【诺基亚贝尔】2024年6G网络安全白皮书构建更安全的6G无线接入层_11页_368kb
报告摘要
Summary of Nokia White Paper: Reinforced Access Stratum Security for 6G
Core Content
This white paper by Nokia explores the importance of enhancing security at the Medium Access Control (MAC) layer in 6G networks. It emphasizes the need for a "secure by design" approach, building on the robust security mechanisms established in 5G. The paper highlights the current lack of cryptographic protection at the MAC layer and proposes solutions to reinforce it, aligning with the broader security goals of 6G.
Main Viewpoints
-
Mobile Networks and Security: Mobile networks are crucial for global economic growth and must be trustworthy, secure, and resilient. Security is achieved through research, standardization, and the adoption of advanced technologies.
-
5G Security Foundations: 5G introduced separate security associations for the Access Stratum (AS) and Non-Access Stratum (NAS), ensuring secure communication between the user equipment (UE) and the base station (gNB). The security of the control plane (CP) and user plane (UP) traffic is managed at the PDCP layer, avoiding real-time constraints on lower layers.
-
MAC Layer Vulnerabilities: While the MAC layer was considered relatively secure in 4G and 5G, recent research has identified vulnerabilities, such as the ability to exploit MAC Control Elements (CEs) to infer UE locations or monitor user behavior. These attacks, though not yet widely used, highlight the need for stronger MAC layer protection.
-
Quantum Computing Threats: The paper acknowledges that quantum computing could pose new security risks, necessitating the adoption of quantum-safe algorithms and protocols in 6G. This includes Post Quantum Cryptography (PQC) and other advanced security mechanisms.
-
Proposed MAC Layer Enhancements: Nokia suggests that 6G should include cryptographic protection for MAC CEs, potentially moving CP security from the PDCP layer down to the MAC layer. This would allow for a more granular and flexible security design, with the ability to define protected zones within MAC PDUs.
-
Protection Mechanisms: The proposed approach involves adding header fields to MAC PDUs to indicate the presence of a protected zone, along with a counter and a MAC-I field. These mechanisms can reuse existing 5G cryptographic algorithms and allow for future evolution, including 256-bit algorithms and authenticated encryption with associated data (AEAD).
-
Real-Time Considerations: The MAC layer is subject to real-time constraints, so protection should be limited to sensitive control communications. This minimizes computational overhead and ensures that the MAC layer can still operate efficiently.
Key Information
-
Current 5G Security:
- Encryption and integrity protection for CP and UP traffic are handled at the PDCP layer.
- The MAC layer is not cryptographically protected due to perceived low risk.
- The PDCP uses three algorithm pairs (SNOW3G, AES, ZUC) for encryption and integrity protection.
-
MAC Layer Security Gaps:
- MAC CEs can be exploited to infer UE location or monitor user behavior.
- Attacks on MAC CEs are becoming more impactful, and new threats like quantum computing are emerging.
-
6G Security Vision:
- 6G is expected to support critical services and will require stronger security mechanisms.
- The MAC layer should be reinforced to protect control procedures, including cell changes and carrier aggregation configurations.
- Security should be integrated into the design of 6G systems to ensure long-term resilience.
-
Technical Solutions:
- Introduce a "protected zone" within MAC PDUs.
- Use header fields to indicate protection, along with a counter and MAC-I.
- Leverage existing 5G security algorithms and allow for future enhancements.
-
Benefits:
- Enhanced security for control plane communications.
- Flexibility in defining which MAC CEs are protected.
- Compatibility with current and future cryptographic standards.
Conclusion
To meet the security demands of 6G, it is essential to reinforce the MAC layer's security. While current 5G networks may not be under serious threat from MAC layer vulnerabilities, the long-term security of 6G systems requires a more comprehensive approach. By extending cryptographic protection to the MAC layer, Nokia aims to ensure that 6G networks are secure, resilient, and capable of supporting critical applications. This approach aligns with the broader trend of adopting quantum-safe and privacy-enhancing technologies in next-generation networks.
试读结束,高清完整版pdf/doc/ppt,请点下载