Design Principles for 5G Security 81
include attach/detach, bearer activation, location update, and authentication. These
form the NAS signaling storms [1]. This can be more challenging in 5G, where billions
of devices will be connected to the same core network. Nokia Seimens Networks published [15] that signaling traffic is increasing 50% faster than the data traffic. Small cells
with a vast number of connected devices being mobile will increase mobility handovers, thus increasing the signaling traffic. This will not only increase the signaling load
on Mobility Management Entity (MME), but on other control entities such as HSS,
public data network gateway (P‐GW) and Serving Gateways (S‐GW), to maintain the
Quality of Service (QoS). Furthermore, the NAS layer of 3GPP protocols for UE attach
or detach functions, bearer activation, location update, and authentication can cause
signaling storms [16]. 3GPP recommends the use of IPSec encryption for LTE interfaces, such as X2, S1‐MME, S5 and S6, etc. Thus, each eNB is required to support
hundreds of IPSec tunnels, while the backhaul has to support thousands of tunnels.
Such a massive tunnel establishment not only complicates the security establishment
but massively increases the signaling load in the network. Furthermore, the tunnel
establishment is static in nature and predefined by the administrator that further complicates the process of ensuring security of the control traffic. The tunnels, statically
established, might not be in use but still sending periodic control information also
increases the signaling load.
Therefore, using the currently deployed security architectures in 5G will cause major
scalability and availability challenges, thus paving the way for DoS and DDoS attacks.
Novel security architectures are needed for 5G to ensure the security of users and protect the network from malicious attacks.
4.3 Novel Technologies for 5G Security
Since 5G is not an incremental improvement in 4G, security systems should also be
re‐designed according to the design and architectural requirements of 5G. The vision
for secure 5G systems outlined by NGMN is based on three principles:
1) Flexible security mechanisms;
2) Supreme built‐in security; and
3) Automation.
The vision is that 5G should provide highly robust security systems against cyber‐
attacks, with enhanced privacy and security assurance. The security mechanisms must
be flexible to incorporate novel technologies, for example for authentication and
identification. The flexibility should enable the option of using encryption for the user
plane and per network slice security parameters adjustment. The security systems must
also be able to be automated to adjust and adapt itself intelligently according to the
environment, threats or security controls. A holistic security orchestration and management will be highly required [4].
Since 5G has higher flexibility and agility, the two concepts that are most prominent to
play a vital role in 5G are virtual network functions (VNFs) and software‐based network
control. These features are foreseen to be enabled by Network Functions Virtualization
(NFV) and Software Defined Networking (SDN). NFV enables vendors to implement
network function in software called VNFs and deploy them on high‐end servers or cloud
include attach/detach, bearer activation, location update, and authentication. These
form the NAS signaling storms [1]. This can be more challenging in 5G, where billions
of devices will be connected to the same core network. Nokia Seimens Networks published [15] that signaling traffic is increasing 50% faster than the data traffic. Small cells
with a vast number of connected devices being mobile will increase mobility handovers, thus increasing the signaling traffic. This will not only increase the signaling load
on Mobility Management Entity (MME), but on other control entities such as HSS,
public data network gateway (P‐GW) and Serving Gateways (S‐GW), to maintain the
Quality of Service (QoS). Furthermore, the NAS layer of 3GPP protocols for UE attach
or detach functions, bearer activation, location update, and authentication can cause
signaling storms [16]. 3GPP recommends the use of IPSec encryption for LTE interfaces, such as X2, S1‐MME, S5 and S6, etc. Thus, each eNB is required to support
hundreds of IPSec tunnels, while the backhaul has to support thousands of tunnels.
Such a massive tunnel establishment not only complicates the security establishment
but massively increases the signaling load in the network. Furthermore, the tunnel
establishment is static in nature and predefined by the administrator that further complicates the process of ensuring security of the control traffic. The tunnels, statically
established, might not be in use but still sending periodic control information also
increases the signaling load.
Therefore, using the currently deployed security architectures in 5G will cause major
scalability and availability challenges, thus paving the way for DoS and DDoS attacks.
Novel security architectures are needed for 5G to ensure the security of users and protect the network from malicious attacks.
4.3 Novel Technologies for 5G Security
Since 5G is not an incremental improvement in 4G, security systems should also be
re‐designed according to the design and architectural requirements of 5G. The vision
for secure 5G systems outlined by NGMN is based on three principles:
1) Flexible security mechanisms;
2) Supreme built‐in security; and
3) Automation.
The vision is that 5G should provide highly robust security systems against cyber‐
attacks, with enhanced privacy and security assurance. The security mechanisms must
be flexible to incorporate novel technologies, for example for authentication and
identification. The flexibility should enable the option of using encryption for the user
plane and per network slice security parameters adjustment. The security systems must
also be able to be automated to adjust and adapt itself intelligently according to the
environment, threats or security controls. A holistic security orchestration and management will be highly required [4].
Since 5G has higher flexibility and agility, the two concepts that are most prominent to
play a vital role in 5G are virtual network functions (VNFs) and software‐based network
control. These features are foreseen to be enabled by Network Functions Virtualization
(NFV) and Software Defined Networking (SDN). NFV enables vendors to implement
network function in software called VNFs and deploy them on high‐end servers or cloud
