14
BEL 2 Spezial, Unterschleißheim, Germany 03.07.2014 Stephan Neidlinger Security in Optical Networks – Useless or Necessary?

Security in Optical Networks - Useless or Necessary?

Embed Size (px)

DESCRIPTION

Check out Stephan Neidlinger's slides tha

Citation preview

Page 1: Security in Optical Networks - Useless or Necessary?

BEL 2 Spezial, Unterschleißheim, Germany

03.07.2014

Stephan Neidlinger

Security in Optical Networks – Useless or Necessary?

Page 2: Security in Optical Networks - Useless or Necessary?

© 2014 ADVA Optical Networking. All rights reserved. Confidential.22

Broadband Access Network Market Trends

• Service data rates keep on increasing• NG video: 3D, UHDTV, on-line streaming services, …

• Several markets need to be addressed in order to decrease return of investment time in FTTH infrastructure projects (according to the FTTH business guide published by FTTH Council Europe)• Residential• Business• Carrier• Public sector

• These applications call for• Equal down/upstream bandwidth (e g business, carrier services)• Scalable architecture (e g user individual bandwidth upgrade)• Simple systems for low cost potential (especially for residential market)• Secure architecture (e g business services)

Page 3: Security in Optical Networks - Useless or Necessary?

© 2014 ADVA Optical Networking. All rights reserved. Confidential.33

FTTH Business Guide

Page 4: Security in Optical Networks - Useless or Necessary?

© 2014 ADVA Optical Networking. All rights reserved. Confidential.44

FTTH Business Guide

Page 5: Security in Optical Networks - Useless or Necessary?

© 2014 ADVA Optical Networking. All rights reserved. Confidential.55

Example:Data Center Environment & Security

APPS APPS

Page 6: Security in Optical Networks - Useless or Necessary?

© 2014 ADVA Optical Networking. All rights reserved. Confidential.66

Data Center Environment & SecurityPhysical Access to the Data Center

APPS APPS

Page 7: Security in Optical Networks - Useless or Necessary?

© 2014 ADVA Optical Networking. All rights reserved. Confidential.77

Data Center Environment & SecurityHardware Security

APPS APPS

Page 8: Security in Optical Networks - Useless or Necessary?

© 2014 ADVA Optical Networking. All rights reserved. Confidential.88

Data Center Environment & SecuritySoftware Security

APPS APPS

Page 9: Security in Optical Networks - Useless or Necessary?

© 2014 ADVA Optical Networking. All rights reserved. Confidential.99

Data Center Environment & Security…and what about the Fiber Connection?

APPS APPS

Page 10: Security in Optical Networks - Useless or Necessary?

© 2014 ADVA Optical Networking. All rights reserved. Confidential.1010

Fiber Optic NetworksTapping Possibilities

Y-Bridge for service activities

Fiber Coupling device

Street cabinet

How to get access?

Whereto get access?

Splice boxes / cassettes

(Outdoor / Inhouse)

There are multiple ways to access fiber

Page 11: Security in Optical Networks - Useless or Necessary?

© 2014 ADVA Optical Networking. All rights reserved. Confidential.1111

Fiber Optic NetworksOptical Tapping Method

Cladding: 125 µm

Core: 9 µm

Lost Light

“For both public and private networks, optical taps and analytic devices are required and inexpensive maintenance equipment in common use worldwide today. Various types of optical taps […] are also used for corporate espionage…”

„Clearly, physical protection of optical transmission media and junction boxes

is essential; in addition, data encryption plays a role in protecting

sensitive data.” [5][5] Security Strategies Alert, M.E. Kabay, March 2003

Page 12: Security in Optical Networks - Useless or Necessary?

© 2014 ADVA Optical Networking. All rights reserved. Confidential.1212

Fiber Optical Networks Security Options

Encryption

Security-Hardened Software

Physical Layer Monitoring

Power TrackingIntrusion DetectionOptical Time-Domain Reflectometer (OTDR)

RADIUSSecure ShellSNMPv3

AES-256AuthenticationDiffie-Hellman

Optical Networks Security Tools are necessary and available

122842636

Page 13: Security in Optical Networks - Useless or Necessary?

© 2014 ADVA Optical Networking. All rights reserved. Confidential.1313

WAN

Ipsec / MacSec

Encryption

WDM-transport WDM-transport

Site BSite A

WAN

Appliance based

Encryption

WDM-transport

Site B

WDM-transport

Site A

Optical Transmission SecuritySpeed of Encryption

WAN

Router Site A Site B

xWDM basedEncryption

Sp

eed, th

roug

hpu

t and sim

plicity

TDM TDM

FC Switch

Router

FC Switch

Router

FC Switch

Router

FC Switch

Router

FC Switch

Router

FC Switch

Page 14: Security in Optical Networks - Useless or Necessary?

[email protected]

Thank You

IMPORTANT NOTICE

The content of this presentation is strictly confidential. ADVA Optical Networking is the exclusive owner or licensee of the content, material, and information in this presentation. Any reproduction, publication or reprint, in whole or in part, is strictly prohibited.

The information in this presentation may not be accurate, complete or up to date, and is provided without warranties or representations of any kind, either express or implied. ADVA Optical Networking shall not be responsible for and disclaims any liability for any loss or damages, including without limitation, direct, indirect, incidental, consequential and special damages, alleged to have been caused by or in connection with using and/or relying on the information contained in this presentation.

Copyright © for the entire content of this presentation: ADVA Optical Networking.