Overview
ISO/IEC TR 29181-5:2014 addresses the problem statements and requirements for security in the Future Network (FN). The report analyzes current network shortcomings and sets out high-level requirements to support data security, network security and application security in a clean-slate or incremental FN design. The document highlights the need to move beyond patching legacy protocols toward a new architecture that embeds security by design.
Key Topics
-
Problems in current networks
- Users shoulder most security risk and responsibility rather than the network.
- IP addressing provides no strong proof of origin; addresses are irregular and easily spoofed.
- Centralized control structures can cause wide-scale security failures if compromised.
-
Limitations of present protections
- Common measures (firewalls, antivirus) are reactive and rely on signature-based detection.
- Defense-in-depth on private LANs does not scale to the global interconnection of the Internet.
-
Goals and requirements for FN security
- Shift from passive defense to active security management.
- Replace brute-force computing confrontation with robust authentication technologies.
- Support one-to-many system solutions that use authentication as a foundation.
-
Technical components recommended
- Identity authentication system (supporting real-name and anonymity modes).
- Platform security (trusted computing) to harden endpoints.
- Secure connection and transmission for end-to-end protection and key exchange.
- Application security integrated into FN architecture.
-
Key implementation considerations
- Support large-scale deployment and direct end-to-end authentication and key exchange.
- Enable management-domain segmentation and cross-domain authentication.
- Prioritize simple structure, low cost, convenient use, and easy popularization.
- Leverage identity infrastructures such as PKI or KMI and devices like USB-keys or IC cards where applicable.
Applications
- Designing FN architectures where security is intrinsic rather than additive
- Implementing identity-based routing, access control and provenance verification
- Building scalable authentication and key management infrastructures for service providers
- Hardening endpoints and applications through trusted computing features
Practical value: this TR helps architects and security teams prioritize authentication, trusted platforms and secure transmission mechanisms early in network design, reducing reliance on reactive measures and improving resilience at scale.
Related Standards
- ISO/IEC TR 29181-1 (Overall aspects of Future Network)
- Other parts of ISO/IEC TR 29181 (Naming & addressing, Switching & routing, Mobility, Media transport, Service composition)
These related documents provide complementary problem statements and requirements across FN topics and should be reviewed together when planning an FN security strategy.