Security requirements for service function chaining isolation and encryption
Håkon Gunleifsen, Thomas Kemmerich · 2017
This paper presents a study of Service Function Chaining (SFC) isolation and encryption in interconnected Network Function Virtualisation (NFV) domains. The adoption of NFV deployments is currently designed to be implemented within trusted domains where overlay networks with statically trusted links are considered to enable network security. We challenge this statement and introduce a security problem related to Virtual Network Functions (VNF) confidentiality and isolation. A dataflow that traverses through a chain of Virtual Network Functions (VNF) cannot be end-to-end encrypted when each VNF must have access to the dataflow. This restricts both end-users and Service Providers from enabling end-to-end security and VNF isolation to their NFV flow. Therefore, there is a need to encrypt the dataflows on a per flow basis. In this paper we present the discovered security problem, set the requirements for the problem solution and study the constraints for securing and isolating VNFs in a Service Function Chain.