{"id":54348,"date":"2019-12-24T00:00:00","date_gmt":"2019-12-23T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/vvedenie-v-arhitekturu-bezopasnosti-5g-nfv-klyuchi-i-2-autentifikatsii"},"modified":"2020-02-18T14:02:21","modified_gmt":"2020-02-18T11:02:21","slug":"vvedenie-v-arhitekturu-bezopasnosti-5g-nfv-klyuchi-i-2-autentifikatsii","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/vvedenie-v-arhitekturu-bezopasnosti-5g-nfv-klyuchi-i-2-autentifikatsii","title":{"rendered":"Introduction to 5G Security Architecture: NFV, Keys, and 2 Authentication","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/481446\/\"><img decoding=\"async\" alt=\"Introduction to 5G Security Architecture: NFV, Keys, and 2 Authentication\" src=\"\/wp-content\/uploads\/2019\/12\/731a83ddc08dfb8303c1dafb6ef0ef73.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<p>Clearly, embarking on the development of a new communication standard without considering security mechanisms is an extraordinarily questionable and futile endeavor.<\/p>\n<p><u>5G Security Architecture<\/u> \u2014 a set of security mechanisms and procedures implemented in <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/5G\">fifth-generation networks<\/a><\/noindex> covering all components of the network, from the core to the radio interfaces. <\/p>\n<p>Fifth-generation networks are essentially an evolution of <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/4G\">fourth-generation LTE networks.<\/a><\/noindex>The most significant changes have occurred in radio access technologies. A new <noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/Radio_access_technology\">RAT<\/a><\/noindex> (Radio Access Technology) \u2014 <noindex><a rel=\"nofollow\" href=\"https:\/\/www.riverpublishers.com\/journal\/journal_articles\/RP_Journal_2245-800X_614.pdf\">5G New Radio<\/a><\/noindex>. As for the core network, it has not undergone such substantial changes. Consequently, the security architecture of 5G networks was developed with an emphasis on reusing relevant technologies adopted in the 4G LTE standard.<\/p>\n<p>However, it is worth noting that rethinking well-known threats such as attacks on radio interfaces and the signaling layer (<noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/Signaling_(telecommunications)\">signalling<\/a><\/noindex> plane), DDoS attacks, Man-In-The-Middle attacks, etc., has prompted telecommunications operators to develop new standards and integrate entirely new security mechanisms into fifth-generation networks. <br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><br \/>\n<img decoding=\"async\" alt=\"Introduction to 5G Security Architecture: NFV, Keys, and 2 Authentication\" src=\"\/wp-content\/uploads\/2019\/12\/c934556e832cb4ba4e3053cf36f6170a.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<h1>Prerequisites<\/h1>\n<p>\nIn 2015, the International Telecommunication Union created the first of its kind global plan for the development of fifth-generation networks, making the development of security mechanisms and procedures in 5G networks particularly urgent. <\/p>\n<p>The new technology promised truly impressive data transfer speeds (over 1 Gbps), latency of less than 1 ms, and the ability to simultaneously connect up to 1 million devices within a radius of 1 km\u00b2. Such high demands placed on fifth-generation networks were reflected in their organizational principles.<\/p>\n<p>The key principle became decentralization, which involved placing numerous local databases and processing centers at the edge of the network. This helped minimize delays during <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/%D0%9C%D0%B5%D0%B6%D0%BC%D0%B0%D1%88%D0%B8%D0%BD%D0%BD%D0%BE%D0%B5_%D0%B2%D0%B7%D0%B0%D0%B8%D0%BC%D0%BE%D0%B4%D0%B5%D0%B9%D1%81%D1%82%D0%B2%D0%B8%D0%B5\">M2M<\/a><\/noindex>-communication and alleviate the core network's load due to the service of a vast number of IoT devices. Thus, the boundaries of next-generation networks were extended all the way to base stations, enabling the creation of local communication centers and the provision of cloud services without the risk of critical delays or service outages. Naturally, the altered approach to network organization and customer service attracted the attention of malicious actors, as it opened up new opportunities for attacks on both users' confidential information and the network components themselves, with the aim of causing service disruptions or seizing the operator's computing resources.<\/p>\n<h2>Main vulnerabilities of 5th generation networks<\/h2>\n<p><\/p>\n<h3>Increased attack surface<\/h3>\n<p>\n<b class=\"spoiler_title\">Learn more<\/b>When building telecommunication networks of the 3rd and 4th generations, operators typically limited themselves to working with one or several vendors who provided a complete package of hardware and software. This meant that everything could work 'out of the box'\u2014it was enough to install and configure the equipment purchased from the vendor; there was no need to replace or supplement proprietary software. Current trends contradict this 'classic' approach and are directed towards network virtualization, a multi-vendor approach to their construction, and software diversity. Technologies such as <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/%D0%9F%D1%80%D0%BE%D0%B3%D1%80%D0%B0%D0%BC%D0%BC%D0%BD%D0%BE-%D0%BE%D0%BF%D1%80%D0%B5%D0%B4%D0%B5%D0%BB%D1%8F%D0%B5%D0%BC%D0%B0%D1%8F_%D1%81%D0%B5%D1%82%D1%8C\">SDN<\/a><\/noindex> (Software Defined Network) and <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/%D0%92%D0%B8%D1%80%D1%82%D1%83%D0%B0%D0%BB%D0%B8%D0%B7%D0%B0%D1%86%D0%B8%D1%8F_%D1%81%D0%B5%D1%82%D0%B5%D0%B2%D1%8B%D1%85_%D1%84%D1%83%D0%BD%D0%BA%D1%86%D0%B8%D0%B9\">NFV<\/a><\/noindex> (Network Functions Virtualization) are becoming increasingly popular, leading to the inclusion of a vast amount of software built on open-source foundations in the processes and functionalities of network management. This gives malicious actors the opportunity to better study the operator's network and identify more vulnerabilities, which, in turn, increases the attack surface of next-generation networks compared to current ones.<\/p>\n<h3>A large number of IoT devices<\/h3>\n<p>\n<b class=\"spoiler_title\">Learn more<\/b>By 2021, around 57% of devices connected to 5G networks will be IoT devices. This means that most hosts will have limited cryptographic capabilities (see point 2) and, consequently, will be vulnerable to attacks. The enormous number of such devices will increase the risk of botnet proliferation and enable even more powerful and distributed DDoS attacks.<\/p>\n<h3>Limited cryptographic capabilities of IoT devices<\/h3>\n<p>\n<b class=\"spoiler_title\">Learn more<\/b>As already mentioned, fifth-generation networks actively engage peripheral devices that help offload some of the network core, thereby reducing latency. This is crucial for essential services such as unmanned vehicle management and emergency alert systems <noindex><a rel=\"nofollow\" href=\"https:\/\/www.etsi.org\/deliver\/etsi_ts\/123100_123199\/123167\/12.00.00_60\/ts_123167v120000p.pdf\">IMS<\/a><\/noindex> and others, for which ensuring minimal latency is critical, as human lives depend on it. Due to the connection of a large number of IoT devices, which, due to their small size and low energy consumption, have very limited computational resources, 5G networks become vulnerable to attacks aimed at taking control and subsequently manipulating such devices. For example, scenarios may involve infecting IoT devices that are part of a \"<noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/Building_automation\">smart home<\/a><\/noindex>\", with types of malware such as <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/%D0%92%D0%B8%D1%80%D1%83%D1%81-%D0%B2%D1%8B%D0%BC%D0%BE%D0%B3%D0%B0%D1%82%D0%B5%D0%BB%D1%8C\">Ransomware and extortion programs<\/a><\/noindex>. There are also possible scenarios for taking control of unmanned vehicles, which receive commands and navigation information through the \"cloud\". Formally, this vulnerability stems from the decentralization of next-generation networks, but the next point will highlight the issue of decentralization more explicitly.<\/p>\n<h3>Decentralization and expanding network boundaries<\/h3>\n<p>\n<b class=\"spoiler_title\">Learn more<\/b>Peripheral devices acting as local network cores route user traffic, handle requests, and perform local caching and storage of user data. Thus, the boundaries of 5th generation networks are expanding beyond the core to the edge, including local databases and 5G-NR (5G New Radio) radio interfaces. This creates a potential attack vector for the computational resources of local devices, which are inherently less secure than the central network core nodes, aimed at causing denial of service. This could result in internet outages for entire regions, malfunctions of IoT devices (such as in smart home systems), and unavailability of emergency alert services IMS.<\/p>\n<p><img decoding=\"async\" alt=\"Introduction to 5G Security Architecture: NFV, Keys, and 2 Authentication\" src=\"\/wp-content\/uploads\/2019\/12\/9b468364652e5077606e997d203ef398.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nHowever, ETSI and 3GPP have currently published more than 10 standards addressing various aspects of 5G network security. The overwhelming majority of the mechanisms described there aim to protect against vulnerabilities (including those mentioned above). One of the main standards is <noindex><a rel=\"nofollow\" href=\"https:\/\/www.etsi.org\/deliver\/etsi_ts\/133500_133599\/133501\/15.06.00_60\/ts_133501v150600p.pdf\">TS 23.501 Version 15.6.0<\/a><\/noindex>, which describes the security architecture of 5th generation networks.<\/p>\n<h1>5G Architecture<\/h1>\n<p>\n<img decoding=\"async\" alt=\"Introduction to 5G Security Architecture: NFV, Keys, and 2 Authentication\" src=\"\/wp-content\/uploads\/2019\/12\/3d1b8c350acf85f5fa77e0f3414771cb.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\nFirst, let\u2019s turn to the key principles of 5G network architecture, which will help fully reveal the meaning and responsibilities of each software module and security function within 5G.<\/p>\n<ul>\n<li>Separation of network nodes into elements that ensure the operation of protocols for the <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/cbs\/blog\/301000\/\">user plane<\/a><\/noindex> and elements that ensure the operation of protocols for the <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/cbs\/blog\/301000\/\">control plane<\/a><\/noindex> , enhancing flexibility regarding the scaling and deployment of the network, i.e., allowing for centralized or decentralized placement of individual network node components.<\/li>\n<li>Support for <noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/5G_network_slicing\">network slicing<\/a><\/noindex>, based on services provided to specific groups of end-users.<\/li>\n<li>Implementation of network elements as <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/%D0%92%D0%B8%D1%80%D1%82%D1%83%D0%B0%D0%BB%D0%B8%D0%B7%D0%B0%D1%86%D0%B8%D1%8F_%D1%81%D0%B5%D1%82%D0%B5%D0%B2%D1%8B%D1%85_%D1%84%D1%83%D0%BD%D0%BA%D1%86%D0%B8%D0%B9\">virtual network functions<\/a><\/noindex>.<\/li>\n<li>Supporting simultaneous access to centralized and local services, i.e., realizing the concepts of cloud <noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/Fog_computing\">fog computing<\/a><\/noindex>and edge computing. <noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/Edge_computing\">Convergent<\/a><\/noindex>architecture, uniting different types of access networks \u2014 3GPP 5G New Radio and<\/li>\n<li>Implementation <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/%D0%9A%D0%BE%D0%BD%D0%B2%D0%B5%D1%80%D0%B3%D0%B5%D0%BD%D1%86%D0%B8%D1%8F_(%D1%82%D0%B5%D0%BB%D0%B5%D0%BA%D0%BE%D0%BC%D0%BC%D1%83%D0%BD%D0%B8%D0%BA%D0%B0%D1%86%D0%B8%D0%B8)\">non-3GPP<\/a><\/noindex> (Wi-Fi, etc.) \u2014 with a single network core. <noindex><a rel=\"nofollow\" href=\"https:\/\/www.etsi.org\/deliver\/etsi_ts\/124500_124599\/124502\/15.00.00_60\/ts_124502v150000p.pdf\">non-3GPP<\/a><\/noindex> (Wi-Fi, etc.) \u2014 with a single network core.<\/li>\n<li>Support for unified authentication algorithms and procedures regardless of the type of access network.<\/li>\n<li>Support for stateless network functions, where the computed resource is separated from the resource storage.<\/li>\n<li>Support for roaming with traffic routing both through the home network and local breakout in the guest network.<\/li>\n<li>Interaction between network functions is represented in two ways: <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/%D0%A1%D0%B5%D1%80%D0%B2%D0%B8%D1%81-%D0%BE%D1%80%D0%B8%D0%B5%D0%BD%D1%82%D0%B8%D1%80%D0%BE%D0%B2%D0%B0%D0%BD%D0%BD%D0%B0%D1%8F_%D0%B0%D1%80%D1%85%D0%B8%D1%82%D0%B5%D0%BA%D1%82%D1%83%D1%80%D0%B0\">service-oriented<\/a><\/noindex> and <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/%D0%98%D0%BD%D1%82%D0%B5%D1%80%D1%84%D0%B5%D0%B9%D1%81\">interface-oriented<\/a><\/noindex>.<\/li>\n<\/ul>\n<p>\n<b>The security concept of fifth-generation networks includes<\/b>:<\/p>\n<ul>\n<li>User authentication from the network side.<\/li>\n<li>Network authentication from the user side.<\/li>\n<li>Cryptographic key agreement between the network and user equipment.<\/li>\n<li>Encryption and integrity control of signaling traffic.<\/li>\n<li>Encryption and integrity control of user traffic.<\/li>\n<li>Protection of the user identifier.<\/li>\n<li>Protection of interfaces between different network elements according to the security domain concept.<\/li>\n<li>Isolation of different layers of the mechanism <noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/5G_network_slicing\">network slicing<\/a><\/noindex> and defining distinct security levels for each layer.<\/li>\n<li>User authentication and traffic protection at the end service level (IMS, IoT, and others).<\/li>\n<\/ul>\n<p><\/p>\n<h2>Key software modules and 5G security network functions<\/h2>\n<p>\n<img decoding=\"async\" alt=\"Introduction to 5G Security Architecture: NFV, Keys, and 2 Authentication\" src=\"\/wp-content\/uploads\/2019\/12\/223109a13286d858d29263d076888b09.jpg\" style=\"display:block;margin: 0 auto;\" \/> <b>AMF<\/b> (Access &amp; Mobility Management Function) \u2014 provides:<\/p>\n<ul>\n<li>Organization of control plane interfaces.<\/li>\n<li>Organization of signaling traffic exchange <noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/Radio_Resource_Control\">RRC<\/a><\/noindex>, encryption and integrity protection of its data.<\/li>\n<li>Organization of signaling traffic exchange <noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/Non-access_stratum\">NAS<\/a><\/noindex>, encryption and integrity protection of its data.<\/li>\n<li>Management of user equipment registration in the network and control of possible registration states.<\/li>\n<li>Management of user equipment connection to the network and control of possible states.<\/li>\n<li>Management of user equipment availability in the network in CM-IDLE state.<\/li>\n<li>Management of user equipment mobility in the network in CM-CONNECTED state.<\/li>\n<li>Transmission of short messages between user equipment and SMF.<\/li>\n<li>Management of geolocation services.<\/li>\n<li>Allocation of stream identifier <noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/System_Architecture_Evolution\">EPS<\/a><\/noindex> for interaction with EPS.<\/li>\n<\/ul>\n<p>\n<b>SMF<\/b> (Session Management Function) \u2014 provides:<\/p>\n<ul>\n<li>Session management, i.e., creation, modification, and release of a session, including support for tunneling between the access network and the UPF.<\/li>\n<li>Distribution and management of IP addresses for end-user equipment.<\/li>\n<li>Selection of the UPF gateway to be used.<\/li>\n<li>Organization of interaction with the PCF.<\/li>\n<li>Policy application management. <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/QoS\">QoS.<\/a><\/noindex>.<\/li>\n<li>Dynamic configuration of end-user equipment using DHCPv4 and DHCPv6 protocols.<\/li>\n<li>Control over the collection of billing data and organization of interaction with the billing system.<\/li>\n<li>Seamless service provision (from English. <noindex><a rel=\"nofollow\" href=\"http:\/\/4g5gworld.com\/blog\/session-and-service-continuity-evolution-5g-networks\">SSC \u2014 Session and Service Continuity.<\/a><\/noindex>).<\/li>\n<li>Interaction with guest networks during roaming.<\/li>\n<\/ul>\n<p>\n<b>UPF.<\/b> (English: User Plane Function) \u2014 provides:<\/p>\n<ul>\n<li>Interaction with external data transmission networks, including the global Internet.<\/li>\n<li>Routing of user packets.<\/li>\n<li>Marking of packets according to QoS policies.<\/li>\n<li>Diagnostics of user packets (for example, application detection based on signatures).<\/li>\n<li>Provision of traffic usage reports.<\/li>\n<li>The UPF also serves as a anchor point for supporting mobility both within one and across different radio access technologies.<\/li>\n<\/ul>\n<p>\n<b>UDM.<\/b> (English: Unified Data Management) \u2014 provides:<\/p>\n<ul>\n<li>Management of user profile data, including storage and modification of the list of services available to users and their corresponding parameters.<\/li>\n<li>Management <noindex><a rel=\"nofollow\" href=\"http:\/\/www.techplayon.com\/5g-identifiers-supi-and-suci\/\">SUPI.<\/a><\/noindex><\/li>\n<li>Generation of 3GPP authentication credentials. <noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/Authentication_and_Key_Agreement\">AKA.<\/a><\/noindex>.<\/li>\n<li>Access authorization based on profile data (for example, roaming restrictions).<\/li>\n<li>Management of user registration, i.e., storing the servicing AMF.<\/li>\n<li>Support for service and session continuity, i.e., storage of the SMF assigned for the current communication session.<\/li>\n<li>Management of SMS delivery.<\/li>\n<li>Multiple different UDMs can serve a single user across various transactions.<\/li>\n<\/ul>\n<p>\n<b>UDR.<\/b> (English: Unified Data Repository) \u2014 provides storage for various user data and is essentially a database for all subscribers in the network. <\/p>\n<p><b>UDSF.<\/b> (eng. Unstructured Data Storage Function) - provides the storage of current contexts of registered users by AMF modules. This information can generally be represented as data of an undefined structure. User contexts can be used to ensure seamless and uninterrupted subscriber sessions both during the planned removal of one of the AMFs from service and in the event of an emergency situation. In both cases, the backup AMF will 'take over' the service using the contexts saved in the USDF.<\/p>\n<p>Combining UDR and UDSF on a single physical platform is a typical implementation of these network functions.<\/p>\n<p><b>PCF<\/b> (eng. Policy Control Function) - formulates and assigns users various service policies, including QoS parameters and billing rules. For example, virtual channels with different characteristics can be created dynamically for the transmission of a specific type of traffic. In this case, the requirements of the service requested by the subscriber, the level of network congestion, the amount of traffic consumed, etc. can be taken into consideration.<\/p>\n<p><b>NEF<\/b> (eng. Network Exposure Function) - ensures:<\/p>\n<ul>\n<li>The organization of secure interaction between external platforms and applications with the core network.<\/li>\n<li>Management of QoS parameters and billing rules for specific users.<\/li>\n<\/ul>\n<p>\n<b>SEAF<\/b> (eng. Security Anchor Function) - works alongside AUSF to authenticate users during their network registration with any access technology.<\/p>\n<p><b>AUSF<\/b> (eng. Authentication Server Function) - acts as the authentication server that receives and processes requests from SEAF and redirects them to ARPF.<\/p>\n<p><b>ARPF<\/b> (eng. Authentication Credential Repository and Processing Function) - provides the storage of personal secret keys (KI) and cryptographic algorithm parameters, as well as the generation of authentication vectors according to the 5G-AKA algorithms or <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/EAP\">EAP<\/a><\/noindex>-AKA. It is located in a data center of the home communications operator, protected from external physical impacts, and is typically integrated with UDM.<\/p>\n<p><b>SCMF<\/b> (eng. Security Context Management Function) - manages <noindex><a rel=\"nofollow\" href=\"https:\/\/it.wikireading.ru\/60129\">security context<\/a><\/noindex>) \u2014 manages the lifecycle of the 5G security context.<\/p>\n<p><b>SPCF<\/b> (Security Policy Control Function) \u2014 facilitates the agreement and implementation of security policies for specific users. This takes into account network capabilities, user equipment capabilities, and the requirements of particular services (for instance, the protection levels provided by critical communications services and wireless broadband access services may differ). The application of security policies includes: selecting AUSF, selecting authentication algorithms, choosing data encryption and integrity control algorithms, determining the length and lifecycle of keys.<\/p>\n<p><b>SIDF<\/b> (Subscription Identifier De-concealing Function) \u2014 allows the extraction of the subscriber's permanent subscription identifier (SUPI) from the concealed identifier ( <noindex><a rel=\"nofollow\" href=\"http:\/\/www.techplayon.com\/5g-identifiers-supi-and-suci\/\">SUCI<\/a><\/noindex>), obtained during the authentication procedure request 'Auth Info Req'.<\/p>\n<h2>Key security requirements for 5G communication networks<\/h2>\n<p>\n<b class=\"spoiler_title\">Learn more<\/b><b>User authentication<\/b>: The serving 5G network must authenticate the user's SUPI during the 5G AKA process between the user and the network.<\/p>\n<p><b>Serving network authentication<\/b>: The user must authenticate the identity of the serving 5G network, with authentication ensured through the successful use of keys obtained in the 5G AKA procedure.<\/p>\n<p><b>User authorization<\/b>: The serving network must authorize the user based on the user profile obtained from the home network operator.<\/p>\n<p><b>Serving network authorization by the home network operator<\/b>: The user must receive confirmation that they are connected to a serving network authorized by the home network operator to provide services. Authorization is implicit in that it is ensured through the successful completion of the 5G AKA procedure.<\/p>\n<p><b>Access network authorization by the home network operator<\/b>The user must be provided with confirmation that they are connected to an access network authorized by the home operator to provide services. Authorization is implicit in the sense that it is ensured by the successful establishment of access network security. This type of authorization should apply to any type of access network.<\/p>\n<p><b>Unauthenticated emergency services<\/b>To meet regulatory requirements in some regions, 5G networks must provide the option for unauthenticated access for emergency services.<\/p>\n<p><b>Core network and radio access network<\/b>The 5G core network and radio access network must support the use of encryption and integrity protection algorithms with a key length of 128 bits to ensure security. <noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/Access_stratum\">AS<\/a><\/noindex> and <noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/Non-access_stratum\">NAS<\/a><\/noindex>Network interfaces must support 256-bit encryption keys.<\/p>\n<h2>Key security requirements for user equipment<\/h2>\n<p>\n<b class=\"spoiler_title\">Learn more<\/b><\/p>\n<ul>\n<li>User equipment must support encryption, integrity protection, and protection against replay attacks on user data transmitted between it and the radio access network.<\/li>\n<li>User equipment must activate data encryption and integrity protection mechanisms as directed by the radio access network.<\/li>\n<li>User equipment must support encryption, integrity protection, and protection against replay attacks on RRC and NAS signaling traffic.<\/li>\n<li>User equipment must support the following cryptographic algorithms: NEA0, NIA0, 128-NEA1, 128-NIA1, 128-NEA2, 128-NIA2.<\/li>\n<li>User equipment may support the following cryptographic algorithms: 128-NEA3, 128-NIA3.<\/li>\n<li>User equipment must support the following cryptographic algorithms: 128-EEA1, 128-EEA2, 128-EIA1, 128-EIA2 if it supports connection to the E-UTRA radio access network.<\/li>\n<li>The protection of the privacy of user data transmitted between user equipment and the radio access network is optional but must be ensured in all cases where permitted by regulations.<\/li>\n<li>The protection of RRC and NAS signaling traffic privacy is optional.<\/li>\n<li>The permanent user key must be protected and stored in well-secured components of user equipment.<\/li>\n<li>The permanent subscriber identifier must not be transmitted in clear text over the radio access network except for information necessary for proper routing (for example, <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/Mobile_Country_Code\">MCC<\/a><\/noindex> and <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/MNC\">MNC<\/a><\/noindex>).<\/li>\n<li>The operator's home network public key, the identifier of this key, the protection scheme identifier, and the routing identifier must be stored in <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/USIM-%D0%BA%D0%B0%D1%80%D1%82%D0%B0\">USIM<\/a><\/noindex>.<\/li>\n<\/ul>\n<p>\nEach encryption algorithm is associated with a binary number:<\/p>\n<ul>\n<li>\u20180000\u2019: NEA0 \u2014 Null ciphering algorithm<\/li>\n<li>\u20180001\u2019: 128-NEA1 \u2014 128-bit <noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/SNOW\">SNOW<\/a><\/noindex> 3G based algorithm<\/li>\n<li>\u20180010\u2019 128-NEA2 \u2014 128-bit <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/Advanced_Encryption_Standard\">AES<\/a><\/noindex> based algorithm<\/li>\n<li>\u20180011\u2019 128-NEA3 \u2014 128-bit <noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/Zuc_stream_cipher\">ZUC<\/a><\/noindex> based algorithm.<\/li>\n<\/ul>\n<p>\n<b class=\"spoiler_title\">Data encryption using 128-NEA1 and 128-NEA2<\/b><img decoding=\"async\" alt=\"Introduction to 5G Security Architecture: NFV, Keys, and 2 Authentication\" src=\"\/wp-content\/uploads\/2019\/12\/101481062364f5cc777df59b9a589e5b.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nP.S. The scheme is borrowed from <noindex><a rel=\"nofollow\" href=\"https:\/\/www.etsi.org\/deliver\/etsi_ts\/133500_133599\/133501\/15.06.00_60\/ts_133501v150600p.pdf\">TS 133.501<\/a><\/noindex><\/p>\n<p><b class=\"spoiler_title\">Generation of message authentication codes by algorithms 128-NIA1 and 128-NIA2 to ensure integrity<\/b><img decoding=\"async\" alt=\"Introduction to 5G Security Architecture: NFV, Keys, and 2 Authentication\" src=\"\/wp-content\/uploads\/2019\/12\/35271aaab9173837fcb859e71a31cc87.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nP.S. The scheme is borrowed from <noindex><a rel=\"nofollow\" href=\"https:\/\/www.etsi.org\/deliver\/etsi_ts\/133500_133599\/133501\/15.06.00_60\/ts_133501v150600p.pdf\">TS 133.501<\/a><\/noindex><\/p>\n<p><\/p>\n<h2>Main security requirements for 5G network functions<\/h2>\n<p>\n<b class=\"spoiler_title\">Learn more<\/b><\/p>\n<ul>\n<li>AMF must support primary authentication using SUCI.<\/li>\n<li>SEAF must support primary authentication using SUCI.<\/li>\n<li>UDM and ARPF must store the permanent user key and protect it from theft.<\/li>\n<li>AUSF must provide SUPI to the local serving network only upon successful primary authentication using SUCI.<\/li>\n<li>NEF must not forward hidden core network information outside the operator's security domain.<\/li>\n<\/ul>\n<h1>Main security procedures<\/h1>\n<p><\/p>\n<h2>Trust domains<\/h2>\n<p>\nIn 5th generation networks, trust in network elements decreases as elements move away from the core of the network. This concept influences decisions implemented in the 5G security architecture. Thus, we can speak of the trust model of 5G networks, which defines the behavior of network security mechanisms.<\/p>\n<p>From the user's side, the trust domain is formed by UICC and USIM.<\/p>\n<p>On the network side, the trust domain has a more complex structure.<\/p>\n<p><img decoding=\"async\" alt=\"Introduction to 5G Security Architecture: NFV, Keys, and 2 Authentication\" src=\"\/wp-content\/uploads\/2019\/12\/de3f67c48e1f61afca7637417a2a735b.jpg\" style=\"display:block;margin: 0 auto;\" \/> The radio access network is divided into two components \u2014 <b>DU<\/b> (from English: Distributed Units) and <b>CU<\/b> (from English: Central Units). Together they form <b>gNB<\/b> \u2014 radio interface of the 5G network base station. DUs do not have direct access to user data, as they may be deployed in segments of unprotected infrastructure. CUs must be deployed in secure segments of the network, as they are responsible for terminating traffic for the AS security mechanisms. In the core of the network is located <b>AMF<\/b>, terminating traffic for the NAS security mechanisms. The current specification from 3GPP for 5G Phase 1 describes the integration <b>AMF<\/b> with the security function <b>SEAF<\/b>, containing the root key (also known as the 'anchor key') of the visited (serving) network. <b>AUSF<\/b> is responsible for storing the key obtained after successful authentication. It is necessary for reuse in cases where a user is simultaneously connected to multiple radio access networks. <b>ARPF<\/b> stores user credentials and is analogous to the USIM for subscribers. <b>UDR.<\/b> and <b>UDM.<\/b> store user information that is used to define the logic of generating credentials, user identifiers, ensuring session continuity, etc.<\/p>\n<h2>Hierarchy of keys and their distribution schemes<\/h2>\n<p>\nIn 5th generation networks, unlike in 4G-LTE networks, the authentication procedure has two components: primary and secondary authentication. Primary authentication is mandatory for all user devices connecting to the network. Secondary authentication can be performed upon request from external networks if the subscriber connects to such networks.<\/p>\n<p>After the successful completion of the primary authentication and the generation of the shared key K between the user and the network, KSEAF \u2014 a special anchor (root) key of the serving network is extracted from the key K. Subsequently, from this key, keys are generated that ensure the confidentiality and integrity of the RRC and NAS signaling traffic data.<\/p>\n<p><b class=\"spoiler_title\">Diagram with explanations<\/b><img decoding=\"async\" alt=\"Introduction to 5G Security Architecture: NFV, Keys, and 2 Authentication\" src=\"\/wp-content\/uploads\/2019\/12\/c10946db4ddebcb53f6fcfc585b7be23.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<b>Notations<\/b>:<br \/>\n<b>CK<\/b> (Cipher Key)<br \/>\n<b>IK<\/b> (Integrity Key) \u2014 a key used in data integrity protection mechanisms.<br \/>\n<b>CK\u2019<\/b> (Cipher Key) \u2014 another cryptographic key created from CK for the EAP-AKA mechanism.<br \/>\n<b>IK\u2019<\/b> (Integrity Key) \u2014 another key used in data integrity protection mechanisms for EAP-AKA.<br \/>\n<b>KAUSF<\/b> \u2014 created by the ARPF function and user equipment from <b>CK<\/b> and <b>IK<\/b> during 5G AKA and EAP-AKA.<br \/>\n<b>KSEAF<\/b> \u2014 anchor key obtained by the AUSF function from the key <b>KAMFAUSF<\/b>.<br \/>\n<b>KAMF<\/b> \u2014 key obtained by the SEAF function from the key <b>KSEAF<\/b>.<br \/>\n<b>KNASint<\/b>, <b>KNASenc<\/b> \u2014 keys obtained by the AMF function from the key <b>KAMF<\/b> for protecting NAS signaling traffic.<br \/>\n<b>KRRCint<\/b>, <b>KRRCenc<\/b> \u2014 keys obtained by the AMF function from the key <b>KAMF<\/b> for protecting RRC signaling traffic.<br \/>\n<b>KUPint<\/b>, <b>KUPenc<\/b> \u2014 keys obtained by the AMF function from the key <b>KAMF<\/b> for protecting AS signaling traffic.<br \/>\n<b>NH<\/b> \u2014 intermediate key obtained by the AMF function from the key <b>KAMF<\/b> for ensuring data security during handovers.<br \/>\n<b>KgNB<\/b> \u2014 key obtained by the AMF function from the key <b>KAMF<\/b> for ensuring the security of mobility mechanisms.<\/p>\n<p><b class=\"spoiler_title\">SUCI generation schemes from SUPI and vice versa<\/b><\/p>\n<h2>SUPI and SUCI retrieval schemes<\/h2>\n<p>\nGeneration of SUCI from SUPI and SUPI from SUCI:<br \/>\n<img decoding=\"async\" alt=\"Introduction to 5G Security Architecture: NFV, Keys, and 2 Authentication\" src=\"\/wp-content\/uploads\/2019\/12\/ba2bdfbe1bded3f34edb7853a3758fbd.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<h2>Authentication<\/h2>\n<p><\/p>\n<h3>Primary authentication<\/h3>\n<p>\nIn 5G networks, EAP-AKA and 5G AKA are standard primary authentication mechanisms. We will break down the primary authentication mechanism into two phases: the first is responsible for initiating authentication and selecting the authentication method, the second is for mutual authentication between the user and the network.<\/p>\n<p><img decoding=\"async\" alt=\"Introduction to 5G Security Architecture: NFV, Keys, and 2 Authentication\" src=\"\/wp-content\/uploads\/2019\/12\/87d17467440f027da9c5f8f521f2f800.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<h4>Initiation<\/h4>\n<p>\nThe user sends a registration request to SEAF, which contains the concealed user subscription identifier SUCI.<\/p>\n<p>SEAF sends an authentication request message (Nausf_UEAuthentication_Authenticate Request) to AUSF, containing the SNN (Serving Network Name) and SUPI or SUCI.<\/p>\n<p>AUSF checks if the requesting SEAF is allowed to use this SNN. If the serving network is not authorized to use this SNN, AUSF responds with an authorization error message \u2018Serving network not authorized\u2019 (Nausf_UEAuthentication_Authenticate Response).<\/p>\n<p>The request for authentication credentials from AUSF to UDM, ARPF, or SIDF is made using SUPI or SUCI and SNN.<\/p>\n<p>Based on SUPI or SUCI and user information, UDM\/ARPF selects the authentication method to be used subsequently and issues user credentials.<\/p>\n<h4>Mutual authentication<\/h4>\n<p>\nWhen using any authentication method, the network functions UDM\/ARPF must generate an authentication vector (AV).<\/p>\n<p>EAP-AKA: UDM\/ARPF first generates an authentication vector with a separating bit AMF = 1, after which it generates <b>CK\u2019<\/b> and <b>IK\u2019<\/b> from <b>CK<\/b>, <b>IK<\/b> and SNN and composes a new authentication vector AV (RAND, AUTN, XRES*, <b>CK\u2019<\/b>, <b>IK\u2019<\/b>), which is sent to AUSF instructing it to use it only for EAP-AKA.<\/p>\n<p>5G AKA: UDM\/ARPF receives the key <b>KAUSF<\/b> from <b>CK<\/b>, <b>IK<\/b> and SNN, after which it generates the 5G HE AV (5G Home Environment Authentication Vector). The authentication vector 5G HE AV (RAND, AUTN, XRES, <b>KAUSF<\/b>) is sent to AUSF instructing it to use it only for 5G AKA.<\/p>\n<p>After this, AUSF obtains the anchor key <b>KSEAF<\/b> from the key <b>KAUSF<\/b> and sends a 'Challenge' request to SEAF in the message 'Nausf_UEAuthentication_Authenticate Response', which also contains RAND, AUTN, and RES*. Then, RAND and AUTN are transmitted to the user equipment via a secure signaling message from NAS. The user's USIM calculates RES* from the received RAND and AUTN and sends it to SEAF. SEAF relays this value to AUSF for verification.<\/p>\n<p>AUSF compares the stored XRES* with the received RES* from the user. If they match, AUSF and UDM in the operator's home network are notified of successful authentication, and the user and SEAF independently generate a key <b>KAMF<\/b> from <b>KSEAF<\/b> and SUPI for further communication.<\/p>\n<h3>Secondary Authentication<\/h3>\n<p>\nThe 5G standard supports optional secondary authentication based on EAP-AKA between user equipment and the external data network. In this case, the SMF acts as the EAP authenticator and relies on the operation of <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/AAA_(%D0%B8%D0%BD%D1%84%D0%BE%D1%80%D0%BC%D0%B0%D1%86%D0%B8%D0%BE%D0%BD%D0%BD%D0%B0%D1%8F_%D0%B1%D0%B5%D0%B7%D0%BE%D0%BF%D0%B0%D1%81%D0%BD%D0%BE%D1%81%D1%82%D1%8C)\">the AAA<\/a><\/noindex>-server of the external network, which authenticates and authorizes the user.<\/p>\n<p><img decoding=\"async\" alt=\"Introduction to 5G Security Architecture: NFV, Keys, and 2 Authentication\" src=\"\/wp-content\/uploads\/2019\/12\/a42963ec26acea1397a4c7a9e4c2dc9f.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<ul>\n<li>Mandatory primary authentication of the user occurs in the home network and generates a shared NAS security context with AMF.<\/li>\n<li>The user sends a session establishment request to AMF.<\/li>\n<li>AMF sends a session establishment request to SMF, indicating the user's SUPI.<\/li>\n<li>SMF verifies the user's credentials in UDM using the provided SUPI.<\/li>\n<li>SMF sends a response to the AMF request.<\/li>\n<li>SMF initiates the EAP authentication procedure to obtain permission for session establishment from the AAA server of the external network. For this, SMF and the user exchange messages to initiate the procedure.<\/li>\n<li>The user and the AAA server of the external network then exchange messages to authenticate and authorize the user. The user sends messages to SMF, which in turn exchanges messages with the external network through UPF.<\/li>\n<\/ul>\n<p><\/p>\n<h1>Conclusion<\/h1>\n<p>\nDespite the fact that the security architecture of 5G is based on the reuse of existing technologies, it faces entirely new challenges. A massive number of IoT devices, extended network boundaries, and elements of decentralized architecture are just some of the key principles of the 5G standard, giving cybercriminals plenty of room for creativity.<\/p>\n<p>The main standard for 5G security architecture \u2014 <noindex><a rel=\"nofollow\" href=\"https:\/\/www.etsi.org\/deliver\/etsi_ts\/133500_133599\/133501\/15.06.00_60\/ts_133501v150600p.pdf\">TS 23.501 Version 15.6.0<\/a><\/noindex> \u2014 contains key points about the operation of security mechanisms and procedures. In particular, it describes the role of each VNF in ensuring the protection of user data and network nodes, in generating cryptographic keys, and in carrying out the authentication procedure. However, even this standard does not address the pressing security questions that operators face, which arise more frequently as next-generation networks develop and come into operation.<\/p>\n<p>In this regard, one hopes that the challenges of operating and securing 5th generation networks will not impact ordinary users, who are promised transmission speed and response times that resemble those of a friend's son, eager to try all the declared features of next-generation networks.<\/p>\n<h1>Useful links<\/h1>\n<p>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/www.3gpp.org\/DynaReport\/33-series.htm\">3GPP Specification series<\/a><\/noindex><br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/www.etsi.org\/deliver\/etsi_ts\/133500_133599\/133501\/15.06.00_60\/ts_133501v150600p.pdf\">5G security architecture<\/a><\/noindex><br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/www.etsi.org\/deliver\/etsi_ts\/123500_123599\/123501\/15.02.00_60\/ts_123501v150200p.pdf\">5G system architecture<\/a><\/noindex><br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/5G\">5G Wiki<\/a><\/noindex><br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/itechinfo.ru\/content\/%D0%B0%D1%80%D1%85%D0%B8%D1%82%D0%B5%D0%BA%D1%82%D1%83%D1%80%D0%B0-%D1%81%D0%B5%D1%82%D0%B8-5g\">5G architecture notes<\/a><\/noindex><br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/www.riverpublishers.com\/journal\/journal_articles\/RP_Journal_2245-800X_619.pdf\">5G security overview<\/a><\/noindex><br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/481446\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u0447\u0435\u0432\u0438\u0434\u043d\u043e, \u0431\u0440\u0430\u0442\u044c\u0441\u044f \u0437\u0430 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0443 \u043d\u043e\u0432\u043e\u0433\u043e \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u0430 \u0441\u0432\u044f\u0437\u0438, \u043d\u0435 \u0434\u0443\u043c\u0430\u044f \u043e \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c\u0430\u0445 \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0435\u043d\u0438\u044f \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438, \u2014 \u0434\u0435\u043b\u043e \u043d\u0435\u043e\u0431\u044b\u0447\u0430\u0439\u043d\u043e \u0441\u043e\u043c\u043d\u0438\u0442\u0435\u043b\u044c\u043d\u043e\u0435 \u0438 \u0431\u0435\u0441\u043f\u043e\u043b\u0435\u0437\u043d\u043e\u0435. \u0410\u0440\u0445\u0438\u0442\u0435\u043a\u0442\u0443\u0440\u0430 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 5G \u2014 \u0441\u043e\u0432\u043e\u043a\u0443\u043f\u043d\u043e\u0441\u0442\u044c \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c\u043e\u0432 \u0438 \u043f\u0440\u043e\u0446\u0435\u0434\u0443\u0440 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438, \u0440\u0435\u0430\u043b\u0438\u0437\u043e\u0432\u0430\u043d\u043d\u044b\u0445 \u0432 \u0441\u0435\u0442\u044f\u0445 5-\u0433\u043e \u043f\u043e\u043a\u043e\u043b\u0435\u043d\u0438\u044f \u0438 \u043e\u0445\u0432\u0430\u0442\u044b\u0432\u0430\u044e\u0449\u0438\u0445 \u0432\u0441\u0435 \u043a\u043e\u043c\u043f\u043e\u043d\u0435\u043d\u0442\u044b \u0441\u0435\u0442\u0438, \u043d\u0430\u0447\u0438\u043d\u0430\u044f \u043e\u0442 \u044f\u0434\u0440\u0430 \u0438 \u0437\u0430\u043a\u0430\u043d\u0447\u0438\u0432\u0430\u044f \u0440\u0430\u0434\u0438\u043e\u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0430\u043c\u0438. \u0421\u0435\u0442\u0438 5-\u043e\u0433\u043e \u043f\u043e\u043a\u043e\u043b\u0435\u043d\u0438\u044f \u044f\u0432\u043b\u044f\u044e\u0442\u0441\u044f, \u043f\u043e \u0441\u0443\u0442\u0438 \u0441\u0432\u043e\u0435\u0439, \u044d\u0432\u043e\u043b\u044e\u0446\u0438\u0435\u0439 \u0441\u0435\u0442\u0435\u0439 4-\u043e\u0433\u043e \u043f\u043e\u043a\u043e\u043b\u0435\u043d\u0438\u044f [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-54348","post","type-post","status-publish","format-standard","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/vvedenie-v-arhitekturu-bezopasnosti-5g-nfv-klyuchi-i-2-autentifikatsii\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412\u0432\u0435\u0434\u0435\u043d\u0438\u0435 \u0432 \u0430\u0440\u0445\u0438\u0442\u0435\u043a\u0442\u0443\u0440\u0443 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 5G: NFV, \u043a\u043b\u044e\u0447\u0438 \u0438 2 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 | ProHoster\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/vvedenie-v-arhitekturu-bezopasnosti-5g-nfv-klyuchi-i-2-autentifikatsii\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-12-23T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T11:02:21+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Introduction to 5G security architecture: NFV, keys, and 2 authentication methods | ProHoster","description":"","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/vvedenie-v-arhitekturu-bezopasnosti-5g-nfv-klyuchi-i-2-autentifikatsii","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412\u0432\u0435\u0434\u0435\u043d\u0438\u0435 \u0432 \u0430\u0440\u0445\u0438\u0442\u0435\u043a\u0442\u0443\u0440\u0443 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 5G: NFV, \u043a\u043b\u044e\u0447\u0438 \u0438 2 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 | ProHoster","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/vvedenie-v-arhitekturu-bezopasnosti-5g-nfv-klyuchi-i-2-autentifikatsii","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-12-23T21:00:00+00:00","article:modified_time":"2020-02-18T11:02:21+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"54348","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 11:00:25","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 20:07:25","updated":"2026-01-24 11:00:25","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/54348","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=54348"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/54348\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=54348"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=54348"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=54348"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}