Ahmad, Liyanage, Shahabuddin, Ylianttila, and Gurtov
90
Mutual authentication and key agreement between the UE and the network is
important in many aspects, the most important being the identity insurance of the UE.
In LTE, the UE and the network, or its entities such as the Mobility Management Entity
(MME), perform mutual authentication through the Evolved Packet System (EPS)
Authentication and Key Agreement (AKA), known as the EPS AKA. The EPS AKA is
secure enough and has no visible vulnerabilities demonstrated so far [47]. When a UE
connects to the EPC through the non‐3GPP access network, the UE is authenticated
through the AAA server. For trusted non‐3GGP access networks, the UE and AAA
server use Extensible Authentication Protocol‐AKA (EAP‐AKA) or improved EAP‐
AKA for authentication. For mistrusted non‐3GPP access networks, the UE uses the
evolved packet data gateway (ePDG) IPsec tunnel establishment to connect to the
EPC [49]. Such control channels, besides being secure, have the following benefits [47]:
● The messages are short compared to other authentication protocols.
● It requires only one handshake between the UE and serving network, and between
the serving and home networks.
● The HSS is updated through the serving network, thus is capable of handling many
requests.
● The symmetric‐key‐based protocol makes the computations required in the authentication center (part of the HSS), and in the USIM (Universal Subscriber Identity
Module) very efficient compared to public‐key‐based mechanisms. However,
the advantages of the use of public‐key based authentication and key agreement
schemes could include that the home network does not need to be contacted for each
authentication.
It is expected that in 5G there will be multiple control points in a network, which will
require security of the control channels among those control points. For example, the
concepts of SDN will be used for the benefits described in the previous sections. Thus,
multiple controllers will be used for higher availability and scalability. Therefore, the control channels among the controllers must be secured. Similarly, the control channel
between SDN controller and SDN switches must also be secured. The OpenFlow variant
of SDN uses TLS, in which identification certificates are properly checked in either
direction and allow encrypting the control channel in order to secure it and prevent it
from eavesdropping. Furthermore, multiple control channels ( associations) between
switches and controllers are suggested to avoid the chances of services outages due to
connection failures. The latest OpenFlow specifications support multiple con nections
between switches and controllers to improve network resilience in case of link failures.
Therefore, fast link restoration mechanisms and backup entries with different priorities
in the OpenFlow switches have been proposed and demonstrated in [49]. The backup
links are computed by the controller and the traffic is switched to the backup link upon
failure of the existing link. Similarly, flow entry migration techniques are proposed in
[51] to reinstate a flow within 36 ms. This mechanism fulfills the carrier grade recovery
requirement of 50 ms. Furthermore, HIP‐based [52] secure control channels between the
switches and the controllers are also proposed [53].
Moreover, IPsec is the most commonly used security protocol to secure the communication channels in current telecommunication networks such as 4G‐LTE [55].
Thus, novel IPsec‐based communication architectures were designed to secure control
and data channels of 5G [56]. The proposed architecture use distributed Security
90
Mutual authentication and key agreement between the UE and the network is
important in many aspects, the most important being the identity insurance of the UE.
In LTE, the UE and the network, or its entities such as the Mobility Management Entity
(MME), perform mutual authentication through the Evolved Packet System (EPS)
Authentication and Key Agreement (AKA), known as the EPS AKA. The EPS AKA is
secure enough and has no visible vulnerabilities demonstrated so far [47]. When a UE
connects to the EPC through the non‐3GPP access network, the UE is authenticated
through the AAA server. For trusted non‐3GGP access networks, the UE and AAA
server use Extensible Authentication Protocol‐AKA (EAP‐AKA) or improved EAP‐
AKA for authentication. For mistrusted non‐3GPP access networks, the UE uses the
evolved packet data gateway (ePDG) IPsec tunnel establishment to connect to the
EPC [49]. Such control channels, besides being secure, have the following benefits [47]:
● The messages are short compared to other authentication protocols.
● It requires only one handshake between the UE and serving network, and between
the serving and home networks.
● The HSS is updated through the serving network, thus is capable of handling many
requests.
● The symmetric‐key‐based protocol makes the computations required in the authentication center (part of the HSS), and in the USIM (Universal Subscriber Identity
Module) very efficient compared to public‐key‐based mechanisms. However,
the advantages of the use of public‐key based authentication and key agreement
schemes could include that the home network does not need to be contacted for each
authentication.
It is expected that in 5G there will be multiple control points in a network, which will
require security of the control channels among those control points. For example, the
concepts of SDN will be used for the benefits described in the previous sections. Thus,
multiple controllers will be used for higher availability and scalability. Therefore, the control channels among the controllers must be secured. Similarly, the control channel
between SDN controller and SDN switches must also be secured. The OpenFlow variant
of SDN uses TLS, in which identification certificates are properly checked in either
direction and allow encrypting the control channel in order to secure it and prevent it
from eavesdropping. Furthermore, multiple control channels ( associations) between
switches and controllers are suggested to avoid the chances of services outages due to
connection failures. The latest OpenFlow specifications support multiple con nections
between switches and controllers to improve network resilience in case of link failures.
Therefore, fast link restoration mechanisms and backup entries with different priorities
in the OpenFlow switches have been proposed and demonstrated in [49]. The backup
links are computed by the controller and the traffic is switched to the backup link upon
failure of the existing link. Similarly, flow entry migration techniques are proposed in
[51] to reinstate a flow within 36 ms. This mechanism fulfills the carrier grade recovery
requirement of 50 ms. Furthermore, HIP‐based [52] secure control channels between the
switches and the controllers are also proposed [53].
Moreover, IPsec is the most commonly used security protocol to secure the communication channels in current telecommunication networks such as 4G‐LTE [55].
Thus, novel IPsec‐based communication architectures were designed to secure control
and data channels of 5G [56]. The proposed architecture use distributed Security
