Presenters and Affiliations
Y. Chandramouli — Chennai Mathematical Institute, Chennai, India
Overview / Abstract
The transition from 4G to 5G introduces a fundamentally different network architecture built on Network Function Virtualization (NFV), Software-Defined Networking (SDN), and Service-Based Architecture (SBA). These changes bring new security challenges. This tutorial introduces the 5G security landscape, covering virtualization-related risks, network slicing, massive IoT connectivity, multi-vendor and Open RAN deployments, 5G-AKA, SUCI-based subscriber identity protection, and zero-trust approaches. It also considers practical trade-offs such as security enforcement and ultra-low-latency performance.
Target Audience
- Security researchers, telecommunications engineers, graduate students, and industry practitioners interested in mobile network security.
Prerequisites
- Working knowledge of basic cellular network concepts (RAN, core network, and UE/base-station interaction).
- Fundamental cryptographic primitives, including public-key encryption and key-agreement protocols.
- General network-security concepts such as authentication, authorization, and access control.
Learning Outcomes
- Identify and explain 4G-to-5G architectural shifts that introduce security risks.
- Analyze isolation and trust challenges specific to network slicing.
- Describe 5G-AKA and its cryptographic mechanisms (SUCI/SUPI).
- Evaluate zero-trust design principles for 5G core network functions.
- Identify open research problems for future work in 5G/6G security.
Tutorial Structure / Technical Details
| Time | Segment | Indicative focus |
|---|---|---|
| 0:00–0:20 | Introduction | 4G vs. 5G architecture; motivation for a new threat model |
| 0:20–0:50 | Attack-surface expansion | NFV/SDN vulnerabilities; API/SBA exploitation |
| 0:50–1:20 | Network-slicing security | Isolation challenges; real-world attack scenarios |
| 1:20–1:30 | Break | |
| 1:30–2:00 | 5G-AKA deep dive | SUCI/SUPI, ECIES encryption, known attacks (linkability, downgrade) |
| 2:00–2:30 | Zero trust for network slicing | Micro-segmentation, NRF/SCP enforcement, case studies |
| 2:30–2:50 | Open problems | URLLC latency trade-offs, Open RAN supply chain, cross-operator slicing |
| 2:50–3:00 | Q&A / closing discussion |
Technical segment details
Segments combine conceptual exposition with protocol- and architecture-level detail, supported by illustrative attack scenarios drawn from published literature.
Introduction and motivation
- Contrast 4G’s hardware-centric core with 5G’s virtualized service-based architecture (SBA).
Expanded attack surface
- Examine cloud and IT vulnerability classes introduced by commodity-server and container-based network functions, including hypervisor escape, API injection, and broken authentication.
Network slicing security
- Consider isolation failure scenarios across RAN, transport, and core layers, with reference to isolation requirements in 3GPP TS 23.501 and TS 33.501.
5G-AKA deep dive
- Walk through SUPI-to-SUCI concealment using ECIES; review published findings on residual linkability and bidding-down vulnerabilities.
Zero trust for network slicing
- Apply continuous verification and least privilege to inter-slice and inter-network-function communication; discuss NRF and SCP roles.
Open problems and emerging risks
- IoT device hygiene at mMTC scale; Open RAN supply-chain trust; continuous verification trade-offs against URLLC latency.
Materials / Demonstration
NA.
Biography
Y. Chandramouli is Professor of Practice in Computer Science at the Chennai Mathematical Institute, where he teaches Networking Fundamentals and Applied Data Analytics. He has over 30 years of industry and research experience, including roles as Technical Architect at Cisco Systems and Research Scientist at Bell Communications Research and AT&T Bell Laboratories. His expertise includes traffic measurement, performance analysis, network security, and SDN-based analytics. He is the author of five IETF RFC Internet Standards and holds nine US patents. He holds M.S. and Ph.D. degrees in Systems Engineering from the University of Arizona and was a Visiting Scientist at the Robert Bosch Centre, IISc Bangalore.
References
- D. Basin, J. Dreier, L. Hirschi, S. Radomirović, R. Sasse, and V. Stettler. “A formal analysis of 5G authentication.” Proceedings of ACM SIGSAC Conference on Computer and Communications Security (CCS), 2018.
- C. Cremers and M. Dehnel-Wild. “Component-based formal analysis of 5G-AKA: Channel assumptions and session confusion.” Proceedings of Network and Distributed System Security Symposium (NDSS), 2019.
- S. R. Hussain, M. Echeverria, I. Karim, O. Chowdhury, and E. Bertino. “5G Reasoner: A property-directed security and privacy analysis framework for 5G cellular network protocol.” Proceedings of ACM SIGSAC Conference on Computer and Communications Security (CCS), 2019.
- S. R. Hussain, O. Chowdhury, S. Mehnaz, and E. Bertino. “LTE Inspector: A systematic approach for adversarial testing of 4G LTE.” Proceedings of Network and Distributed System Security Symposium (NDSS), 2018.
- A. Shaik, R. Borgaonkar, N. Asokan, V. Niemi, and J.-P. Seifert. “Practical attacks against privacy and availability in 4G/LTE mobile communication systems.” Proceedings of Network and Distributed System Security Symposium (NDSS), 2016.
Views: 4
