Deterministic Networking Security Considerations
RFC 9055, “Deterministic Networking Security Considerations”, is an Informational document published in June 2021 by E. Grossman, T. Mizrahi, A. Hacker. The canonical text is published by the RFC Editor.
Abstract
A DetNet (deterministic network) provides specific performance guarantees to its data flows, such as extremely low data loss rates and bounded latency (including bounded latency variation, i.e., "jitter"). As a result, securing a DetNet requires that in addition to the best practice security measures taken for any mission-critical network, additional security measures may be needed to secure the intended operation of these novel service properties.
This document addresses DetNet-specific security considerations from the perspectives of both the DetNet system-level designer and component designer. System considerations include a taxonomy of relevant threats and attacks, and associations of threats versus use cases and service properties. Component-level considerations include ingress filtering and packet arrival-time violation detection.
This document also addresses security considerations specific to the IP and MPLS data plane technologies, thereby complementing the Security Considerations sections of those documents.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 9055 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9056 Deterministic Networking Data Plane: IP over MPLS
- RFC 9057 Email Author Header Field
- RFC 9058 Multilinear Galois Mode
- RFC 9051 Internet Message Access Protocol - Version 4rev2
- RFC 9059 Path Computation Element Communication Protocol Extensions for Associated Bidirectional Label Switched Paths
- RFC 9050 Path Computation Element Communication Protocol Procedures and Extensions for Using the PCE as a Central Controller of LSPs
- RFC 9060 Secure Telephone Identity Revisited Certificate Delegation
- RFC 9049 Path Aware Networking: Obstacles to Deployment