Design Principles for 5G Security 77
industries, provide anything as‐a‐service, and integrate new models of service delivery. The 5G ecosystem cannot be fully visualized at this moment, due to the rapid
development and integration of new devices and services. However, the main attractions of 5G beyond extended connectivity, higher data rates and lower latencies will
be the easy placement and utilization of new services and functions. This will complicate the security landscape as well. To make the security landscape easy to comprehend, we provide a discussion on security in two domains. First, the security of
access networks, for example Radio Access Networks (RAN) that can be a composite of multiple access technologies such as cellular networks RAN comprising small
and large base stations and WiFi, etc. Second, the security of the core network in
which the network control resides with operator and vendor specific services. The
International Telecommunication Union’s Telecommunication sector (ITU‐T) has
proposed dimensions of security for telecommunication networks that address all
the aspects of security [6]. Hence, first we will provide a brief introduction to these
recommendations and then we will discuss different security challenges in different
areas of 5G networks.
4.2.1 Security Recommendations by ITU‐T
Security dimensions are proposed by ITU‐T in its security recommendation [6] to
address almost all the aspects of network security. The security dimensions include a
set of security measures that can be used to protect the users and network against all
major security threats. These dimensions are:
● Access Control: security measures that ensure only authorized personnel or devices
access the network resources.
● Authentication: security mechanisms that ensure identities of the communicating
parties and that a user or device is not attempting a masquerade or unauthorized
replay of previous communications.
● Non‐Repudiation: ensure that a particular action has been performed by a specific
user or device is non‐repudiation. Proper identities are used to ensure that authentic
user or device can access particular services and resources.
● Data Confidentiality: security mechanisms to protect the data from unauthorized
access. Encryption, access control mechanisms and file permissions are used to
ensure data confidentiality.
● Communication Security: ensure that the data flows between the authorized end‐
points and is not diverted or intercepted in between.
● Data Integrity: ensures the correctness or accuracy of data in transmission and protects it from unauthorized modification, deletion, creation and replication.
● Availability: ensures that there is no denial of authorized access to network resources
and applications. Events impacting the network, such as system failures or disasters,
scalability and security compromise, must not limit access to authorized users
and devices.
● Privacy: mechanisms that ensure protection of information, which might be derived
from observing network activities.
industries, provide anything as‐a‐service, and integrate new models of service delivery. The 5G ecosystem cannot be fully visualized at this moment, due to the rapid
development and integration of new devices and services. However, the main attractions of 5G beyond extended connectivity, higher data rates and lower latencies will
be the easy placement and utilization of new services and functions. This will complicate the security landscape as well. To make the security landscape easy to comprehend, we provide a discussion on security in two domains. First, the security of
access networks, for example Radio Access Networks (RAN) that can be a composite of multiple access technologies such as cellular networks RAN comprising small
and large base stations and WiFi, etc. Second, the security of the core network in
which the network control resides with operator and vendor specific services. The
International Telecommunication Union’s Telecommunication sector (ITU‐T) has
proposed dimensions of security for telecommunication networks that address all
the aspects of security [6]. Hence, first we will provide a brief introduction to these
recommendations and then we will discuss different security challenges in different
areas of 5G networks.
4.2.1 Security Recommendations by ITU‐T
Security dimensions are proposed by ITU‐T in its security recommendation [6] to
address almost all the aspects of network security. The security dimensions include a
set of security measures that can be used to protect the users and network against all
major security threats. These dimensions are:
● Access Control: security measures that ensure only authorized personnel or devices
access the network resources.
● Authentication: security mechanisms that ensure identities of the communicating
parties and that a user or device is not attempting a masquerade or unauthorized
replay of previous communications.
● Non‐Repudiation: ensure that a particular action has been performed by a specific
user or device is non‐repudiation. Proper identities are used to ensure that authentic
user or device can access particular services and resources.
● Data Confidentiality: security mechanisms to protect the data from unauthorized
access. Encryption, access control mechanisms and file permissions are used to
ensure data confidentiality.
● Communication Security: ensure that the data flows between the authorized end‐
points and is not diverted or intercepted in between.
● Data Integrity: ensures the correctness or accuracy of data in transmission and protects it from unauthorized modification, deletion, creation and replication.
● Availability: ensures that there is no denial of authorized access to network resources
and applications. Events impacting the network, such as system failures or disasters,
scalability and security compromise, must not limit access to authorized users
and devices.
● Privacy: mechanisms that ensure protection of information, which might be derived
from observing network activities.
