality
SDN/NFV architecture vision and reality
 
CisCon 2018 - SDN, complessità e TCO: non c’è un modo più semplice?
CisCon 2018 -  SDN, complessità e TCO: non c’è un modo più semplice?CisCon 2018 -  SDN, complessità e TCO: non c’è un modo più semplice?
CisCon 2018 - SDN, complessità e TCO: non c’è un modo più semplice?
 
Microservices K8S
Microservices K8SMicroservices K8S
Microservices K8S
 
Revolutionizing IT and Telecom Industry with OpenStack, SDN and NFV
Revolutionizing IT and Telecom Industry with OpenStack, SDN and NFVRevolutionizing IT and Telecom Industry with OpenStack, SDN and NFV
Revolutionizing IT and Telecom Industry with OpenStack, SDN and NFV
 
Independent Validation of Cisco’s Multi Vendor Support
Independent Validation of Cisco’s Multi Vendor SupportIndependent Validation of Cisco’s Multi Vendor Support
Independent Validation of Cisco’s Multi Vendor Support
 
Implementing vCPE with OpenStack and Software Defined Networks
Implementing vCPE with OpenStack and Software Defined NetworksImplementing vCPE with OpenStack and Software Defined Networks
Implementing vCPE with OpenStack and Software Defined Networks
 
SDN-Based Enterprise Connectivity Service
SDN-Based Enterprise Connectivity ServiceSDN-Based Enterprise Connectivity Service
SDN-Based Enterprise Connectivity Service
 
CisCon 2018 - Analytics per Storage Area Networks
CisCon 2018 - Analytics per Storage Area NetworksCisCon 2018 - Analytics per Storage Area Networks
CisCon 2018 - Analytics per Storage Area Networks
 
Open Network Edge Services Software for 5G and Edge
Open Network Edge Services Software for 5G and EdgeOpen Network Edge Services Software for 5G and Edge
Open Network Edge Services Software for 5G and Edge
 
Using Microservices Architecture and Patterns to Address Applications Require...
Using Microservices Architecture and Patterns to Address Applications Require...Using Microservices Architecture and Patterns to Address Applications Require...
Using Microservices Architecture and Patterns to Address Applications Require...
 
Intelligent IoT gateway on openwrt
Intelligent IoT gateway on openwrtIntelligent IoT gateway on openwrt
Intelligent IoT gateway on openwrt
 
M-CORD cloud-native
M-CORD cloud-nativeM-CORD cloud-native
M-CORD cloud-native
 

Viewers also liked

Sesión 13 ejercitación
Sesión 13 ejercitaciónSesión 13 ejercitación
Sesión 13 ejercitación
Andrés García
 
Sesión 15 ejercitación
Sesión 15 ejercitaciónSesión 15 ejercitación
Sesión 15 ejercitación
Andrés García
 
Secure from GO: Design considerations for the integration of security into L...
Secure from GO:  Design considerations for the integration of security into L...Secure from GO:  Design considerations for the integration of security into L...
Secure from GO: Design considerations for the integration of security into L...
Mary McEvoy Carroll
 

Viewers also liked (16)

A guided tour to the internet of things in the sim connected world
A guided tour to the internet of things in the sim connected worldA guided tour to the internet of things in the sim connected world
A guided tour to the internet of things in the sim connected world
 
Connectem VCM powered by VMware - partner brief
Connectem VCM powered by VMware - partner briefConnectem VCM powered by VMware - partner brief
Connectem VCM powered by VMware - partner brief
 
Escaleras 2
Escaleras 2Escaleras 2
Escaleras 2
 
Ventanas
VentanasVentanas
Ventanas
 
Sesión 13 ejercitación
Sesión 13 ejercitaciónSesión 13 ejercitación
Sesión 13 ejercitación
 
Sesión 15 ejercitación
Sesión 15 ejercitaciónSesión 15 ejercitación
Sesión 15 ejercitación
 
Cartonlab: cardboard ecodesign
Cartonlab: cardboard ecodesignCartonlab: cardboard ecodesign
Cartonlab: cardboard ecodesign
 
Ecodesign with cardboard.CartonLAB Co&Co Bilbao 26 02_2014
Ecodesign with cardboard.CartonLAB Co&Co Bilbao 26 02_2014Ecodesign with cardboard.CartonLAB Co&Co Bilbao 26 02_2014
Ecodesign with cardboard.CartonLAB Co&Co Bilbao 26 02_2014
 
Lessini Durello: Autentico Autoctono
Lessini Durello: Autentico AutoctonoLessini Durello: Autentico Autoctono
Lessini Durello: Autentico Autoctono
 
Riesling: nobiltà e lignaggio al servizio del terroir
Riesling: nobiltà e lignaggio al servizio del terroirRiesling: nobiltà e lignaggio al servizio del terroir
Riesling: nobiltà e lignaggio al servizio del terroir
 
What is the connected retail environment?
What is the connected retail environment?What is the connected retail environment?
What is the connected retail environment?
 
Secure from GO: Design considerations for the integration of security into L...
Secure from GO:  Design considerations for the integration of security into L...Secure from GO:  Design considerations for the integration of security into L...
Secure from GO: Design considerations for the integration of security into L...
 
Hadoop top 20 influencers of 2015
Hadoop top 20 influencers of 2015Hadoop top 20 influencers of 2015
Hadoop top 20 influencers of 2015
 
Lte transport requirements
Lte transport requirementsLte transport requirements
Lte transport requirements
 
Infonetics and Stoke webinar: Security at the speed of VoLTE
Infonetics and Stoke webinar: Security at the speed of VoLTEInfonetics and Stoke webinar: Security at the speed of VoLTE
Infonetics and Stoke webinar: Security at the speed of VoLTE
 
Lte security concepts and design considerations
Lte security concepts and design considerationsLte security concepts and design considerations
Lte security concepts and design considerations
 

Similar to Sec conf london_v07

LTE: Building next-gen application services for mobile telecoms
LTE: Building next-gen application services for mobile telecomsLTE: Building next-gen application services for mobile telecoms
LTE: Building next-gen application services for mobile telecoms
NuoDB
 

Similar to Sec conf london_v07 (20)

Securing the shared network
Securing the shared networkSecuring the shared network
Securing the shared network
 
Securing the Onion: 5G Cloud Native Infrastructure
Securing the Onion: 5G Cloud Native InfrastructureSecuring the Onion: 5G Cloud Native Infrastructure
Securing the Onion: 5G Cloud Native Infrastructure
 
New world IP traffic, new dimensions for Diameter management
New world IP traffic, new dimensions for Diameter managementNew world IP traffic, new dimensions for Diameter management
New world IP traffic, new dimensions for Diameter management
 
New world IP traffic, new dimensions for Diameter management
New world IP traffic, new dimensions for Diameter managementNew world IP traffic, new dimensions for Diameter management
New world IP traffic, new dimensions for Diameter management
 
[cb22] Tales of 5G hacking by Karsten Nohl
[cb22] Tales of 5G hacking by Karsten Nohl[cb22] Tales of 5G hacking by Karsten Nohl
[cb22] Tales of 5G hacking by Karsten Nohl
 
LTE: Building next-gen application services for mobile telecoms
LTE: Building next-gen application services for mobile telecomsLTE: Building next-gen application services for mobile telecoms
LTE: Building next-gen application services for mobile telecoms
 
 Network Innovations Driving Business Transformation
 Network Innovations Driving Business Transformation Network Innovations Driving Business Transformation
 Network Innovations Driving Business Transformation
 
PLNOG 7: Klaudiusz Staniek - MPLS a QoS - praktycznie
PLNOG 7: Klaudiusz Staniek - MPLS a QoS - praktyczniePLNOG 7: Klaudiusz Staniek - MPLS a QoS - praktycznie
PLNOG 7: Klaudiusz Staniek - MPLS a QoS - praktycznie
 
Colt SD-WAN experience learnings and future plans
Colt SD-WAN experience learnings and future plansColt SD-WAN experience learnings and future plans
Colt SD-WAN experience learnings and future plans
 
Module 2-lte architecture and protocol
Module 2-lte architecture and protocolModule 2-lte architecture and protocol
Module 2-lte architecture and protocol
 
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
 
BRKCRS-2110.pdf
BRKCRS-2110.pdfBRKCRS-2110.pdf
BRKCRS-2110.pdf
 
[Cisco Connect 2018 - Vietnam] Satit adirek hn under_the_hood_sdwan deep_dive
[Cisco Connect 2018 - Vietnam] Satit adirek hn under_the_hood_sdwan deep_dive[Cisco Connect 2018 - Vietnam] Satit adirek hn under_the_hood_sdwan deep_dive
[Cisco Connect 2018 - Vietnam] Satit adirek hn under_the_hood_sdwan deep_dive
 
Edge / Far Edge: Convergent Access & Transport Infrastructure
Edge / Far Edge: Convergent Access & Transport InfrastructureEdge / Far Edge: Convergent Access & Transport Infrastructure
Edge / Far Edge: Convergent Access & Transport Infrastructure
 
CTIA 2010 Corporate Overview
CTIA 2010 Corporate OverviewCTIA 2010 Corporate Overview
CTIA 2010 Corporate Overview
 
Cisco connect winnipeg 2018 gain insight and programmability with cisco dc ...
Cisco connect winnipeg 2018   gain insight and programmability with cisco dc ...Cisco connect winnipeg 2018   gain insight and programmability with cisco dc ...
Cisco connect winnipeg 2018 gain insight and programmability with cisco dc ...
 
Cisco Connect Toronto 2018 sd-wan - delivering intent-based networking to t...
Cisco Connect Toronto 2018   sd-wan - delivering intent-based networking to t...Cisco Connect Toronto 2018   sd-wan - delivering intent-based networking to t...
Cisco Connect Toronto 2018 sd-wan - delivering intent-based networking to t...
 
Introduction to Segment Routing
Introduction to Segment RoutingIntroduction to Segment Routing
Introduction to Segment Routing
 
Skt.2013.innovation technology for future convergence network
Skt.2013.innovation technology for future convergence networkSkt.2013.innovation technology for future convergence network
Skt.2013.innovation technology for future convergence network
 
Introducing Application Engineered Routing Powered by Segment Routing
Introducing Application Engineered Routing Powered by Segment RoutingIntroducing Application Engineered Routing Powered by Segment Routing
Introducing Application Engineered Routing Powered by Segment Routing
 

Recently uploaded

Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo Diehl
Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo DiehlFuture Visions: Predictions to Guide and Time Tech Innovation, Peter Udo Diehl
Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo Diehl
Peter Udo Diehl
 
Essentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with ParametersEssentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with Parameters
Safe Software
 

Recently uploaded (20)

ODC, Data Fabric and Architecture User Group
ODC, Data Fabric and Architecture User GroupODC, Data Fabric and Architecture User Group
ODC, Data Fabric and Architecture User Group
 
Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo Diehl
Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo DiehlFuture Visions: Predictions to Guide and Time Tech Innovation, Peter Udo Diehl
Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo Diehl
 
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered QualitySoftware Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
 
AI revolution and Salesforce, Jiří Karpíšek
AI revolution and Salesforce, Jiří KarpíšekAI revolution and Salesforce, Jiří Karpíšek
AI revolution and Salesforce, Jiří Karpíšek
 
Optimizing NoSQL Performance Through Observability
Optimizing NoSQL Performance Through ObservabilityOptimizing NoSQL Performance Through Observability
Optimizing NoSQL Performance Through Observability
 
Integrating Telephony Systems with Salesforce: Insights and Considerations, B...
Integrating Telephony Systems with Salesforce: Insights and Considerations, B...Integrating Telephony Systems with Salesforce: Insights and Considerations, B...
Integrating Telephony Systems with Salesforce: Insights and Considerations, B...
 
Designing Great Products: The Power of Design and Leadership by Chief Designe...
Designing Great Products: The Power of Design and Leadership by Chief Designe...Designing Great Products: The Power of Design and Leadership by Chief Designe...
Designing Great Products: The Power of Design and Leadership by Chief Designe...
 
IoT Analytics Company Presentation May 2024
IoT Analytics Company Presentation May 2024IoT Analytics Company Presentation May 2024
IoT Analytics Company Presentation May 2024
 
Custom Approval Process: A New Perspective, Pavel Hrbacek & Anindya Halder
Custom Approval Process: A New Perspective, Pavel Hrbacek & Anindya HalderCustom Approval Process: A New Perspective, Pavel Hrbacek & Anindya Halder
Custom Approval Process: A New Perspective, Pavel Hrbacek & Anindya Halder
 
Essentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with ParametersEssentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with Parameters
 
Demystifying gRPC in .Net by John Staveley
Demystifying gRPC in .Net by John StaveleyDemystifying gRPC in .Net by John Staveley
Demystifying gRPC in .Net by John Staveley
 
Knowledge engineering: from people to machines and back
Knowledge engineering: from people to machines and backKnowledge engineering: from people to machines and back
Knowledge engineering: from people to machines and back
 
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
 
Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)
Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)
Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)
 
SOQL 201 for Admins & Developers: Slice & Dice Your Org’s Data With Aggregate...
SOQL 201 for Admins & Developers: Slice & Dice Your Org’s Data With Aggregate...SOQL 201 for Admins & Developers: Slice & Dice Your Org’s Data With Aggregate...
SOQL 201 for Admins & Developers: Slice & Dice Your Org’s Data With Aggregate...
 
In-Depth Performance Testing Guide for IT Professionals
In-Depth Performance Testing Guide for IT ProfessionalsIn-Depth Performance Testing Guide for IT Professionals
In-Depth Performance Testing Guide for IT Professionals
 
UiPath Test Automation using UiPath Test Suite series, part 3
UiPath Test Automation using UiPath Test Suite series, part 3UiPath Test Automation using UiPath Test Suite series, part 3
UiPath Test Automation using UiPath Test Suite series, part 3
 
JMeter webinar - integration with InfluxDB and Grafana
JMeter webinar - integration with InfluxDB and GrafanaJMeter webinar - integration with InfluxDB and Grafana
JMeter webinar - integration with InfluxDB and Grafana
 
Key Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdfKey Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdf
 
Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...
Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...
Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...
 

Sec conf london_v07

  • 1. © 2014 Stoke Securing the LTE Core – the Road to NFV | Proprietary and Confidential Dilip Pillaipakam Vice President, Product Management and Marketing
  • 2. © 2014 Stoke The LTE Security Framework 2 S9 S1-C Internet S1-U S5/S8 S6A Gx Gz/Gy Other LTE Network S11 RAN-Core Border SEG The border between RAN and Core (S1) requires protection against specific risks to critical infrastructure at that interface Control Plane Functions -  IKE -  AAA -  Routing DRA SBC IMS Core SGW MME CSCF Internet Border Policy / Charging Control SGi Data Plane Functions -  Forwarding -  QoS -  ACL -  Packet Inspection Device and Application
  • 3. © 2014 Stoke LTE Security at the S1 Link – Emerging Trends 3 Challenge Requirements Stronger Security •  2048 bit key length •  PKI Signaling Protection - New Threat Vectors •  Protect core - exponential transaction increase •  S1 protocol/state validation VoLTE Rollout •  Low latency transport •  Sub-1 second recovery Elastic Deployment •  Virtualized security gateway on COTS •  SDN integration Scalable Small Cell Deployments •  Dense session aggregation •  Intelligent load balancing
  • 4. © 2014 Stoke Use Case: Macro and Small Cell Security 4 »  Unsecured backhaul »  Rapidly increasing throughput »  High tunnel density »  Ultra-low latency »  Directly impacts subscriber QoE 44 MME SGW Office Home Outdoor Metrocell Small Cells 4G LTE EPC Millions of Tunnels MME SGW EPC E2E Latency Budget = 100 ms VoLTE: Low Latency Small Packets High Bandwidth
  • 5. © 2014 Stoke Office Home Outdoor Metrocell Small Cells Use Case: Signaling Overload »  Signaling Overload Threats »  Application initiated »  Compromised eNodeBs »  Natural disasters »  Prioritized Traffic »  Already connected subscribers »  Specific eNodeBs SGW 4G LTE EPCMillions of Service Requests MME Application Update Server QoE: Prioritize 5
  • 6. © 2014 Stoke The LTE Security Framework vSEG Phase 1 6 S9 Internet S5/S8 S6A Gx Gz/Gy Other LTE Network S11 RAN-Core Border Control Plane Functions -  IKE -  AAA -  Routing DRA SBC IMS Core SGW MME CSCF Internet Border Policy / Charging Control SGi Data Plane Functions -  Forwarding -  QoS -  ACL -  Inspections Device and Application »  vSEG on COTS hardware on Linux »  Similar deployment and operational model as today »  Benefits: »  Removes restriction of physical chassis »  scale to very large number of line cards SEG v-SEG (DP) v-SEG (CP)
  • 7. © 2014 Stoke The LTE Security Framework vSEG Phase 2 7 Other LTE Network SGW MME DRA SBC CSCF Internet Border Policy / Charging Control Internet S1-C S1-U Internet V-EPC RAN-Core Border v-SEG (DP) v-SEG (CP) Security Gateway Cloud QoS InspectionACLs IKE AAA Routing SEG Controller SDN Controller »  Disaggregate control plane and data plane functions to scale each function independently. »  Can be integrated with Operator's SDN infrastructure »  Benefits »  Fully elastic on-demand deployment »  Capacity can be added dynamically by adding more service nodes »  Scale some functions disproportionately
  • 8. © 2014 Stoke Conclusions 8 »  Each domain of the LTE Security Framework provides protection against specific threats and therefore has unique functional and performance requirements »  S1 Link has stringent performance and latency requirements »  Purpose built platforms will remain the mainstay for next few years »  Virtualization has benefits, but is not the answer for all use cases | Proprietary and Confidential