Strategies for the Placement of Security Functions in Telecommunication Systems
Reiner Sailer, Hannes Federrath, Andreas Pfitzmann · University of Regensburg Publication Server (University of Regensburg) · 1999
The placement of security functions determines which kinds of data they can protect against which kinds of attackers.Firstly, security functions are classified regarding their sphere of influence, e.g. between end points of communication associations (end-to-end) or end points of transmission lines (link-by-link).Next, we derive and illustrate restrictions and implications that limit the free choice concerning the placement of security functions.The general results are applied to interconnected telecommunication systems structured according to the OSI reference model.We investigate placement alternatives within user domains, network operators' domains, and service providers' domains and related implications on achievable security.We classify existing security solutions and describe the security that can be achieved by the respective solutions in order to promote the application of theoretical results.