Security Executive Summary Securing LTE Radio Access Networks Effectively
LTE networks require a dedicated security solution As an all-ip technology, LTE brings new capabilities to improve the customer experience, but also demands new security measures to protect those same customers, as well as the operator. A vital part of moving LTE networks from pilot deployments to full commercial roll outs is the implementation of solid security measures to protect the network and its users from hacking and other cyber-attacks. It s an increasingly important issue because the effects of a security breach could be financially devastating for an operator. In one instance, a European operator suffered losses of around 25 million due to increased churn following an attack on a gateway that led to poor browsing service for several days. LTE is fully IP, creating vulnerabilities not seen in 2G and 3G networks. In GSM and WCDMA networks, traffic is protected by encrypting it between the user equipment and the radio network controller, typically installed in a building and trusted environment. LTE architecture is different because it is all-ip within the core and all the way to the base station. Encryption is typically applied only between the LTE base station and the end-user device, leaving traffic on the transport network unencrypted. The business impact of any disruptive event can be dramatic. As an example, any attempt to illegally track voice and data can damage the sensitive relationship between operator and customer, which could ultimately lead to subscriber churn. Unauthorized access to the core network can also cause denial of service or even corrupt the operator s management systems, for example, operations support system (OSS). Page 2
Small cells set further demands for protection The use of IP/Ethernet connectivity for the backhaul, which by nature is more open than traditional circuit-based networks, means that customer data needs to be protected against eavesdropping. Furthermore, operator systems must be secured against misuse and other threats between the base station and packet core. The risks are increased by the deployment of small cells, an important aspect of LTE networks that are designed to provide virtually unlimited capacity and coverage. Increasingly, LTE base stations will be installed in areas more easily accessible to the public - in shopping malls, airports and on the street. The potential for people to physically access a base station, or even steal it and try to use it on another network, is very real. The importance of being 3GPP-compliant 3GPP has long recognized the issues of mobile network security. With the help of Nokia Networks long history in IP, its forward looking approach to stringent LTE security, its industry leading contributions and leading role in standards body leadership, 3GPP has developed today s specifications for LTE security. Yet, Nokia Networks contribution does not stop there. Nokia Networks continues to implement LTE innovation security in its commercial products where gaps exist between commercial reality and conformance to standards. Nokia Networks offers a 3GPP-compliant end-to-end security solution built for LTE. The solution secures data between the base station and the core network with IP security (IPSec). In addition, strong certificate authority using Public Key Infrastructure (PKI) ensures only operator-authorized base stations can access the network. Efficient operation is provided through fully automated certificate life cycle management for both the LTE base station and security gateway. When base stations are deployed they need an authentication certificate to allow them to connect to the network. In the Nokia Networks solution, the certificates are issued automatically, resulting in up to 25% faster roll out with 25% cost savings. Adopting a 3GPP-compliant solution has important advantages for operators. Not only is compliance mandatory in some countries, but Nokia Networks has a full understanding of mobile operators strict dual source procurement requirements. Standards-based product deployments have many benefits, including operational efficiencies which are not available with proprietary security solutions. With Nokia Networks end-to-end, 3GPP-compliant security solution built for LTE, operators can protect their customers to the same high levels as in 2G and 3G networks. It s a cost-effective way to avoid security breaches that can lead to costly increases in churn, potentially damaging the operator s investment in LTE. Strong security will therefore play a vital role in protecting the brand reputation of any operator moving into an all-ip environment such as LTE. Page 3
Carrier Grade Security - a must-have to take full advantage of LTE LTE is normally associated with delivering an enhanced user experience through high speed, fast reaction and extended broadband coverage in rural areas. Moreover, it also stands for higher efficiency provided by simplified and flattened architecture, all IP transport and highly efficient radio technology providing higher data rates at reduced cost. It also opens up a host of opportunities for generating revenue through new services, business models and partners. However, just as data throughput and administrative access can be affected across a network, so can the areas responsible for robust security. It is for this reason that Nokia Networks uses a carrier-class development approach and a 3GPP based security eco-system to ensure critical components are never compromised as a network grows. Combining forward looking LTE security innovation with its strong security partnerships, Nokia Networks employs specialized carrier-grade security offerings for LTE radio access, packet core, and network access management. Each solution is pre-validated and supported, providing customers with turnkey solutions that will work in their environments out of the box. Nokia Networks continues to receive positive feedback from mobile operators who have expressed their confidence and trust in Nokia Networks approach to securing their networks. Today, Nokia Networks is the market leader in providing 3GPP compliant automated security for LTE networks. It s security solution offers high availability and redundancy allowing operators to achieve carrier grade (99,999%) availability and support seamless growth of their LTE networks. Page 4
Nokia Networks Radio Access security solution offers comprehensive protection combined with high performance and availability Our 3GPP-compliant solution secures data between the base station and the core network with IP security (IPSec). In addition, strong certificate authority using Public Key Infrastructure (PKI) ensures only operator-authorized base stations can access the network. The solution includes Certificate Authority and Security Gateway as hardware/software components as well as services covering the solution s full life cycle, from architecture and design, to implementation and support. Nokia Networks uses its experience to provide operators with the best-in-class security solution available on the market: Complete end-to-end security solution for LTE networks with live deployment experience Built-in IPSec in our enodebs with high throughput ensuring highest performance. Pre-validated LTE RAN solutions Efficient operation through fully automated certificate life cycle management for both enodeb and Security Gateway. Page 5
Why Nokia Networks? As an early adopter of IP technology in mobile networks, Nokia Networks is passionate about securing LTE networks. This unwavering focus has allowed many operators to transition from legacy technologies to LTE with confidence. In addition, Nokia Networks has received global recognition for uniquely securing these LTE networks. Evidence of this includes best-in-class security practices as acknowledged by its customers and competitors and active leadership in the 3GPP standards body. It has also built a reputation for telco-grade solutions through its commitment to continually validating performance and stability with the help of its strong eco-system of partners. Nokia Networks expertise is based on a worldwide network of highly skilled and experienced security specialists who hold more than 350+ security certifications (e.g. CISSP, CCSA, CISA, CISM). Nokia Networks has successfully delivered over 500 security projects worldwide, ranging from consulting engagements to complete turnkey solutions and support. Page 6
Public Nokia is a registered trademark of Nokia Corporation. Other product and company names mentioned herein may be trademarks or trade names of their respective owners. Nokia Nokia Solutions and Networks Oy P.O. Box 1 FI-02022 Finland Visiting address: Karaportti 3, ESPOO, Finland Switchboard +358 71 400 4000 Product code C401-01146-ES-201412-1-EN Nokia Solutions and Networks 2014