A new scalable authentication and access control mechanism for 5G-based IoT

被引:31
作者
Behrad, Shanay [1 ,2 ]
Bertin, Emmanuel [2 ]
Tuffin, Stephane [3 ]
Crespi, Noel [4 ]
机构
[1] Orange Labs, Authenticat & Access Control Mech 5G Syst, Caen, France
[2] Orange Labs, Transact & Commun Serv, Caen, France
[3] Orange Labs, Lannion, France
[4] Telecom SudParis, Evry, France
来源
FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE | 2020年 / 108卷
关键词
AAC; IoT; 5G; Signaling load; OAI; KEY AGREEMENT PROTOCOL; SECURITY; 5G; LTE; NETWORKS; ISSUES; AKA;
D O I
10.1016/j.future.2020.02.014
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The fifth generation of mobile networks, 5G, is expected to support a set of many requirements and use cases such as handling connectivity for a massive number of IoT (Internet of Things) devices. Authenticating IoT devices and controlling their access to the network plays a vital role in the security of these devices and of the whole cellular system. In current cellular networks, as well as in 3GPP specifications release 16 on 5G, the AAC (Authentication and Access Control) of IoT devices is done in the same manner as the AAC of MBB (Mobile Broadband) UE (User Equipment). Considering the expected growth of IoT devices, this will likely induce a very high load on the connectivity provider's CN (Core Network) and cause network failures. To manage the AAC of this massive number of devices, we propose an SSAAC (Slice Specific Authentication and Access Control) mechanism that makes use of the flexibility provided by virtualization technologies. This mechanism allows the authentication and access control of IoT devices to be delegated to the 3rd parties providing these devices, thereby decreasing the load of the connectivity provider's CN, while increasing the flexibility and modularity of the whole 5G network. We evaluate the feasibility of our proposal with the OAI (Open Air Interface) open-source platform. Next, we provide a security analysis of the proposal and highlight the security requirements to use with this proposal. We also evaluate the impact of this delegation approach on the network load considering the anticipated number of AAC signaling messages compared to the existing AAC mechanisms in cellular networks. According to these evaluations, our approach is feasible and it would provide cellular networks the opportunity to overcome the security shortcomings in their AAC mechanisms. It also considerably reduces the AAC signaling load on the connectivity provider's CN. (C) 2020 Elsevier B.V. All rights reserved.
引用
收藏
页码:46 / 61
页数:16
相关论文
共 72 条
[1]  
3GPP, 2019, TS 22.261 v15.6.0 Release 15. S.l.
[2]  
3GPP, 2019, document TS 33.401
[3]  
3GPP, 2018, 33102 3GPP TS
[4]  
3GPP, 2019, 24301 3GPP TS
[5]  
3GPP, 2019, TS 33.501, v16.0.0
[6]  
5G Ensure Project, 2016, DEL D2 3 RISK ASS MI
[7]  
5G Ensure Project, 2017, DEL D2 7 SEC ARCH FI
[8]  
5G Ensure Project, 2018, DEL D 2 5 TRUST MOD
[9]  
5G Ensure Project, 2016, DEL D 3 5 5G PPP EN
[10]  
5G Ensure Project, 2016, DEL D 2 1 US CAS