Gs NFV-IFA033v040101p
Gs NFV-IFA033v040101p
1 (2020-08)
GROUP SPECIFICATION
Disclaimer
The present document has been produced and approved by the Network Functions Virtualisation (NFV) ETSI Industry
Specification Group (ISG) and represents the views of those members who participated in this ISG.
It does not necessarily represent the views of the entire ETSI membership.
2 ETSI GS NFV-IFA 033 V4.1.1 (2020-08)
Reference
DGS/NFV-IFA033
Keywords
cyber security, interface, management, MANO,
NFV, orchestration, security, virtualisation
ETSI
Important notice
The present document may be made available in electronic versions and/or in print. The content of any electronic and/or
print versions of the present document shall not be modified without the prior written authorization of ETSI. In case of any
existing or perceived difference in contents between such versions and/or in print, the prevailing version of an ETSI
deliverable is the one made publicly available in PDF format at www.etsi.org/deliver.
Users of the present document should be aware that the document may be subject to revision or change of status.
Information on the current status of this and other ETSI documents is available at
https://portal.etsi.org/TB/ETSIDeliverableStatus.aspx
If you find errors in the present document, please send your comment to one of the following services:
https://portal.etsi.org/People/CommiteeSupportStaff.aspx
Copyright Notification
No part may be reproduced or utilized in any form or by any means, electronic or mechanical, including photocopying
and microfilm except as authorized by written permission of ETSI.
The content of the PDF version shall not be modified without the written authorization of ETSI.
The copyright and the foregoing restriction extend to reproduction in all media.
© ETSI 2020.
All rights reserved.
DECT™, PLUGTESTS™, UMTS™ and the ETSI logo are trademarks of ETSI registered for the benefit of its Members.
3GPP™ and LTE™ are trademarks of ETSI registered for the benefit of its Members and
of the 3GPP Organizational Partners.
oneM2M™ logo is a trademark of ETSI registered for the benefit of its Members and
of the oneM2M Partners.
GSM® and the GSM logo are trademarks registered and owned by the GSM Association.
ETSI
3 ETSI GS NFV-IFA 033 V4.1.1 (2020-08)
Contents
Intellectual Property Rights ................................................................................................................................4
Foreword.............................................................................................................................................................4
Modal verbs terminology....................................................................................................................................4
1 Scope ........................................................................................................................................................5
2 References ................................................................................................................................................5
2.1 Normative references ......................................................................................................................................... 5
2.2 Informative references ........................................................................................................................................ 5
3 Definition of terms, symbols and abbreviations .......................................................................................6
3.1 Terms.................................................................................................................................................................. 6
3.2 Symbols .............................................................................................................................................................. 6
3.3 Abbreviations ..................................................................................................................................................... 6
4 Overview of interfaces for the Sc-Or, Sc-Vnfm and Sc-Vi reference points ...........................................6
4.1 Introduction ........................................................................................................................................................ 6
4.1.1 Reference architecture .................................................................................................................................. 6
4.1.2 NFVO as a proxy for getting information from other functional blocks ...................................................... 6
4.1.3 Interfaces on the Sc-Or reference point ........................................................................................................ 7
4.1.4 Interfaces on the Sc-Vi reference point......................................................................................................... 7
4.2 Relation to other NFV Group Specifications...................................................................................................... 7
5 Reference point and interface requirements .............................................................................................7
5.1 Introduction ........................................................................................................................................................ 7
5.2 Reference point requirements ............................................................................................................................. 8
5.2.1 Sc-Or reference point requirements .............................................................................................................. 8
5.2.2 Sc-Vi reference point requirements .............................................................................................................. 8
5.3 Interface requirements ........................................................................................................................................ 8
5.3.1 Interface requirements for NS Lifecycle Management ................................................................................. 8
5.3.2 Interface requirements for Status Information Management ........................................................................ 9
5.3.3 Interface requirements for Security Policy Enforcement ............................................................................ 10
5.3.4 Interface requirements for Security VNF Management .............................................................................. 11
5.3.5 Interface requirements for Telemetry Information Management ................................................................ 11
5.4 Security requirements ....................................................................................................................................... 11
6 Interfaces over Sc-Or reference point.....................................................................................................12
6.1 Introduction ...................................................................................................................................................... 12
6.2 NS Lifecycle Management Interface ................................................................................................................ 12
6.3 Status Information Management Interface ....................................................................................................... 13
6.4 Security Policy Enforcement Interface ............................................................................................................. 13
6.5 Security VNF Management Interface ............................................................................................................... 14
7 Interfaces over Sc-Vnfm reference point ...............................................................................................14
7.1 Introduction ...................................................................................................................................................... 14
8 Interfaces over Sc-Vi reference point .....................................................................................................14
8.1 Introduction ...................................................................................................................................................... 14
8.2 Telemetry Information Management interface ................................................................................................. 14
8.2.1 Description.................................................................................................................................................. 14
History ..............................................................................................................................................................17
ETSI
4 ETSI GS NFV-IFA 033 V4.1.1 (2020-08)
IPRs essential or potentially essential to normative deliverables may have been declared to ETSI. The information
pertaining to these essential IPRs, if any, is publicly available for ETSI members and non-members, and can be found
in ETSI SR 000 314: "Intellectual Property Rights (IPRs); Essential, or potentially Essential, IPRs notified to ETSI in
respect of ETSI standards", which is available from the ETSI Secretariat. Latest updates are available on the ETSI Web
server (https://ipr.etsi.org/).
Pursuant to the ETSI IPR Policy, no investigation, including IPR searches, has been carried out by ETSI. No guarantee
can be given as to the existence of other IPRs not referenced in ETSI SR 000 314 (or the updates on the ETSI Web
server) which are, or may be, or may become, essential to the present document.
Trademarks
The present document may include trademarks and/or tradenames which are asserted and/or registered by their owners.
ETSI claims no ownership of these except for any which are indicated as being the property of ETSI, and conveys no
right to use or reproduce any trademark and/or tradename. Mention of those trademarks in the present document does
not constitute an endorsement by ETSI of products, services or organizations associated with those trademarks.
Foreword
This Group Specification (GS) has been produced by ETSI Industry Specification Group (ISG) Network Functions
Virtualisation (NFV).
"must" and "must not" are NOT allowed in ETSI deliverables except when used in direct citation.
ETSI
5 ETSI GS NFV-IFA 033 V4.1.1 (2020-08)
1 Scope
The present document specifies the requirements applicable to the interfaces supported over the Sc-Or, Sc-Vnfm, Sc-Vi
reference points as well as the operations invoked over these interfaces. The purpose of the interfaces is to support
security monitoring and management as specified in ETSI GS NFV-SEC 013 [i.3].
2 References
Referenced documents which are not found to be publicly available in the expected location might be found at
https://docbox.etsi.org/Reference.
NOTE: While any hyperlinks included in this clause were valid at the time of publication, ETSI cannot guarantee
their long term validity.
The following referenced documents are necessary for the application of the present document.
[1] ETSI GS NFV-IFA 005: "Network Functions Virtualisation (NFV) Release 3; Management and
Orchestration; Or-Vi reference point - Interface and Information Model Specification".
[2] ETSI GS NFV-IFA 006: "Network Functions Virtualisation (NFV) Release 3; Management and
Orchestration; Vi-Vnfm reference point - Interface and Information Model Specification".
[3] ETSI GS NFV-IFA 013: "Network Functions Virtualisation (NFV) Release 3; Management and
Orchestration; Os-Ma-nfvo reference point - Interface and Information Model Specification".
NOTE: While any hyperlinks included in this clause were valid at the time of publication, ETSI cannot guarantee
their long term validity.
The following referenced documents are not necessary for the application of the present document but they assist the
user with regard to a particular subject area.
[i.1] ETSI GS NFV 002: "Network Functions Virtualisation (NFV); Architectural Framework".
[i.2] ETSI GR NFV 003: "Network Functions Virtualisation (NFV); Terminology for Main Concepts in
NFV".
[i.3] ETSI GS NFV-SEC 013: "Network Functions Virtualisation (NFV) Release 3; Security; Security
Management and Monitoring specification".
[i.4] ETSI GS NFV-IFA 026: "Network Functions Virtualisation (NFV) Release 3; Management and
Orchestration; Architecture enhancement for Security Management Specification".
[i.5] ETSI GS NFV-IFA 007: "Network Functions Virtualisation (NFV) Release 3; Management and
Orchestration; Or-Vnfm reference point - Interface and Information Model Specification".
[i.6] ETSI GS NFV-SOL 003: "Network Functions Virtualisation (NFV) Release 3; Protocols and Data
Models; RESTful protocols specification for the Or-Vnfm Reference Point".
ETSI
6 ETSI GS NFV-IFA 033 V4.1.1 (2020-08)
3.1 Terms
For the purposes of the present document, the terms given in ETSI GR NFV 003 [i.2] and ETSI GS NFV-IFA 026 [i.4]
apply.
3.2 Symbols
Void.
3.3 Abbreviations
For the purposes of the present document, the abbreviations given in ETSI GR NFV 003 [i.2] and the following apply:
NOTE: An abbreviation defined in the present document takes precedence over the definition of the same
abbreviation, if any, in ETSI GR NFV 003 [i.2].
4.1 Introduction
4.1.1 Reference architecture
The Sc-Or, Sc-Vnfm and Sc-Vi reference points are specified in ETSI GS NFV-IFA 026 [i.4].
4.1.2 NFVO as a proxy for getting information from other functional blocks
The Security Manager has requirements for getting information which originates from the NFVO, VIM, VNFM or
OSS/BSS. As a general principle, the information originated from either the VIM, VNFM or OSS/BSS is sent to the
NFVO from the originated entity, then the information is sent from the NFVO to the SM in which the NFVO acts as a
proxy.
• The present document defines a reference point between the NFVO and the SM.
• The present document does not define a reference point between the OSS/BSS and the SM (NFVO as a
proxy).
• The present document does not define a reference point between the VNFM and the SM (NFVO as a proxy).
• The present document defines a reference point between the VIM and the SM, and only one interface
including a reduced set of operations compared to Or-Vi and Vi-Vnfm reference point is specified for this
reference point.
ETSI
7 ETSI GS NFV-IFA 033 V4.1.1 (2020-08)
5.1 Introduction
This clause defines or references requirements applicable to interfaces in the context of the Sc-Or and Sc-Vi reference
points, in order to support security monitoring and management as specified in ETSI GS NFV-SEC 013 [i.3].
Requirements are labelled according to whether they are applicable to Passive, Semi-Active or Fully-Active security
monitoring, using the definitions from ETSI GS NFV-IFA 026 [i.4]. The right-most column of all tables in clause 5 is
entitled "PSF" and is used to list the type of SMs to which the requirement applies. "S" and "F" indicate that it applies to
"Semi-Active" or "Fully-Active", while "SF" indicates that it applies to Semi-Active and Fully-Active (this is therefore
a conditional requirement). If the requirement applies to all types of SM (written as "All") then the requirement is
considered to be a mandatory requirement, unless it is otherwise stated in the text of the requirement.
ETSI
8 ETSI GS NFV-IFA 033 V4.1.1 (2020-08)
Table 5.3.1-1 specifies requirements applicable to the NS Lifecycle Management interface produced by the NFVO over
the Sc-Or reference point.
ETSI
9 ETSI GS NFV-IFA 033 V4.1.1 (2020-08)
ETSI
10 ETSI GS NFV-IFA 033 V4.1.1 (2020-08)
ETSI
11 ETSI GS NFV-IFA 033 V4.1.1 (2020-08)
ETSI
12 ETSI GS NFV-IFA 033 V4.1.1 (2020-08)
6.1 Introduction
This clause defines the interfaces exposed by the NFVO towards the SM over the Sc-Or reference point.
The following operations are defined for this interface, and these operations shall follow the specification from ETSI
GS NFV-IFA 013 [3], except that the producer is the NFVO and the consumer is the SM:
ETSI
13 ETSI GS NFV-IFA 033 V4.1.1 (2020-08)
NOTE: The Subscription/Notifications operations in clauses 7.3.11 to 7.3.14 of ETSI GS NFV-IFA 013 [3]
enable Sc-Or.NsLcm.006 to be met as follows:
This gives the appropriate identifiers in order to use the QueryNS operation to retrieve all the
information required by Sc-Or.NsLcm.006. Specifically, QueryNS returns NSInfo which contains
VnfInfo, which meets Sc-Or.NsLcm.006 as follows:
The following operations are defined for this interface, and these operations shall follow the specification from ETSI
GS NFV-IFA 013 [3], except that the producer is the NFVO and the consumer is the SM:
The following operations are defined for this interface, and these operations shall follow the specification from ETSI
GS NFV-IFA 013 [3], except that the producer is the NFVO and the consumer is the SM:
• Update NS (refer to clause 7.3.5 of ETSI GS NFV-IFA 013 [3], see note 1).
• Update VNF Package Info (refer to clause 7.7.16 of ETSI GS NFV-IFA 013 [3], see note 3).
To meet Sc-Or.SecEnforce.002 and .003 (terminating VNF), with updateType = RemoveVnf and a
removeVnfInstanceId attribute set to the appropriate identifier (see note 2).
To meet Sc-Or.SecEnforce.002 and .003 (whether another VNF may be created) by sending one
UpdateNS request to kill the VNF instance and sending another UpdateNS request to recreate it if
required.
NOTE 2: According to ETSI GS NFV-IFA 013 [3], note 1 of table 7.3.5.2-1, a VNF instance is only terminated by
the NFVO if it is no longer used by any NS. As a consequence, in order to terminate a VNF instance, the
SM has to send an UpdateNS request to each NS where this VNF instance is a part.
ETSI
14 ETSI GS NFV-IFA 033 V4.1.1 (2020-08)
NOTE 4: An explanation of how to meet Sc-Or.SecEnforce.004 is not given in the present document.
The following operations are defined for this interface, and these operations shall follow the specification from ETSI
GS NFV-IFA 013 [3], except that the producer is the NFVO and the consumer is the SM:
NOTE: It is assumed that the VNFD of the security-related VNF is referenced from the NSD.
7.1 Introduction
The present document does not define any interfaces over the Sc-Vnfm reference point.
8.1 Introduction
This clause defines the interfaces exposed by the VIM towards the SM over the Sc-Vi reference point.
The following operations are defined for this interface, and these operations shall follow the specifications from ETSI
GS NFV-IFA 005 [1] and ETSI GS NFV-IFA 006 [2], except that the producer is the VIM and the consumer is the SM.
The interface supports the following Query operations derived from interfaces in ETSI GS NFV-IFA 005 [1] and ETSI
GS NFV-IFA 006 [2]:
• From ETSI GS NFV-IFA 005 [1], clause 7.3.4.2 Query Compute Capacity operation
• From ETSI GS NFV-IFA 005 [1], clause 7.3.4.5 Query Compute Resource Zone operation
• From ETSI GS NFV-IFA 005 [1], clause 7.3.4.6 Query NFVI-PoP Compute Information operation
• From ETSI GS NFV-IFA 005 [1], clause 7.4.4.2 Query Network Capacity operation
• From ETSI GS NFV-IFA 005 [1], clause 7.4.4.5 Query NFVI-PoP Network Information operation
• From ETSI GS NFV-IFA 005 [1], clause 7.4.5.3 Query NFP operation
• From ETSI GS NFV-IFA 005 [1], clause 7.5.4.5 Query NFVI-PoP Storage Information operation
• From ETSI GS NFV-IFA 005 [1], clause 7.5.4.6 Query Storage Resource Zone operation
• From ETSI GS NFV-IFA 005 [1], clause 7.9.3.3 Query Storage Resource Quota operation
ETSI
15 ETSI GS NFV-IFA 033 V4.1.1 (2020-08)
• From ETSI GS NFV-IFA 005 [1], clause 7.10.3 Query Compute Host Reservation operation
• From ETSI GS NFV-IFA 006 [2], clause 7.2.2 Query Images operation
• From ETSI GS NFV-IFA 006 [2], clause 7.2.3 Query Image operation
• From ETSI GS NFV-IFA 006 [2], clause 7.3.1.3 Query Virtualised Compute Resource operation
• From ETSI GS NFV-IFA 006 [2], clause 7.3.3.4 Query Virtualised Compute Resource Information
operation
• From ETSI GS NFV-IFA 006 [2], clause 7.3.4.3 Query Compute Flavour operation
• From ETSI GS NFV-IFA 006 [2], clause 7.4.1.3 Query Virtualised Network Resource operation
• From ETSI GS NFV-IFA 006 [2], clause 7.4.3.4 Query Virtualised Network Resource Information
operation
• From ETSI GS NFV-IFA 006 [2], clause 7.5.1.3 Query Virtualised Storage Resource operation
• From ETSI GS NFV-IFA 006 [2], clause 7.5.3.4 Query Virtualised Storage Resources Information
operation
• From ETSI GS NFV-IFA 006 [2], clause 7.7.3 Query PM Job operation
• From ETSI GS NFV-IFA 006 [2], clause 7.7.8 Query Threshold operation
• From ETSI GS NFV-IFA 006 [2], clause 7.8.1.2 Query Compute Resource Reservation operation
• From ETSI GS NFV-IFA 006 [2], clause 7.8.2.2 Query Network Resource Reservation operation
• From ETSI GS NFV-IFA 006 [2], clause 7.8.3.2 Query Storage Resource Reservation operation
• From ETSI GS NFV-IFA 006 [2], clause 7.9.1.2 Query Compute Resource Quota operation
• From ETSI GS NFV-IFA 006 [2], clause 7.9.2.2 Query Network Resource Quota operation
• From ETSI GS NFV-IFA 006 [2], clause 7.9.3.2 Query Storage Resource operation
• From ETSI GS NFV-IFA 006 [2], clause 7.10.4 Query Policy operation
• From ETSI GS NFV-IFA 006 [2], clause 7.10.10 Query Subscription Info operation
The interface supports subscription/notification operations derived from the following interfaces in ETSI
GS NFV-IFA 005 [1] and ETSI GS NFV-IFA 006 [2]:
• From ETSI GS NFV-IFA 005 [1], clause 7.3.4 Virtualised Compute Resources Capacity Management
Interface
• From ETSI GS NFV-IFA 005 [1], clause 7.5.4 Virtualised Storage Resources Capacity Management
Interface
• From ETSI GS NFV-IFA 005 [1], clause 7.11.1 Compute Host Capacity Management Interface
• From ETSI GS NFV-IFA 006 [2], clause 7.3.2 Virtualised Compute Resources Change Notification
Interface
• From ETSI GS NFV-IFA 006 [2], clause 7.3.3 Virtualised Compute Resources Information Management
Interface
• From ETSI GS NFV-IFA 006 [2], clause 7.4.2 Virtualised Network Resources Change Notification
Interface
• From ETSI GS NFV-IFA 006 [2], clause 7.4.3 Virtualised Network Resources Information Management
Interface
ETSI
16 ETSI GS NFV-IFA 033 V4.1.1 (2020-08)
• From ETSI GS NFV-IFA 006 [2], clause 7.5.2 Virtualised Storage Resources Change Notification
Interface
• From ETSI GS NFV-IFA 006 [2], clause 7.5.3 Virtualised Storage Resources Information Management
Interface
• From ETSI GS NFV-IFA 006 [2], clause 7.6 Virtualised Resources Fault Management Interface
• From ETSI GS NFV-IFA 006 [2], clause 7.7 Virtualised Resources Performance Management Interface
• From ETSI GS NFV-IFA 006 [2], clause 7.8.4 Virtualised Resources Reservation Change Notification
Interface
• From ETSI GS NFV-IFA 006 [2], clause 7.9.4 Virtualised Resources Quota Change Notification Interface
• From ETSI GS NFV-IFA 006 [2], clause 7.10 Policy Management Interface
ETSI
17 ETSI GS NFV-IFA 033 V4.1.1 (2020-08)
History
Document history
V4.1.1 August 2020 Publication
ETSI