Introduction to 5G Security Architecture: NFV, Keys, and 2 Authentication

Introduction to 5G Security Architecture: NFV, Keys, and 2 Authentication

Clearly, embarking on the development of a new communication standard without considering security mechanisms is an extraordinarily questionable and futile endeavor.

5G Security Architecture — a set of security mechanisms and procedures implemented in fifth-generation networks covering all components of the network, from the core to the radio interfaces.

Fifth-generation networks are essentially an evolution of fourth-generation LTE networks.The most significant changes have occurred in radio access technologies. A new RAT (Radio Access Technology) — 5G New Radio. As for the core network, it has not undergone such substantial changes. Consequently, the security architecture of 5G networks was developed with an emphasis on reusing relevant technologies adopted in the 4G LTE standard.

However, it is worth noting that rethinking well-known threats such as attacks on radio interfaces and the signaling layer (signalling plane), DDoS attacks, Man-In-The-Middle attacks, etc., has prompted telecommunications operators to develop new standards and integrate entirely new security mechanisms into fifth-generation networks.

Introduction to 5G Security Architecture: NFV, Keys, and 2 Authentication

Prerequisites

In 2015, the International Telecommunication Union created the first of its kind global plan for the development of fifth-generation networks, making the development of security mechanisms and procedures in 5G networks particularly urgent.

The new technology promised truly impressive data transfer speeds (over 1 Gbps), latency of less than 1 ms, and the ability to simultaneously connect up to 1 million devices within a radius of 1 km². Such high demands placed on fifth-generation networks were reflected in their organizational principles.

The key principle became decentralization, which involved placing numerous local databases and processing centers at the edge of the network. This helped minimize delays during M2M-communication and alleviate the core network's load due to the service of a vast number of IoT devices. Thus, the boundaries of next-generation networks were extended all the way to base stations, enabling the creation of local communication centers and the provision of cloud services without the risk of critical delays or service outages. Naturally, the altered approach to network organization and customer service attracted the attention of malicious actors, as it opened up new opportunities for attacks on both users' confidential information and the network components themselves, with the aim of causing service disruptions or seizing the operator's computing resources.

Main vulnerabilities of 5th generation networks

Increased attack surface

Learn moreWhen building telecommunication networks of the 3rd and 4th generations, operators typically limited themselves to working with one or several vendors who provided a complete package of hardware and software. This meant that everything could work 'out of the box'—it was enough to install and configure the equipment purchased from the vendor; there was no need to replace or supplement proprietary software. Current trends contradict this 'classic' approach and are directed towards network virtualization, a multi-vendor approach to their construction, and software diversity. Technologies such as SDN (Software Defined Network) and NFV (Network Functions Virtualization) are becoming increasingly popular, leading to the inclusion of a vast amount of software built on open-source foundations in the processes and functionalities of network management. This gives malicious actors the opportunity to better study the operator's network and identify more vulnerabilities, which, in turn, increases the attack surface of next-generation networks compared to current ones.

A large number of IoT devices

Learn moreBy 2021, around 57% of devices connected to 5G networks will be IoT devices. This means that most hosts will have limited cryptographic capabilities (see point 2) and, consequently, will be vulnerable to attacks. The enormous number of such devices will increase the risk of botnet proliferation and enable even more powerful and distributed DDoS attacks.

Limited cryptographic capabilities of IoT devices

Learn moreAs already mentioned, fifth-generation networks actively engage peripheral devices that help offload some of the network core, thereby reducing latency. This is crucial for essential services such as unmanned vehicle management and emergency alert systems IMS and others, for which ensuring minimal latency is critical, as human lives depend on it. Due to the connection of a large number of IoT devices, which, due to their small size and low energy consumption, have very limited computational resources, 5G networks become vulnerable to attacks aimed at taking control and subsequently manipulating such devices. For example, scenarios may involve infecting IoT devices that are part of a "smart home", with types of malware such as Ransomware and extortion programs. There are also possible scenarios for taking control of unmanned vehicles, which receive commands and navigation information through the "cloud". Formally, this vulnerability stems from the decentralization of next-generation networks, but the next point will highlight the issue of decentralization more explicitly.

Decentralization and expanding network boundaries

Learn morePeripheral devices acting as local network cores route user traffic, handle requests, and perform local caching and storage of user data. Thus, the boundaries of 5th generation networks are expanding beyond the core to the edge, including local databases and 5G-NR (5G New Radio) radio interfaces. This creates a potential attack vector for the computational resources of local devices, which are inherently less secure than the central network core nodes, aimed at causing denial of service. This could result in internet outages for entire regions, malfunctions of IoT devices (such as in smart home systems), and unavailability of emergency alert services IMS.

Introduction to 5G Security Architecture: NFV, Keys, and 2 Authentication

However, ETSI and 3GPP have currently published more than 10 standards addressing various aspects of 5G network security. The overwhelming majority of the mechanisms described there aim to protect against vulnerabilities (including those mentioned above). One of the main standards is TS 23.501 Version 15.6.0, which describes the security architecture of 5th generation networks.

5G Architecture

Introduction to 5G Security Architecture: NFV, Keys, and 2 Authentication
First, let’s turn to the key principles of 5G network architecture, which will help fully reveal the meaning and responsibilities of each software module and security function within 5G.

  • Separation of network nodes into elements that ensure the operation of protocols for the user plane and elements that ensure the operation of protocols for the control plane , enhancing flexibility regarding the scaling and deployment of the network, i.e., allowing for centralized or decentralized placement of individual network node components.
  • Support for network slicing, based on services provided to specific groups of end-users.
  • Implementation of network elements as virtual network functions.
  • Supporting simultaneous access to centralized and local services, i.e., realizing the concepts of cloud fog computingand edge computing. Convergentarchitecture, uniting different types of access networks — 3GPP 5G New Radio and
  • Implementation non-3GPP (Wi-Fi, etc.) — with a single network core. non-3GPP (Wi-Fi, etc.) — with a single network core.
  • Support for unified authentication algorithms and procedures regardless of the type of access network.
  • Support for stateless network functions, where the computed resource is separated from the resource storage.
  • Support for roaming with traffic routing both through the home network and local breakout in the guest network.
  • Interaction between network functions is represented in two ways: service-oriented and interface-oriented.

The security concept of fifth-generation networks includes:

  • User authentication from the network side.
  • Network authentication from the user side.
  • Cryptographic key agreement between the network and user equipment.
  • Encryption and integrity control of signaling traffic.
  • Encryption and integrity control of user traffic.
  • Protection of the user identifier.
  • Protection of interfaces between different network elements according to the security domain concept.
  • Isolation of different layers of the mechanism network slicing and defining distinct security levels for each layer.
  • User authentication and traffic protection at the end service level (IMS, IoT, and others).

Key software modules and 5G security network functions

Introduction to 5G Security Architecture: NFV, Keys, and 2 Authentication AMF (Access & Mobility Management Function) — provides:

  • Organization of control plane interfaces.
  • Organization of signaling traffic exchange RRC, encryption and integrity protection of its data.
  • Organization of signaling traffic exchange NAS, encryption and integrity protection of its data.
  • Management of user equipment registration in the network and control of possible registration states.
  • Management of user equipment connection to the network and control of possible states.
  • Management of user equipment availability in the network in CM-IDLE state.
  • Management of user equipment mobility in the network in CM-CONNECTED state.
  • Transmission of short messages between user equipment and SMF.
  • Management of geolocation services.
  • Allocation of stream identifier EPS for interaction with EPS.

SMF (Session Management Function) — provides:

  • Session management, i.e., creation, modification, and release of a session, including support for tunneling between the access network and the UPF.
  • Distribution and management of IP addresses for end-user equipment.
  • Selection of the UPF gateway to be used.
  • Organization of interaction with the PCF.
  • Policy application management. QoS..
  • Dynamic configuration of end-user equipment using DHCPv4 and DHCPv6 protocols.
  • Control over the collection of billing data and organization of interaction with the billing system.
  • Seamless service provision (from English. SSC — Session and Service Continuity.).
  • Interaction with guest networks during roaming.

UPF. (English: User Plane Function) — provides:

  • Interaction with external data transmission networks, including the global Internet.
  • Routing of user packets.
  • Marking of packets according to QoS policies.
  • Diagnostics of user packets (for example, application detection based on signatures).
  • Provision of traffic usage reports.
  • The UPF also serves as a anchor point for supporting mobility both within one and across different radio access technologies.

UDM. (English: Unified Data Management) — provides:

  • Management of user profile data, including storage and modification of the list of services available to users and their corresponding parameters.
  • Management SUPI.
  • Generation of 3GPP authentication credentials. AKA..
  • Access authorization based on profile data (for example, roaming restrictions).
  • Management of user registration, i.e., storing the servicing AMF.
  • Support for service and session continuity, i.e., storage of the SMF assigned for the current communication session.
  • Management of SMS delivery.
  • Multiple different UDMs can serve a single user across various transactions.

UDR. (English: Unified Data Repository) — provides storage for various user data and is essentially a database for all subscribers in the network.

UDSF. (eng. Unstructured Data Storage Function) - provides the storage of current contexts of registered users by AMF modules. This information can generally be represented as data of an undefined structure. User contexts can be used to ensure seamless and uninterrupted subscriber sessions both during the planned removal of one of the AMFs from service and in the event of an emergency situation. In both cases, the backup AMF will 'take over' the service using the contexts saved in the USDF.

Combining UDR and UDSF on a single physical platform is a typical implementation of these network functions.

PCF (eng. Policy Control Function) - formulates and assigns users various service policies, including QoS parameters and billing rules. For example, virtual channels with different characteristics can be created dynamically for the transmission of a specific type of traffic. In this case, the requirements of the service requested by the subscriber, the level of network congestion, the amount of traffic consumed, etc. can be taken into consideration.

NEF (eng. Network Exposure Function) - ensures:

  • The organization of secure interaction between external platforms and applications with the core network.
  • Management of QoS parameters and billing rules for specific users.

SEAF (eng. Security Anchor Function) - works alongside AUSF to authenticate users during their network registration with any access technology.

AUSF (eng. Authentication Server Function) - acts as the authentication server that receives and processes requests from SEAF and redirects them to ARPF.

ARPF (eng. Authentication Credential Repository and Processing Function) - provides the storage of personal secret keys (KI) and cryptographic algorithm parameters, as well as the generation of authentication vectors according to the 5G-AKA algorithms or EAP-AKA. It is located in a data center of the home communications operator, protected from external physical impacts, and is typically integrated with UDM.

SCMF (eng. Security Context Management Function) - manages security context) — manages the lifecycle of the 5G security context.

SPCF (Security Policy Control Function) — facilitates the agreement and implementation of security policies for specific users. This takes into account network capabilities, user equipment capabilities, and the requirements of particular services (for instance, the protection levels provided by critical communications services and wireless broadband access services may differ). The application of security policies includes: selecting AUSF, selecting authentication algorithms, choosing data encryption and integrity control algorithms, determining the length and lifecycle of keys.

SIDF (Subscription Identifier De-concealing Function) — allows the extraction of the subscriber's permanent subscription identifier (SUPI) from the concealed identifier ( SUCI), obtained during the authentication procedure request 'Auth Info Req'.

Key security requirements for 5G communication networks

Learn moreUser authentication: The serving 5G network must authenticate the user's SUPI during the 5G AKA process between the user and the network.

Serving network authentication: The user must authenticate the identity of the serving 5G network, with authentication ensured through the successful use of keys obtained in the 5G AKA procedure.

User authorization: The serving network must authorize the user based on the user profile obtained from the home network operator.

Serving network authorization by the home network operator: The user must receive confirmation that they are connected to a serving network authorized by the home network operator to provide services. Authorization is implicit in that it is ensured through the successful completion of the 5G AKA procedure.

Access network authorization by the home network operatorThe user must be provided with confirmation that they are connected to an access network authorized by the home operator to provide services. Authorization is implicit in the sense that it is ensured by the successful establishment of access network security. This type of authorization should apply to any type of access network.

Unauthenticated emergency servicesTo meet regulatory requirements in some regions, 5G networks must provide the option for unauthenticated access for emergency services.

Core network and radio access networkThe 5G core network and radio access network must support the use of encryption and integrity protection algorithms with a key length of 128 bits to ensure security. AS and NASNetwork interfaces must support 256-bit encryption keys.

Key security requirements for user equipment

Learn more

  • User equipment must support encryption, integrity protection, and protection against replay attacks on user data transmitted between it and the radio access network.
  • User equipment must activate data encryption and integrity protection mechanisms as directed by the radio access network.
  • User equipment must support encryption, integrity protection, and protection against replay attacks on RRC and NAS signaling traffic.
  • User equipment must support the following cryptographic algorithms: NEA0, NIA0, 128-NEA1, 128-NIA1, 128-NEA2, 128-NIA2.
  • User equipment may support the following cryptographic algorithms: 128-NEA3, 128-NIA3.
  • User equipment must support the following cryptographic algorithms: 128-EEA1, 128-EEA2, 128-EIA1, 128-EIA2 if it supports connection to the E-UTRA radio access network.
  • The protection of the privacy of user data transmitted between user equipment and the radio access network is optional but must be ensured in all cases where permitted by regulations.
  • The protection of RRC and NAS signaling traffic privacy is optional.
  • The permanent user key must be protected and stored in well-secured components of user equipment.
  • The permanent subscriber identifier must not be transmitted in clear text over the radio access network except for information necessary for proper routing (for example, MCC and MNC).
  • The operator's home network public key, the identifier of this key, the protection scheme identifier, and the routing identifier must be stored in USIM.

Each encryption algorithm is associated with a binary number:

  • ‘0000’: NEA0 — Null ciphering algorithm
  • ‘0001’: 128-NEA1 — 128-bit SNOW 3G based algorithm
  • ‘0010’ 128-NEA2 — 128-bit AES based algorithm
  • ‘0011’ 128-NEA3 — 128-bit ZUC based algorithm.

Data encryption using 128-NEA1 and 128-NEA2Introduction to 5G Security Architecture: NFV, Keys, and 2 Authentication

P.S. The scheme is borrowed from TS 133.501

Generation of message authentication codes by algorithms 128-NIA1 and 128-NIA2 to ensure integrityIntroduction to 5G Security Architecture: NFV, Keys, and 2 Authentication

P.S. The scheme is borrowed from TS 133.501

Main security requirements for 5G network functions

Learn more

  • AMF must support primary authentication using SUCI.
  • SEAF must support primary authentication using SUCI.
  • UDM and ARPF must store the permanent user key and protect it from theft.
  • AUSF must provide SUPI to the local serving network only upon successful primary authentication using SUCI.
  • NEF must not forward hidden core network information outside the operator's security domain.

Main security procedures

Trust domains

In 5th generation networks, trust in network elements decreases as elements move away from the core of the network. This concept influences decisions implemented in the 5G security architecture. Thus, we can speak of the trust model of 5G networks, which defines the behavior of network security mechanisms.

From the user's side, the trust domain is formed by UICC and USIM.

On the network side, the trust domain has a more complex structure.

Introduction to 5G Security Architecture: NFV, Keys, and 2 Authentication The radio access network is divided into two components — DU (from English: Distributed Units) and CU (from English: Central Units). Together they form gNB — radio interface of the 5G network base station. DUs do not have direct access to user data, as they may be deployed in segments of unprotected infrastructure. CUs must be deployed in secure segments of the network, as they are responsible for terminating traffic for the AS security mechanisms. In the core of the network is located AMF, terminating traffic for the NAS security mechanisms. The current specification from 3GPP for 5G Phase 1 describes the integration AMF with the security function SEAF, containing the root key (also known as the 'anchor key') of the visited (serving) network. AUSF is responsible for storing the key obtained after successful authentication. It is necessary for reuse in cases where a user is simultaneously connected to multiple radio access networks. ARPF stores user credentials and is analogous to the USIM for subscribers. UDR. and UDM. store user information that is used to define the logic of generating credentials, user identifiers, ensuring session continuity, etc.

Hierarchy of keys and their distribution schemes

In 5th generation networks, unlike in 4G-LTE networks, the authentication procedure has two components: primary and secondary authentication. Primary authentication is mandatory for all user devices connecting to the network. Secondary authentication can be performed upon request from external networks if the subscriber connects to such networks.

After the successful completion of the primary authentication and the generation of the shared key K between the user and the network, KSEAF — a special anchor (root) key of the serving network is extracted from the key K. Subsequently, from this key, keys are generated that ensure the confidentiality and integrity of the RRC and NAS signaling traffic data.

Diagram with explanationsIntroduction to 5G Security Architecture: NFV, Keys, and 2 Authentication
Notations:
CK (Cipher Key)
IK (Integrity Key) — a key used in data integrity protection mechanisms.
CK’ (Cipher Key) — another cryptographic key created from CK for the EAP-AKA mechanism.
IK’ (Integrity Key) — another key used in data integrity protection mechanisms for EAP-AKA.
KAUSF — created by the ARPF function and user equipment from CK and IK during 5G AKA and EAP-AKA.
KSEAF — anchor key obtained by the AUSF function from the key KAMFAUSF.
KAMF — key obtained by the SEAF function from the key KSEAF.
KNASint, KNASenc — keys obtained by the AMF function from the key KAMF for protecting NAS signaling traffic.
KRRCint, KRRCenc — keys obtained by the AMF function from the key KAMF for protecting RRC signaling traffic.
KUPint, KUPenc — keys obtained by the AMF function from the key KAMF for protecting AS signaling traffic.
NH — intermediate key obtained by the AMF function from the key KAMF for ensuring data security during handovers.
KgNB — key obtained by the AMF function from the key KAMF for ensuring the security of mobility mechanisms.

SUCI generation schemes from SUPI and vice versa

SUPI and SUCI retrieval schemes

Generation of SUCI from SUPI and SUPI from SUCI:
Introduction to 5G Security Architecture: NFV, Keys, and 2 Authentication

Authentication

Primary authentication

In 5G networks, EAP-AKA and 5G AKA are standard primary authentication mechanisms. We will break down the primary authentication mechanism into two phases: the first is responsible for initiating authentication and selecting the authentication method, the second is for mutual authentication between the user and the network.

Introduction to 5G Security Architecture: NFV, Keys, and 2 Authentication

Initiation

The user sends a registration request to SEAF, which contains the concealed user subscription identifier SUCI.

SEAF sends an authentication request message (Nausf_UEAuthentication_Authenticate Request) to AUSF, containing the SNN (Serving Network Name) and SUPI or SUCI.

AUSF checks if the requesting SEAF is allowed to use this SNN. If the serving network is not authorized to use this SNN, AUSF responds with an authorization error message ‘Serving network not authorized’ (Nausf_UEAuthentication_Authenticate Response).

The request for authentication credentials from AUSF to UDM, ARPF, or SIDF is made using SUPI or SUCI and SNN.

Based on SUPI or SUCI and user information, UDM/ARPF selects the authentication method to be used subsequently and issues user credentials.

Mutual authentication

When using any authentication method, the network functions UDM/ARPF must generate an authentication vector (AV).

EAP-AKA: UDM/ARPF first generates an authentication vector with a separating bit AMF = 1, after which it generates CK’ and IK’ from CK, IK and SNN and composes a new authentication vector AV (RAND, AUTN, XRES*, CK’, IK’), which is sent to AUSF instructing it to use it only for EAP-AKA.

5G AKA: UDM/ARPF receives the key KAUSF from CK, IK and SNN, after which it generates the 5G HE AV (5G Home Environment Authentication Vector). The authentication vector 5G HE AV (RAND, AUTN, XRES, KAUSF) is sent to AUSF instructing it to use it only for 5G AKA.

After this, AUSF obtains the anchor key KSEAF from the key KAUSF and sends a 'Challenge' request to SEAF in the message 'Nausf_UEAuthentication_Authenticate Response', which also contains RAND, AUTN, and RES*. Then, RAND and AUTN are transmitted to the user equipment via a secure signaling message from NAS. The user's USIM calculates RES* from the received RAND and AUTN and sends it to SEAF. SEAF relays this value to AUSF for verification.

AUSF compares the stored XRES* with the received RES* from the user. If they match, AUSF and UDM in the operator's home network are notified of successful authentication, and the user and SEAF independently generate a key KAMF from KSEAF and SUPI for further communication.

Secondary Authentication

The 5G standard supports optional secondary authentication based on EAP-AKA between user equipment and the external data network. In this case, the SMF acts as the EAP authenticator and relies on the operation of the AAA-server of the external network, which authenticates and authorizes the user.

Introduction to 5G Security Architecture: NFV, Keys, and 2 Authentication

  • Mandatory primary authentication of the user occurs in the home network and generates a shared NAS security context with AMF.
  • The user sends a session establishment request to AMF.
  • AMF sends a session establishment request to SMF, indicating the user's SUPI.
  • SMF verifies the user's credentials in UDM using the provided SUPI.
  • SMF sends a response to the AMF request.
  • SMF initiates the EAP authentication procedure to obtain permission for session establishment from the AAA server of the external network. For this, SMF and the user exchange messages to initiate the procedure.
  • The user and the AAA server of the external network then exchange messages to authenticate and authorize the user. The user sends messages to SMF, which in turn exchanges messages with the external network through UPF.

Conclusion

Despite the fact that the security architecture of 5G is based on the reuse of existing technologies, it faces entirely new challenges. A massive number of IoT devices, extended network boundaries, and elements of decentralized architecture are just some of the key principles of the 5G standard, giving cybercriminals plenty of room for creativity.

The main standard for 5G security architecture — TS 23.501 Version 15.6.0 — contains key points about the operation of security mechanisms and procedures. In particular, it describes the role of each VNF in ensuring the protection of user data and network nodes, in generating cryptographic keys, and in carrying out the authentication procedure. However, even this standard does not address the pressing security questions that operators face, which arise more frequently as next-generation networks develop and come into operation.

In this regard, one hopes that the challenges of operating and securing 5th generation networks will not impact ordinary users, who are promised transmission speed and response times that resemble those of a friend's son, eager to try all the declared features of next-generation networks.

Useful links

3GPP Specification series
5G security architecture
5G system architecture
5G Wiki
5G architecture notes
5G security overview

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster