Over the past six months, the term “5G” has become an increasingly regular part of general conversations. It was a big focus at the recently concluded MWC Barcelona event in February, and industry experts and analysts are working to explain 5G to the layman after national security concerns were raised about letting certain vendors into the buildout of 5G infrastructure in Europe and North America.
There are many aspects in which 5G is blazing a new path. It can supply at least 10x more peak data rate (at 10Gbps uplink) than 4G, 10x improvement over latency (at 1ms) than 4G, 1000x capacity expansion over 4G, etc. An important aspect that often gets lost in the speed and feed platitudes of 5G is literally how transformational it is that the entities in 5G core network communicate with each other.
Until 4G, the wireless core network was architected around nodes (or devices) that had physical and logical interfaces morphed over them with a defined stack of protocol layers. These layers exchanged signaling/control messages over point-to-point (logical) links with other nodes. However, in the case of 5G, signaling/control messages between nodes give way to open API calls between virtual network functions (VNF). Let’s explore this a bit more.
Over the last decade and half, the enterprise world has gone from running monolithic purpose-built applications on dedicated servers (similar to nodes in 4G network), to running modular applications consisting of open microservices exposing open APIs (Representational State Transfer [REST] APIs being the most common) running on a public or private cloud.
With 5G, the telecommunications network is finally making a similar transition. Functions served by purpose-built nodes in 4G have been abstracted out as VNFs exposing open APIs (RESTful APIs being the preferred choice in 3GPP) running in a cloud. So, the mode of communication between these VNFs is now leveraging REST API calls instead of exchanging signaling/control messages.
Interestingly, now the protocol layers involved in some of the control functions have changed over generations of wireless networks. To illustrate this, let us specifically consider the protocol layers involved in the initial attachment of the mobile device to the network, the authentication of this mobile device and the associated subscriber in the network (see below).
In the case of 2G (GSM/GPRS), the interface between MSC (News - Alert) and HLR/VLR is sending mobility management (MM) control messages over links running Signaling System 7 (SS7) protocols. In the case of 3G (UMTS), lower-level SS7 layers (MTP and SCCP) are replaced by Signaling Transport (SIGTRAN), and NAS mobility management control messages are sent over SS7 protocols running over links using SIGTRAN protocols. In the case of 4G (LTE), NAS mobility management control messages are sent over S1AP (towards SGW or MME) or DIAMETER (towards HSS) over SCTP. In all three cases, mobility management control messages are sent using myriad of signaling protocols over point-to-point (logical) links.
In the case of 5G, instead of signaling/control messages, mobility management is achieved through the REST API call over HTTP by a service-consuming VNF, which then goes over a TCP session to a peer service-producing VNF. To be fair, it is still traversing a protocol stack that consists of HTTP on the top of TCP/IP. However, the VNF is no longer attached to a node and it can literally move from the core network cloud to the mobile edge cloud while still using same open API to seamlessly communicate with its peer VNF.
In summary, the transformation of the wireless core network from signaling/control messages exchanging nodes to VNFs designed as microservices calling open APIs that traverse public networks exposes entirely new security vulnerabilities. This transformation is using a long legacy of all-IP networks and standard IT infrastructures and it exposes the wireless core network to familiar vulnerabilities that the enterprise world has been dealing with. However, mobile operators are now able to use the security tools that have been in place for many years to protect enterprise applications, such as firewalls, SSL intercept, DDoS protection to address the security vulnerabilities in 5G networks.Ravi Raj Bhat is global field sales Chief Technology Officer at A10 Networks (News - Alert). He is responsible for driving a global technical community, both internally across sales, product management and engineering, and externally with the customer and partner ecosystem. He is focused on aligning technology, sales services and partner solutions to ensure A10 Networks continues to drive technology leadership in 5G, multi-cloud and security infrastructures. Bhat brings over 25 years of experience in the technology industry, including a variety of senior roles leading globally-dispersed engineering teams across Asia Pacific, North America and Europe to deliver multiple industry leading products, including Distributed Cloud platform, SaaS (News - Alert) conferencing solution with REST API, Cloud-native Routing-as-a-Service, IP Routers, LTE eNodeB, and 40G ATCA blades.
Edited by Erik Linask