Preface
xxxiv
achieve extremely high density of users per geographical area. Providing radio
communication at high speeds and low power, as well as seamless roaming and network
mobility, remain major challenges for 5G. Physical layer security on the radio level may
prove to be an important challenge for 5G technology.
5G is presently under development by telecommunication vendors, EU projects (5G‐
ENSURE) and frameworks, and the 5G Infrastructure Public Private Partnership (5G PPP).
Many of the vendors have provided their vision of 5G services and security models in
White Papers. However, the standardization process of 5G is just starting within 3GPP,
although other standardization bodies, such as the Internet Engineering Task Force (IETF),
are continuously developing new secure protocols and architectures to be utilized in 5G.
It is important that 5G networks are securely designed and standardized from the beginning, rather than adding security as an afterthought.
Although security models of 3G and 4G networks based on Universal SIM cards
worked well, 5G security cannot be a carbon copy of existing designs, due to new
requirements. Initially, the main motivation for security in cellular networks was the
right functioning of the billing system, followed by encryption of the radio interface.
Location and identity privacy of the user were also supported, followed by two‐way
authentication in 3G to prevent fake base stations. 4G added state‐of‐the‐art cryptographic protocols and protection of physical tampering with the base stations, which
could be installed on user premises. While all those security properties are still valid, 5G
will face additional challenges due to increased user privacy concerns, new trust and
service models and requirements to support IoT and mission‐critical applications.
The Need for Security
Phone hacking was first spotted somewhere between the 1960s and 1970s, when phreakers demonstrated their skills to manipulate the functions of a telephone network.
Methods to attack telecommunication systems have evolved since then and have
changed shape from war dialers to viruses to worms to modern‐day advance persistent
threats. Tools to protect our telecommunication systems have also evolved from physical access control to antivirus to modern application and context aware firewalls.
Increased use of smartphones for data services and applications has exposed these
devices to the same security threats that were once known and dedicated to personal
computers (PCs). Mobile devices have replaced legacy system and have changed our
ways to learn, work, entertain, shop and travel. Bring Your Own Device (BYOD) and
cloud technologies have further diminished the enterprise boundaries and often challenged security experts to work out of the box strategies.
Motivations for attacking networks have also changed from fun‐loving immature
script kiddies to organized cybercrime rings and hacktivists with clear political and
financial objectives. In this age of digitalization, whereafter connecting humans using
Internet and mobile, we are talking about connecting things and machines. The mobile
has not yet completely replaced the personal computer but has become an ideal place
where personal information can be found for nefarious use. Therefore, security needs
to be architected to not only protect from the current threats but to address the increasing and evolving threat landscape. Adequate security should include threat intelligence,
visibility and real time protection.
xxxiv
achieve extremely high density of users per geographical area. Providing radio
communication at high speeds and low power, as well as seamless roaming and network
mobility, remain major challenges for 5G. Physical layer security on the radio level may
prove to be an important challenge for 5G technology.
5G is presently under development by telecommunication vendors, EU projects (5G‐
ENSURE) and frameworks, and the 5G Infrastructure Public Private Partnership (5G PPP).
Many of the vendors have provided their vision of 5G services and security models in
White Papers. However, the standardization process of 5G is just starting within 3GPP,
although other standardization bodies, such as the Internet Engineering Task Force (IETF),
are continuously developing new secure protocols and architectures to be utilized in 5G.
It is important that 5G networks are securely designed and standardized from the beginning, rather than adding security as an afterthought.
Although security models of 3G and 4G networks based on Universal SIM cards
worked well, 5G security cannot be a carbon copy of existing designs, due to new
requirements. Initially, the main motivation for security in cellular networks was the
right functioning of the billing system, followed by encryption of the radio interface.
Location and identity privacy of the user were also supported, followed by two‐way
authentication in 3G to prevent fake base stations. 4G added state‐of‐the‐art cryptographic protocols and protection of physical tampering with the base stations, which
could be installed on user premises. While all those security properties are still valid, 5G
will face additional challenges due to increased user privacy concerns, new trust and
service models and requirements to support IoT and mission‐critical applications.
The Need for Security
Phone hacking was first spotted somewhere between the 1960s and 1970s, when phreakers demonstrated their skills to manipulate the functions of a telephone network.
Methods to attack telecommunication systems have evolved since then and have
changed shape from war dialers to viruses to worms to modern‐day advance persistent
threats. Tools to protect our telecommunication systems have also evolved from physical access control to antivirus to modern application and context aware firewalls.
Increased use of smartphones for data services and applications has exposed these
devices to the same security threats that were once known and dedicated to personal
computers (PCs). Mobile devices have replaced legacy system and have changed our
ways to learn, work, entertain, shop and travel. Bring Your Own Device (BYOD) and
cloud technologies have further diminished the enterprise boundaries and often challenged security experts to work out of the box strategies.
Motivations for attacking networks have also changed from fun‐loving immature
script kiddies to organized cybercrime rings and hacktivists with clear political and
financial objectives. In this age of digitalization, whereafter connecting humans using
Internet and mobile, we are talking about connecting things and machines. The mobile
has not yet completely replaced the personal computer but has become an ideal place
where personal information can be found for nefarious use. Therefore, security needs
to be architected to not only protect from the current threats but to address the increasing and evolving threat landscape. Adequate security should include threat intelligence,
visibility and real time protection.
