Mail|Chinese
  Your Location:CNIS Home->News->Global vision
ETSI releases middlebox security protocols framework specification
Date: 2021-01-11    Source:ETSI   

ETSI is pleased to announce a new specification, ETSI TS 103 523-1: Part 1 of the Middlebox Security Protocol (MSP) series, which defines the security properties of a Middlebox Security Protocol.

Middleboxes are vital in modern networks - from new 5G deployments, with ever-faster networks that need performance management, to resisting new cyberattacks with evolved threat defence that copes with encrypted traffic, to VPN provision. Industry needs middlebox technology to keep pace with these and other evolving and diverse use cases. However, middlebox deployments often raise complex and multi-layered questions around the security, privacy and trust of using middleboxes.

MSP Part 1 (ETSI TS 103 523-1) addresses this gap by specifying a new security framework for middlebox protocols, allowing middleboxes to perform vital functions securely whilst keeping up with the rapid pace of technical development.

The MSP series is driven by four important principles that are vital for secure MSP deployments to perform their functions. These are:

1.Data Protection (DP): protecting data from network attackers and malicious actors.

2.Transparency (T): having knowledge of which parties have what access to the data.

3.Access Control (AC): allowing endpoints meaningfully to grant access to parties with this knowledge.

4.Good Citizen (GC): preventing complexity that adds DDoS attack vectors to the network.

ETSI TS 103 523-1 defines provisions in the area of each of these principles, called MSP Template Requirements. Using the MSP Framework gives both a flexible and consistent threat model to use across different MSP profiles to MSP profile developers, MSP profile implementors and MSP specification writers. This methodology permits an array of use cases, as well as thorough security analysis, for the next generation of middlebox protocols: MSP.

Such middlebox use cases are many and varied:

1.to provide security services in NFV and SDN environments

2.system and user security, including cyber defence and protection of user data

3.operational use cases including in Content Delivery Networks

4.compliance by network operators with obligations and service agreements, and discharge of transparency and audit obligations in regulated industries

5.maintaining enterprise network and data centre visibility

ETSI TS 103 523-1 is Part 1 of the Middlebox Security Protocol (MSP) series; this series is a set of protocol specifications that enable secure and functional operation of next generation middleboxes.

(Source: ETSI)

 
Attachments:

  Related

About CNIS

News

Publications

Resources

Links

©China National Institute of Standardization | Privacy Policy | Contact Us

Support: CNIS Information Technology Management Office & Biaoxin Science & Technology (Beijing) Co., Ltd.