The five articles in this special section focus on novel research contributions, demonstration results, and standardization efforts on 5G network security, privacy and trust. Currently it is expected that the generation (5G) wireless systems will soon provide rich ubiquitous communication infrastructure with wide a range of high-quality services. It is foreseen that 5G communications will offer significantly greater data bandwidth and much improved capability for networking, resulting in unfaltering user experiences for services such as: massive content streaming, telepresence, virtual/augmented reality, crowded area communications, user-centric computing, smart personal networks, Internet of Things (IoT), smart buildings, smart cities, etc. 5G systems are currently at the center of attention of academia, industry, and governments worldwide as they drive many new requirements for diff erent network capabilities. As 5G aims at utilizing many promising network technologies, such as Software Defined Networking (SDN), Network Functions Virtualization (NFV), Information Centric Network (ICN), Network Slicing, Cloud Computing, MEC, etc., supporting a huge number of connected devices integrating the above mentioned advanced technologies and innovating new techniques will surely bring tremendous challenges for security, privacy and trust.
5G is a paradigm-shifting communications technology that is envisioned to provide an even wider range of high-quality services than 4G. It promises to offer high bandwidth and ultra-low latency, which are desirable not only for voice and mobile broadband, but also for new vertical industries such as healthcare, public transport, manufacturing, media and entertainment. Therefore, secure network architectures, mechanisms, and protocols are necessary to for a foundation of 5G to address potential security threats. This special issue is focusing on original research results and achievements by scientists, designers, and developers working on various issues and challenges related to 5G networks security.
The promise of disparate features envisioned by the 3GPP for 5G, such as offering enhanced Mobile Broadband connectivity while providing massive Machine Type Communications likely with very low data rates and maintaining Ultra Reliable Low Latency Communications requirements, create a very challenging environment for protecting the 5G networks themselves and associated assets. To overcome such complexity, future 5G networks must employ a very high degree of network and service management automation, which is a security challenge by itself as well as an opportunity for smarter and more efficient security functions. In this paper, we present the smart, trustworthy and liable 5G security platform being designed and developed in the INSPIRE-5Gplus1 project. This platform takes advantage of new techniques such as Machine Learning (ML), Artificial Intelligence (AI), Distributed Ledger Technologies (DLT), network softwarization and Trusted Execution Environment (TEE) for closed-loop and end-to-end security management following a zero-touch model in 5G and Beyond 5G networks. To this end, we specifically elaborate on two key aspects of our platform, namely security management with Security Service Level Agreements (SSLAs) and liability management, in addition to the description of the overall architecture.
5G is envisioned as a transformation of the communications architecture towards multi-tenant, scalable and flexible infrastructure, which heavily relies on virtualised network functions and programmable networks. In particular, orchestration will advance one step further in blending both compute and data resources, usually dedicated to virtualisation technologies, and network resources into so-called slices. Although 5G security is being developed in current working groups, slice security is seldom addressed.In this work, we propose to integrate security in the slice life cycle, impacting its management and orchestration that relies on the virtualization/ softwarisation infrastructure. The proposed security architecture connects the demands specified by the tenants through as-a-service mechanisms with built-in security functions relying on the ability to combine enforcement and monitoring functions within the software-defined network infrastructure. The architecture exhibits desirable properties such as isolating slices down to the hardware resources or monitoring service-level performance.
5G networks will provide opportunities for the creation of new services, for new business models, and for new players to enter the mobile market. The networks will support efficient and cost-effective launch of a multitude of services, tailored for different vertical markets having varying service and security requirements, and involving a large number of actors. Key technology concepts are network slicing and network softwarization, including network function virtualization and software-defined networking. The presented security architecture builds upon concepts from the 3G and 4G security architectures but extends and enhances them to cover the new 5G environment. It comprises a toolbox for security relevant modeling of the systems, a set of security design principles, and a set of security functions and mechanisms to implement the security controls needed to achieve stated security objectives. In a smart city use case setting, we illustrate its utility; we examine the high-level security aspects stemming from the deployment of a large number of IoT devices and network softwarization.
The paper elaborates on the technological and architectural innovations researched and developed by 5G-PPP Phase 1 projects and covering innovation areas such as 5G system design and evaluation, novel air interfaces, network management and security as well as virtualization and service deployment aspects.
This document provides an early vision (at M4) of the 5G security and privacy enablers proposed by the 5G-ENSURE project, and that are planned to be developed through two major releases: v1.0 (R1) due at M11/Sep’16 and v2.0 (R2) due at M22/Aug’17. It details the Technical Roadmap for v1.0 (R1) in terms of enablers in scope and their features, while providing insights for v2.0 (R2) enablers that will be fully detailed in an update of this deliverable (D3.5 due at M13/Nov’16) taking account of the progress and achievements made by that time. Enablers envisioned are here presented organized in categories, which represent major security areas recognized as topmost priorities for 5G-PPP & 5G Security: Authentication, Authorization and Accountability (AAA); Privacy; Trust; Security Monitoring and Network management & virtualization isolation. They are also presented following a common template covering each of the following key aspects: product vision, technology area, security aspects, security challenges, technical roadmap for first release vs. next release. In the AAA category the main focus is on 5G users’ authentication, authorization and accounting, but the contribution of the AAA enablers goes beyond the incremental improvements to security that one would expect in a next-generation network. The evolving 5G network will support an unpredictable number of devices due to the boom of Internet of Things (IoT), whose security these enablers will aim to address. Moreover, the enablers target to integrate authentication and authorization functions between satellite and terrestrial systems. The main objective of the 5G-Ensure Privacy enablers is to identify in advance 5G user privacy requirements and to provide security mechanisms able to prevent privacy violations by adopting a proactive, privacy-by-design approach. For each 5G use case, the privacy mitigation technology (e.g., anonymity by using temporary identity, access control mechanisms, new encryption system and procedures, etc.) was also investigated so as to satisfy privacy requirements. The privacy enablers aim to enhance user data protection by proposing solutions at several layers: at the network layer, as well as application layer, i.e., privacy as a service. The Trust category will provide trust models which will address the complex relationships between the many actors in 5G networks including the machine-to-machine interactions characterising the next generation networks. The trust model needs to address the different aspects of trust, between automated systems (M2Mt), between human stakeholders holding responsibilities for different parts of 5G networks, between user and network operators and between users of the network (U2Ut), trust that a human stakeholder has towards a system (U2Mt), that an automated system (machine) has in users that it interacts with. 5G-ENSURE project also aims at providing new innovative solutions ensuring the highest level of security and resilience in 5G network. Mobile networks will dramatically evolve with the fifth generation of networks compared to 3/4G, in particular with new concepts and technologies such Internet of Things, infrastructure virtualization (SDN, NFV), network resource sharing, new access interfaces, dynamic network topologies, slicing and so forth. These technologies introduce new security and resilience and provide new opportunities to implement extensive and accurate security solutions. Thus, new innovative approaches to predict and counter these challenges will be considered by the category devoted to Monitoring the 5G security.
Deliverable D3.5 is the update of the 5G-ENSURE security enablers Technical Roadmap previously delivered (i.e. D3.1). Compared to previous deliverable which was only detailing the features of 5G security enablers in scope of the first release (i.e. v1.0 (R1) released on M11/Sep’16), D3.5 is more complete in the sense it provides all the details regarding enablers (either in continuation or fully new) in scope of the second (also last) release (v2.0 (R2) due at M22/Aug’17) detailing for each of them the targeted features, while showing excellent coverage they have, individually but most importantly conjointly, with respect use cases identified. Overall D3.5 paves the way towards the second wave of 5G security enablers to be specified and then for most of them be software released by end of the project as part of v2.0. It also contributes to further advance 5G Security Vision within 5G-PPP community and beyond.
This deliverable (D2.4) of the 5G-ENSURE project describes a draft security architecture for 5G networks. The focus lies on a logical and functional architecture and omits (most) aspects related to physical/deployment architecture. This focus is motivated by general trends such as network de-perimetrization as well as 5G systems’ strong dependency on software defined networking and virtualization in general. Furthermore, this focus has reduced the otherwise strong interdependency between this architecture task and the trust modelling and risk analysis tasks in 5G-ENSURE. Still, each of these three tasks have at the time of writing produced initial draft documents, which will then be re-used in a second iteration of all three tasks, producing updated, final versions.
This document describes the open specifications of 5G Security enablers planned to compose the first software release (i.e. v1.0) of 5G-ENSURE Project due in September 2016 (M11). The enablers’ open specifications are presented per security areas in scope of the project, namely: Authentication, Authorization and Accounting (AAA), Privacy, Trust, Security Monitoring, and Network management & virtualisation isolation. For each of these categories the open specifications of all enablers planned in the project's Technical Roadmap for v1.0 and having features for v1.0 are detailed following the same template. Overall, this deliverable paves the way towards the development and demonstration of the first set of 5G-ENSURE security enablers as planned for v1.0 in the project's Technical Roadmap (i.e. D3.1). It is also a valuable input to both works on the 5G Security architecture and 5G Security testbed, since it provides the details regarding security enablers necessary in order to understand their mapping to 5G security architectural components, as well as their integration, testing, demonstration, and assessment on the 5G security testbed
OPTET introduces a trustworthiness-by-design methodology for the development of socio-technical systems. It defines a unified model of trust and trustworthiness to describe the processes of such systems, and delivers a set of generic enablers on trustworthiness that will complement large-scale ICT platforms and contribute to achieve better trust distribution.
Cloud- and service-oriented computing paradigms are intrinopaque to their users, as they cannot inspect providers’ implementations, and important concerns about aspects like security, compliance, dependability can arise. Therefore, users have to make trust decisions with respect to software providers, with the hope that there will not be any detrimental consequences. To contrast this situation, the paper proposes a framework to define, assess, monitor and make explicit the elements of a service that render it trustworthy. This paper relies on a number of recent scientific contributions, and aims at supporting informed decisions on obscure service implementations by machine-understandable statements about their objective (trustworthiness) characteristics. Such statements would innovate upon many aspects of service operations, from discovery to composition, deployment and monitoring. To demonstrate this, the paper presents a concept for a Trustworthy Service Marketplace.
Security is becoming a major issue in the development of new environments. Within the European Commission Programs oriented to define the Future Internet; the challenge taken on by FI-WARE project has been the design of server oriented architecture inspired by Secure by Design principles. Security in FI-WARE is defined as context adaptive architecture that guarantees protection against external attacks; privacy in communications & personal data sharing; and secure & trustworthy services as the default operation mode of the Future Internet.
The success of organizations or business networks depends on fast and well-founded decisions taken by the relevant people in their specific area of responsibility. To enable timely and well-founded decisions, it is often necessary to perform ad-hoc analyses in a collaborative manner involving domain experts, line-of-business managers, key suppliers or customers. Current Business Intelligence (BI) solutions fail to meet the challenges of ad-hoc and collaborative decision support, slowing down and hurting organizations. The main goal of our envisioned system, which will be designed and implemented in a future research project, is to realize a highly scalable and flexible platform for collaborative, ad-hoc BI over large data sets. This will be achieved by developing methodologies, concepts and an infrastructure to enable an information self-service for business users and collaborative decision making over high-volume data sources within and across organizations.
Felix Klaedtke合作论文数ETH Zurich
Computer Science Department
Universitatstr. 6
CNB F 107.1
CH-8092 Zurich, Switzerland5