BASTION: Beyond automated service and security orchestration for next-generation networks

IF 4.4 2区 计算机科学 Q1 COMPUTER SCIENCE, HARDWARE & ARCHITECTURE
José Manuel Bernabé Murcia , Alejandro M. Zarca , Antonio Skármeta
{"title":"BASTION: Beyond automated service and security orchestration for next-generation networks","authors":"José Manuel Bernabé Murcia ,&nbsp;Alejandro M. Zarca ,&nbsp;Antonio Skármeta","doi":"10.1016/j.comnet.2025.111352","DOIUrl":null,"url":null,"abstract":"<div><div>The adoption of 5G technology and beyond introduces advanced capabilities, such as dynamic resource coordination and allocation tailored to specific service and security requirements. To achieve efficient security and network management, service automation and orchestration are essential. This paper presents BASTION, a ZSM-aligned framework for enhanced service and security (meta) orchestration. By leveraging an intent-based, policy-driven approach, it enables the orchestration and enforcement of service and security policies across B5G infrastructures, dynamically adapting to real-time infrastructure conditions. While meta-orchestration capabilities focus on selecting the most suitable orchestration algorithm based on the system’s current status and the received requirements, orchestration capabilities primarily determine what, where, when, and how to enforce services and security policies. Additionally, the modular design and implementation allow for the seamless integration of new security capabilities through plugins, drivers, and managers. This advancement represents a significant step towards building resilient, adaptable, and secure B5G networks capable of meeting the complex demands of modern network environments. The implementation details showcase the full range of capabilities offered by the BASTION framework, highlighting its effectiveness through successful European and national projects. Furthermore, the performance evaluation section provides a comprehensive analysis of orchestration efficiency, breaking down execution times across different phases. In particular, BASTION demonstrates exceptional performance, achieving decision times as low as 1.3 ms and deploying services and security policies, including fully operational dynamic VNFs in less than 30 s, underscoring its ability to deliver fast, scalable, and efficient orchestration in complex environments.</div></div>","PeriodicalId":50637,"journal":{"name":"Computer Networks","volume":"267 ","pages":"Article 111352"},"PeriodicalIF":4.4000,"publicationDate":"2025-05-17","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Computer Networks","FirstCategoryId":"94","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S1389128625003196","RegionNum":2,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"COMPUTER SCIENCE, HARDWARE & ARCHITECTURE","Score":null,"Total":0}
引用次数: 0

Abstract

The adoption of 5G technology and beyond introduces advanced capabilities, such as dynamic resource coordination and allocation tailored to specific service and security requirements. To achieve efficient security and network management, service automation and orchestration are essential. This paper presents BASTION, a ZSM-aligned framework for enhanced service and security (meta) orchestration. By leveraging an intent-based, policy-driven approach, it enables the orchestration and enforcement of service and security policies across B5G infrastructures, dynamically adapting to real-time infrastructure conditions. While meta-orchestration capabilities focus on selecting the most suitable orchestration algorithm based on the system’s current status and the received requirements, orchestration capabilities primarily determine what, where, when, and how to enforce services and security policies. Additionally, the modular design and implementation allow for the seamless integration of new security capabilities through plugins, drivers, and managers. This advancement represents a significant step towards building resilient, adaptable, and secure B5G networks capable of meeting the complex demands of modern network environments. The implementation details showcase the full range of capabilities offered by the BASTION framework, highlighting its effectiveness through successful European and national projects. Furthermore, the performance evaluation section provides a comprehensive analysis of orchestration efficiency, breaking down execution times across different phases. In particular, BASTION demonstrates exceptional performance, achieving decision times as low as 1.3 ms and deploying services and security policies, including fully operational dynamic VNFs in less than 30 s, underscoring its ability to deliver fast, scalable, and efficient orchestration in complex environments.
BASTION:超越下一代网络的自动化服务和安全编排
5G及以上技术的采用引入了先进的功能,例如针对特定服务和安全需求量身定制的动态资源协调和分配。为了实现高效的安全和网络管理,服务自动化和编排是必不可少的。本文介绍了BASTION,一个与zsm一致的框架,用于增强服务和安全(元)编排。通过利用基于意图、策略驱动的方法,它支持跨B5G基础设施编排和实施服务和安全策略,动态适应实时基础设施条件。虽然元编排功能侧重于根据系统的当前状态和接收到的需求选择最合适的编排算法,但编排功能主要决定执行服务和安全策略的内容、地点、时间以及方式。此外,模块化设计和实现允许通过插件、驱动程序和管理器无缝集成新的安全功能。这一进展代表着朝着构建具有弹性、适应性和安全性的B5G网络迈出了重要一步,该网络能够满足现代网络环境的复杂需求。实施细节展示了BASTION框架提供的全部能力,通过成功的欧洲和国家项目突出了其有效性。此外,性能评估部分提供了对编排效率的全面分析,分解了不同阶段的执行时间。特别是,BASTION展示了卓越的性能,实现决策时间低至1.3 ms,并在不到30秒的时间内部署服务和安全策略,包括完全可操作的动态VNFs,强调了它在复杂环境中提供快速、可扩展和高效编排的能力。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
Computer Networks
Computer Networks 工程技术-电信学
CiteScore
10.80
自引率
3.60%
发文量
434
审稿时长
8.6 months
期刊介绍: Computer Networks is an international, archival journal providing a publication vehicle for complete coverage of all topics of interest to those involved in the computer communications networking area. The audience includes researchers, managers and operators of networks as well as designers and implementors. The Editorial Board will consider any material for publication that is of interest to those groups.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信