After an assessment of the status of 5G security assets and future trends, security requirements for 5G networks and a threat landscape that have been defined and monitored during the project. 23 use cases based on the business and technical requirements on 5G security have been defined. The following advancements have been achieved by INSPIRE-5Gplus:
• Definition of a High Level Architecture (HLA) of a zero-touch end-to-end smart network and service security management framework that empowers not only protection but also addresses trustworthiness and liability in managing 5G network infrastructures across multiple domains.
• Definition of a set of security enablement technologies, having the potential to significantly contribute to 5G security evolution. Examples are Trusted Execution Environments, DLT, Liability and Root Cause Analysis, enablements related to network automation & zero touch management, SSLAs, and Multi-Domain security policies management.
• Specification and development of a set of enablers for the automatic and autonomic end-to-end and multi-domain security management based on security policies, SSLAs, optimisation of orchestration, the provisioning, and the chaining of virtualised security functions, micro-services, and virtualised network functions. AI and ML based methods and techniques have been developed to optimise and autonomies each of the prediction, detection, and mitigation processes in ZSM closed loops.
• Mechanisms to ensure trust in virtual networks, platforms, and functions, such as the use of certification techniques or Proof Of Transit or managing the trust in slices through the use of a blockchain. Liability mechanisms have also been explored and implemented in the same context, such as Root Cause Analysis in virtualized infrastructure or deep attestation which enables attesting the state of a system having multiple levels (HW, VM).
• Specification and development of examples of ZSM security management closed loops supporting proactive and reactive capabilities as well as trust and liability management in a multi-domain context.
• Definition of three demonstrators providing a complete implementation and validation of the High-Level Architecture capabilities based on validated KPIs.
• An integration and verification platform composed of 11 domains for developing and testing purposes.
• KPIs for security, trust and liability, and their relationship with the 5G PPP KPIs have been defined with a baseline of assessment criteria to be fulfilled by the INSPIRE-5Gplus enablers.
• The results of INSPIRE-5Gplus have been published in 45 conference and 20 journal papers, presented in several industrial events, and provided contributions for various standardisation bodies such as IETF/IRTF and ETSI.
• Business models for the project assets and solutions have been defined with an analysis of beneficial impact on SMEs, and transfer actions of the results to the business lines of industrial partners. A majority of the results will be exploited following an open-source model, which improves the adoption of the implemented security architecture by academia, SMEs and industry.