Home›Telecom›Non-Functional Architecture›Security & Identity← NFR overview
Non-functional architecture
Reference Architecture

Security & Identity

Security & Identity Architecture: Defense-in-depth · Zero Trust · IAM/RBAC · Encryption · DMZ · Firewalls.

Security & Identity Architecture
Defense-in-depth · Zero Trust · IAM/RBAC · Encryption · DMZ · Firewalls
Network Security Zones (Defense-in-Depth / DMZ Architecture)
Public Zone (Internet)
CDN / Edge Cache DDoS Protection WAF (Web Application Firewall) DNS / GSLB TLS 1.3 Termination
▼ Perimeter Firewall (L4/L7) ▼
DMZ — Demilitarised Zone
API Gateway Reverse Proxy / Load Balancer Identity Provider (IdP) Rate Limiter Bot Protection Certificate Management
▼ Internal Firewall + Network Policy ▼
Application Zone (Service Mesh — mTLS enforced)
Microservices (K8s Pods) Service Mesh (mTLS) Event Streaming Bus Cache Layer Internal Load Balancer
▼ Data Firewall + Network Segment Isolation ▼
Data Zone (Encrypted at Rest — AES-256)
Relational Databases NoSQL Stores Object Storage Secret Secrets Management Platform (Hardware-Backed) Key Management Service Audit Log Store
IAM — Identity & Access Management
Authentication · Authorisation · RBAC · ABAC
AuthN ProtocolOAuth 2.0 / OIDC for all human and service identities. Enterprise Federation Protocol (SAML/WS-Fed) for enterprise federation.
Token TypeJWT (Asymmetric Signing Algorithm signed). Access token TTL: configurable. Refresh token TTL: 8 h. Revocation via short-lived JTI allowlist.
RBAC ModelRole → Permission → Resource. Roles assigned to user groups. Least-privilege by default. No wildcard permissions in production.
ABAC ExtensionAttribute-based policies for fine-grained data access (e.g. agent can only view subscribers in their assigned region).
Service IdentityEvery microservice has a workload identity (Workload Identity Framework). mTLS certificates issued per pod — no shared service accounts.
MFATime-based OTP / Hardware Key / Passkey mandatory for all administrative and privileged access. Not optional for production console access.
Session MgmtStateless — no server-side sessions. Token validation at API gateway on every request. Zero-trust: no implicit trust from network location.
Zero-Trust RBAC Workload Identity Standard mTLS Identity
Encryption — At Rest, In Transit & In Use
AES-256 · TLS 1.3 · mTLS · KMS · HSM
At RestAES-256-GCM for all data at rest. Database-level encryption + application-level field encryption for PII and financial data. Keys stored in Hardware-Backed Key Management Service — never in application config.
In TransitTLS 1.3 minimum on all external traffic. TLS 1.2 deprecated. Cipher suites restricted to ECDHE + AES-GCM / CHACHA20. Certificate pinning on mobile clients.
mTLS (Service-to-Service)Mutual TLS enforced for all inter-service communication via service mesh. Certificates auto-rotated on a daily cadence. Short-lived — compromise window minimised.
Key ManagementEnvelope encryption: data encrypted with Data Encryption Key (DEK); DEK encrypted with Key Encryption Key (KEK) in KMS. Key rotation every 90 days. Automatic.
SecretsNo secrets in code, config files or environment variables. All secrets injected at runtime from a secrets vault with short-lived dynamic credentials.
In UseSensitive computations in isolated secure enclaves (TEE/Secure Enclave) for payment card processing and KYC biometric matching where applicable.
AES-256-GCM TLS 1.3 mTLS Hardware-Backed Key Management Service Envelope Encryption
Firewalls, WAF & DDoS Protection
L3/L4/L7 · WAF Rules · Rate Limiting · Anti-Bot
Perimeter FWStateful L4 firewall. Default-deny ingress. Whitelist-only egress. All rules version-controlled in IaC — no manual changes in production.
WAF (L7)OWASP Top 10 ruleset enforced. Custom rules for SQL injection, XSS, path traversal, XXE. Managed rule groups updated weekly. Block mode, not detect mode.
DDoSNetwork-layer volumetric DDoS protection at CDN edge. Application-layer protection at API gateway: per-IP and per-API-key rate limiting with adaptive throttling.
Internal FWKubernetes NetworkPolicy for pod-to-pod traffic. Application zone to data zone traffic restricted to approved microservice-to-database pairs only. No unrestricted lateral movement.
Egress ControlAll outbound traffic from application zone routed through egress proxy. Domain allowlist. Unknown destinations blocked. Egress logs to SIEM.
OWASP Top 10 Default-Deny NetworkPolicy IaC-managed
Non-Functional Requirements — Summary Reference
NFR CategoryRequirementTarget / StandardStatus
AvailabilityPlatform availability SLO99.99% (≈ minutes per year)Mandatory
LatencyAPI P99 latency (tier-1 services)< Sub-second P99Mandatory
ThroughputCDR processing rateVery High — stream processing sustainedMandatory
RTORevenue-critical service recovery<Minutes (Tier 0 — near-zero)Mandatory
RPOMaximum data loss windowNear-zero (Tier 0 — synchronous replication)Mandatory
SecurityEncryption in transitTLS 1.3+ on external traffic, mTLS on all inter-service communicationMandatory
SecurityEncryption at restAES-256-GCM all data storesMandatory
IdentityAuthentication protocolOAuth 2.0 / OIDC + Workload Identity Standard workload identityMandatory
PII ComplianceGDPR — Right to Erasure SLAConfirmed deletion within the regulatory SLA windowMandatory
ResilienceCircuit breaker on all external callsError rate >50% in 10 s window triggers openMandatory
IdempotencyAll financial mutation endpointsIdempotency key + 24 h dedup storeMandatory
ScalabilityHPA on all stateless servicesCPU target 60%, scale within a short cool-down windowMandatory
Anti-AffinityPod distributionRequired: no two replicas on same node; Preferred: spread across AZsMandatory
Technical DebtSprint debt remediation allocationMinimum 20% per sprintRecommended
ObservabilityDistributed tracing coverage100% of requests carry traceId; 10% sampledMandatory
CI/CD SecuritySAST + SCA in every pipelineCritical/High CVEs block mergeMandatory
Non-functional architectureIdentity & Access Management (IAM)→Non-functional architectureNext: Network & Infrastructure→