SlideShare ist ein Scribd-Unternehmen logo
1 von 30
Downloaden Sie, um offline zu lesen
Security for Future Networks

                                         SecFuNet

                                              Diego Kreutz
                                        kreutz@lasige.di.fc.ul.pt

                                  Navigators' team at
                  LaSIGE - Large-Scale Informatics Systems Laboratory


SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil                      1
Outline

        Context
        Challenges
        Goals
        Specific Objectives
        Work-packages
        FCUL

SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil      2
Context

          ●
              Framework Programme 7
          ●
              EC call: FP7-ICT-2011-EU-Brazil
                             Date of publication: 28 September, 2010
                             Deadline: 18 January, 2011

          ●
              Funding Scheme: STREP
                             Small or medium-scale focused research projects

          ●
              Objective: Future Internet – security



SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil                             3
Context

                                             Project info
                  Name: Security for Future Networks
                                   Acronym: SecFuNet
            Duration: 1 May 2011- 1 November 2013
                          (30 months)
                       Coordinator: LIP6 - Guy Pujolle
                  Kickoff meeting: 11 Jully 2011, Paris
SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil          4
Context

             1                           3


                                                                                                6            2



                                         8
                                                                                        4

             7
                                                                                 3          5
                                                                                                        8
                                         6                                              1
                                                                                                    7




             5

                                         4




                                         2                   9


             9
                                                                                                        EU partners
                                   See also the online map at: http://g.co/maps/8zdxs
SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil                                                               5
Context
                                                                   12



                        13
                                                                                        10        12


                                                                           10




                                                                                        15        13




                                            16          11



                                                                                        11        14
                                             14


                                       15                                   16

                                                                                             BR partners
                                   See also the online map at: http://g.co/maps/8zdxs
SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil                                                     6
Context
        Propose a framework providing:
          ●
              secure identification and authentication
          ●
              secure data transfer
          ●
              secure virtualized infrastructure
          ●
              privacy in virtual network and clouds




SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil       7
Challenges

        Main challenge: improve the degree of
        security on virtual networks and clouds
          ➔
              coherent and robust identification schemes
          ➔
              algorithms robust to intrusions
          ➔
              guarantee security in the virtualized
              infrastructure



SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil         8
Goals

         a)Use microcontroller as anchors of trust
         b)Introduce an identification system, using
           pairs of associated microcontrollers
         c)Design an open framework, free of
           proprietary technologies
         d)Create a Radius SIM array to provide a
           unique strong authentication solution


SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil      9
Goals

         e)Develop a secure infrastructure for the
           virtualized networks and clouds
         f) Implement mechanisms for robust
            provisioning of IP services
         g)Develop cryptographic schemes adapted to
           virtual network and clouds


SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil      10
Specific Objectives

        Objective 1: design an extensible context
        framework for the security of the future networks
        Objective 2: authentication with EAP-TLS and
        legacy solutions
        Objective 3: develop a highly secure
        authentication server
        Objective 4: develop a highly secure
        identification scheme based on AAIs

SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil          11
Specific Objectives

        Objective 5: provide a reliable and secure
        environment
        Objective 6: achieve resilience of the
        communications and authentication /
        authorization
        Objective 7: provide cryptographic algorithms
        for future networks


SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil      12
Structure




               Structure of SecFuNet as an integrated project.


SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil               13
Structure




          Overall project structure and components dependency.
SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil               14
Work-packages
        WP0: Project Management, Coordination and
        Dissemination
          ➔
              Dissemination and website and video clip
          ➔
              Standardization and Exploitation Plan
        WP1: Requirement and Functional Architecture
          ➔
              Virtual network architecture and secure micro-
              controller: use cases and first choices
          ➔
              Limitations and requirements of the framework
SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil         15
Work-packages
        WP2: Authentication Server
          ➔
              Infrastructure of the authentication server
          ➔
              Array and software of the authentication server
          ➔
              Development and deployment on the network
        WP3: Secure Identity Management
          ➔
              Identity management system limitations and
              requirements, and prospective AAIs
          ➔
              Identity management system development
SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil          16
Work-packages
        WP4: Virtual Network Isolation
          ➔
              State-of-the-art and isolation between virtual
              networks
          ➔
              Profiling and virtual network migration
        WP5: Infrastructure Resilience
          ➔
              Architecture components for resilient networks
          ➔
              Trustworthy authentication service architecture

SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil             17
Work-packages
        WP6: Cryptographic Schemes
          ➔
              Cryptographic requirements
          ➔
              Cryptographic schemes for virtual networks
              and cloud accesses
        WP7: Testbed
          ➔
              Testbed creation
          ➔
              Test and evaluation experiments

SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil         18
Work-packages
                                  Overall WPs scheduling




                                     Light Blue = milestones with deliverables
SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil                               19
Work-packages




                                                     MGT = Management
SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil
                                                     RTD = Research and Technological Development
                                                                                                    20
FCUL
        WP0: project management (tasks)
          1.Dissemination
          2.Website and video clip
          3.Standardization
          4.Exploitation Plan
        Intermediate (M12) and final reports (M30)
                          Duration: 30 months
                          Deliverables: end of each task (M12 and M30)
SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil                       21
FCUL
        WP1: architecture requirements (tasks)
          1.Virtual network architecture and secure
            microcontroller: use cases and first choices
          2.Limitations and requirements of the framework
        FCUL rule: help in defining the items to be
        studied in virtual networking environment and on
        the secure framework.
                           Duration: 7 months
                           Deliverables: end of each task (M3 and M7)

SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil                      22
FCUL
        WP5: infrastructure resilience (tasks)
          1.Architecture components for resilient
            networks
          2.Trustworthy authentication service
            architecture
        FCUL rule: lead task 1 an help on task 2.
                           Duration: 22 months
                           Deliverables: end of each task (M18 and M21)


SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil                        23
FCUL
        WP6: cryptographic schemes (tasks)
          1.Cryptographic requirements
          2.Cryptographic schemes for virtual networks and
            cloud accesses
        FCUL rule: participate in the definition of the main
        security requirements for future virtual networking
        environments.
                           Duration: 21 months
                           Deliverables: end of each task (M14 and M27)

SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil                        24
FCUL
                                 Summary of staff effort.




SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil          25
FCUL

        On-going work (research)
          ●
              State of art on security of network
              management services
                      (WP1, WP5 and WP6)

          ●
              State of art on future networks
                      (WP1, WP5)
               
                   How they will be
               
                   How they will relate with clouds

SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil     26
FCUL
        On-going work (research)
          ●
              Papers, surveys and projects like:
              ➔
                  TRONE (trone.di.fc.ul.pt)
              ➔
                  MASSIF (www.massif-project.eu)
              ➔
                  4WARD (www.4ward-project.eu)
              ➔
                  EFFECTS+ (www.effectsplus.eu)
              ➔
                  PASSIVE (ict-passive.eu)
              ➔
                  SWIFT (www.ist-swift.org)
              ➔
                  WOMBAT (www.wombat-project.eu)
SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil     27
FCUL
        On-going work (hands-on)
          ●
              TRONE




                      (Trustworthy and Resilient Operations in a Network Environment)
SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil                                      28
FCUL
        On-going work (hands-on)
          ●
              Typhon




SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil     29
Security for Future Networks

                                         SecFuNet

                                              Diego Kreutz
                                        kreutz@lasige.di.fc.ul.pt

                                  Navigators' team at
                  LaSIGE - Large-Scale Informatics Systems Laboratory


SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil                      30

Weitere Àhnliche Inhalte

Ähnlich wie SecFutNet project - Secutiry for Future Network

Lte community networks in brazil sustainable modeling, deployment and mainte...
Lte community networks in brazil  sustainable modeling, deployment and mainte...Lte community networks in brazil  sustainable modeling, deployment and mainte...
Lte community networks in brazil sustainable modeling, deployment and mainte...
Christian Esteve Rothenberg
 
IPTC NITF November 2010
IPTC NITF November 2010IPTC NITF November 2010
IPTC NITF November 2010
Stuart Myles
 
EUBrasilCloudFORUM - Concertation Meeting
EUBrasilCloudFORUM - Concertation MeetingEUBrasilCloudFORUM - Concertation Meeting
EUBrasilCloudFORUM - Concertation Meeting
EUBrasilCloudFORUM .
 

Ähnlich wie SecFutNet project - Secutiry for Future Network (20)

FIBRE (legacy) testbed Future Perspectives
FIBRE (legacy) testbed Future PerspectivesFIBRE (legacy) testbed Future Perspectives
FIBRE (legacy) testbed Future Perspectives
 
FIT@BR – a Future Internet Testbed in Brazil
FIT@BR – a Future Internet Testbed in BrazilFIT@BR – a Future Internet Testbed in Brazil
FIT@BR – a Future Internet Testbed in Brazil
 
FIBRE testbed
FIBRE testbed FIBRE testbed
FIBRE testbed
 
Lte community networks in brazil sustainable modeling, deployment and mainte...
Lte community networks in brazil  sustainable modeling, deployment and mainte...Lte community networks in brazil  sustainable modeling, deployment and mainte...
Lte community networks in brazil sustainable modeling, deployment and mainte...
 
Fibre legacy testbed cloudscape
Fibre legacy testbed cloudscapeFibre legacy testbed cloudscape
Fibre legacy testbed cloudscape
 
FIBRE testbed: Future Perspectives
FIBRE testbed: Future PerspectivesFIBRE testbed: Future Perspectives
FIBRE testbed: Future Perspectives
 
Network Simulation - Prague 2015
Network Simulation - Prague 2015Network Simulation - Prague 2015
Network Simulation - Prague 2015
 
FIBRE - Future Internet Testbed-as-a-Service
FIBRE - Future Internet Testbed-as-a-ServiceFIBRE - Future Internet Testbed-as-a-Service
FIBRE - Future Internet Testbed-as-a-Service
 
FUTEBOL Project
FUTEBOL ProjectFUTEBOL Project
FUTEBOL Project
 
SCAPE general presentation
SCAPE general presentationSCAPE general presentation
SCAPE general presentation
 
Kumar cscl final
Kumar cscl finalKumar cscl final
Kumar cscl final
 
IRJET- Assessment of Network Protocol Packet Analysis in IPV4 and IPV6 on Loc...
IRJET- Assessment of Network Protocol Packet Analysis in IPV4 and IPV6 on Loc...IRJET- Assessment of Network Protocol Packet Analysis in IPV4 and IPV6 on Loc...
IRJET- Assessment of Network Protocol Packet Analysis in IPV4 and IPV6 on Loc...
 
Lessons learned from the development of FUTEBOL A case of cloud and fog inter...
Lessons learned from the development of FUTEBOL A case of cloud and fog inter...Lessons learned from the development of FUTEBOL A case of cloud and fog inter...
Lessons learned from the development of FUTEBOL A case of cloud and fog inter...
 
BLOCKCHAIN IMPLEMENTATION IN EDUCATIONAL SYSTEM
BLOCKCHAIN IMPLEMENTATION IN EDUCATIONAL SYSTEMBLOCKCHAIN IMPLEMENTATION IN EDUCATIONAL SYSTEM
BLOCKCHAIN IMPLEMENTATION IN EDUCATIONAL SYSTEM
 
EUDAT Generic Execution Framework
EUDAT Generic Execution FrameworkEUDAT Generic Execution Framework
EUDAT Generic Execution Framework
 
OGF Standards Overview - Cloudscape V
OGF Standards Overview - Cloudscape VOGF Standards Overview - Cloudscape V
OGF Standards Overview - Cloudscape V
 
Cloud by dev
Cloud by devCloud by dev
Cloud by dev
 
Scaling Prometheus Metrics in Kubernetes with Telegraf | Chris Goller | Influ...
Scaling Prometheus Metrics in Kubernetes with Telegraf | Chris Goller | Influ...Scaling Prometheus Metrics in Kubernetes with Telegraf | Chris Goller | Influ...
Scaling Prometheus Metrics in Kubernetes with Telegraf | Chris Goller | Influ...
 
IPTC NITF November 2010
IPTC NITF November 2010IPTC NITF November 2010
IPTC NITF November 2010
 
EUBrasilCloudFORUM - Concertation Meeting
EUBrasilCloudFORUM - Concertation MeetingEUBrasilCloudFORUM - Concertation Meeting
EUBrasilCloudFORUM - Concertation Meeting
 

Mehr von Diego Kreutz

Mehr von Diego Kreutz (8)

Identity Providers-as-a-Service built as Cloud-of-Clouds: challenges and oppo...
Identity Providers-as-a-Service built as Cloud-of-Clouds: challenges and oppo...Identity Providers-as-a-Service built as Cloud-of-Clouds: challenges and oppo...
Identity Providers-as-a-Service built as Cloud-of-Clouds: challenges and oppo...
 
Towards Secure and Dependable Authentication and Authorization Infrastructures
Towards Secure and Dependable Authentication and Authorization InfrastructuresTowards Secure and Dependable Authentication and Authorization Infrastructures
Towards Secure and Dependable Authentication and Authorization Infrastructures
 
Infrastructure Resilience against Attacks and Faults
Infrastructure Resilience against Attacks and FaultsInfrastructure Resilience against Attacks and Faults
Infrastructure Resilience against Attacks and Faults
 
The dark side of SDN and OpenFlow
The dark side of SDN and OpenFlowThe dark side of SDN and OpenFlow
The dark side of SDN and OpenFlow
 
Software-Defined Networking: Evolution or Revolution?
Software-Defined Networking: Evolution or Revolution?Software-Defined Networking: Evolution or Revolution?
Software-Defined Networking: Evolution or Revolution?
 
SDNs: hot topics, evolution & research opportunities
SDNs: hot topics, evolution & research opportunitiesSDNs: hot topics, evolution & research opportunities
SDNs: hot topics, evolution & research opportunities
 
Computação em Nuvem: conceitos, tendências e aplicações em Software Livre
Computação em Nuvem: conceitos, tendências e aplicações em Software LivreComputação em Nuvem: conceitos, tendências e aplicações em Software Livre
Computação em Nuvem: conceitos, tendências e aplicações em Software Livre
 
Serviços de rede: uma visão de futuro
Serviços de rede: uma visão  de futuroServiços de rede: uma visão  de futuro
Serviços de rede: uma visão de futuro
 

KĂŒrzlich hochgeladen

+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎+971_581248768%)**%*]'#abortion pills for sale in dubai@
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
vu2urc
 

KĂŒrzlich hochgeladen (20)

2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation Strategies
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
Developing An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of BrazilDeveloping An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of Brazil
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 

SecFutNet project - Secutiry for Future Network

  • 1. Security for Future Networks SecFuNet Diego Kreutz kreutz@lasige.di.fc.ul.pt Navigators' team at LaSIGE - Large-Scale Informatics Systems Laboratory SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil 1
  • 2. Outline Context Challenges Goals Specific Objectives Work-packages FCUL SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil 2
  • 3. Context ● Framework Programme 7 ● EC call: FP7-ICT-2011-EU-Brazil Date of publication: 28 September, 2010 Deadline: 18 January, 2011 ● Funding Scheme: STREP Small or medium-scale focused research projects ● Objective: Future Internet – security SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil 3
  • 4. Context Project info Name: Security for Future Networks Acronym: SecFuNet Duration: 1 May 2011- 1 November 2013 (30 months) Coordinator: LIP6 - Guy Pujolle Kickoff meeting: 11 Jully 2011, Paris SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil 4
  • 5. Context 1 3 6 2 8 4 7 3 5 8 6 1 7 5 4 2 9 9 EU partners See also the online map at: http://g.co/maps/8zdxs SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil 5
  • 6. Context 12 13 10 12 10 15 13 16 11 11 14 14 15 16 BR partners See also the online map at: http://g.co/maps/8zdxs SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil 6
  • 7. Context Propose a framework providing: ● secure identification and authentication ● secure data transfer ● secure virtualized infrastructure ● privacy in virtual network and clouds SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil 7
  • 8. Challenges Main challenge: improve the degree of security on virtual networks and clouds ➔ coherent and robust identification schemes ➔ algorithms robust to intrusions ➔ guarantee security in the virtualized infrastructure SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil 8
  • 9. Goals a)Use microcontroller as anchors of trust b)Introduce an identification system, using pairs of associated microcontrollers c)Design an open framework, free of proprietary technologies d)Create a Radius SIM array to provide a unique strong authentication solution SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil 9
  • 10. Goals e)Develop a secure infrastructure for the virtualized networks and clouds f) Implement mechanisms for robust provisioning of IP services g)Develop cryptographic schemes adapted to virtual network and clouds SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil 10
  • 11. Specific Objectives Objective 1: design an extensible context framework for the security of the future networks Objective 2: authentication with EAP-TLS and legacy solutions Objective 3: develop a highly secure authentication server Objective 4: develop a highly secure identification scheme based on AAIs SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil 11
  • 12. Specific Objectives Objective 5: provide a reliable and secure environment Objective 6: achieve resilience of the communications and authentication / authorization Objective 7: provide cryptographic algorithms for future networks SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil 12
  • 13. Structure Structure of SecFuNet as an integrated project. SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil 13
  • 14. Structure Overall project structure and components dependency. SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil 14
  • 15. Work-packages WP0: Project Management, Coordination and Dissemination ➔ Dissemination and website and video clip ➔ Standardization and Exploitation Plan WP1: Requirement and Functional Architecture ➔ Virtual network architecture and secure micro- controller: use cases and first choices ➔ Limitations and requirements of the framework SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil 15
  • 16. Work-packages WP2: Authentication Server ➔ Infrastructure of the authentication server ➔ Array and software of the authentication server ➔ Development and deployment on the network WP3: Secure Identity Management ➔ Identity management system limitations and requirements, and prospective AAIs ➔ Identity management system development SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil 16
  • 17. Work-packages WP4: Virtual Network Isolation ➔ State-of-the-art and isolation between virtual networks ➔ Profiling and virtual network migration WP5: Infrastructure Resilience ➔ Architecture components for resilient networks ➔ Trustworthy authentication service architecture SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil 17
  • 18. Work-packages WP6: Cryptographic Schemes ➔ Cryptographic requirements ➔ Cryptographic schemes for virtual networks and cloud accesses WP7: Testbed ➔ Testbed creation ➔ Test and evaluation experiments SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil 18
  • 19. Work-packages Overall WPs scheduling Light Blue = milestones with deliverables SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil 19
  • 20. Work-packages MGT = Management SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil RTD = Research and Technological Development 20
  • 21. FCUL WP0: project management (tasks) 1.Dissemination 2.Website and video clip 3.Standardization 4.Exploitation Plan Intermediate (M12) and final reports (M30) Duration: 30 months Deliverables: end of each task (M12 and M30) SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil 21
  • 22. FCUL WP1: architecture requirements (tasks) 1.Virtual network architecture and secure microcontroller: use cases and first choices 2.Limitations and requirements of the framework FCUL rule: help in defining the items to be studied in virtual networking environment and on the secure framework. Duration: 7 months Deliverables: end of each task (M3 and M7) SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil 22
  • 23. FCUL WP5: infrastructure resilience (tasks) 1.Architecture components for resilient networks 2.Trustworthy authentication service architecture FCUL rule: lead task 1 an help on task 2. Duration: 22 months Deliverables: end of each task (M18 and M21) SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil 23
  • 24. FCUL WP6: cryptographic schemes (tasks) 1.Cryptographic requirements 2.Cryptographic schemes for virtual networks and cloud accesses FCUL rule: participate in the definition of the main security requirements for future virtual networking environments. Duration: 21 months Deliverables: end of each task (M14 and M27) SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil 24
  • 25. FCUL Summary of staff effort. SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil 25
  • 26. FCUL On-going work (research) ● State of art on security of network management services (WP1, WP5 and WP6) ● State of art on future networks (WP1, WP5)  How they will be  How they will relate with clouds SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil 26
  • 27. FCUL On-going work (research) ● Papers, surveys and projects like: ➔ TRONE (trone.di.fc.ul.pt) ➔ MASSIF (www.massif-project.eu) ➔ 4WARD (www.4ward-project.eu) ➔ EFFECTS+ (www.effectsplus.eu) ➔ PASSIVE (ict-passive.eu) ➔ SWIFT (www.ist-swift.org) ➔ WOMBAT (www.wombat-project.eu) SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil 27
  • 28. FCUL On-going work (hands-on) ● TRONE (Trustworthy and Resilient Operations in a Network Environment) SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil 28
  • 29. FCUL On-going work (hands-on) ● Typhon SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil 29
  • 30. Security for Future Networks SecFuNet Diego Kreutz kreutz@lasige.di.fc.ul.pt Navigators' team at LaSIGE - Large-Scale Informatics Systems Laboratory SecFuNet: STREP 288349 from FP7-ICT-2011-EU-Brazil 30