EST0055
Written evidence submitted on behalf of the UK Research Strategy Community Organisation in Communications, Mobile Computing and Networking (CommNet)
Prepared by: Professor Timothy O’Farrell, Director of CommNet, Department of Electronic and Electrical Engineering, University of Sheffield, Sheffield, S10 2TN.
CommNet is the UK’s community network in Communications, Mobile Computing and Networking within the EPSRC ICT Portfolio. Members of CommNet are leading researchers often with established international reputations in communications and networking technologies, in particular, 5G. Our response thus covers UK research in communications and networking, which is internationally leading and a substantial national asset. This response has been prepared after a widespread consultation with the membership of CommNet and, therefore, constitutes an independent response on behalf of CommNet and the community it serves.
Acknowledgements: Particular thanks are due to Professor David Hutchison (Lancaster University), Professor Gerard Parr MBE (University of East Anglia), Professor Dimitra Simeonidou (University of Bristol) and Professor Rahim Tafazolli (University of Surrey) in the compilation of this response. We are especially grateful for the comments and feedback obtained from the CommNet community.
Summary of Response
I summarise the key opinions derived from the CommNet community response:
Full Response
1.1. 5G infrastructure is immensely important to the UK in respect of the future provision of wireless access to vertical markets such as manufacturing, healthcare, transport and energy supply, for example. UK mobile network operators (MNOs) participate in domestic and international markets at considerable scale and, as such, are immensely dependent on purchasing telecoms equipment from a limited number of vendors, which in recent years has seen considerable consolidation.
1.2. Globally, there are just five single-purpose vendors selling 5G equipment: Ericsson (Sweden), Huawei (China), Nokia (Finland), Samsung (South Korea) and ZTE Corp (China). These vendors depend on a global supply chain of electronic chips, components, subsystems and software, which creates a complicated and highly interdependent ecosystem. While vendors and their suppliers manufacture to meet international telecommunications standards there is little regulation of the quality of their products beyond market reputation.
1.3. Another tier of equipment vendors, known as multi-purpose vendors, includes enterprise networking companies and “compute, storage and fabric” providers that have expanded into the telecommunications industry by supplying hardware, software, FCAPS and services. Examples of multi-purpose vendors include Cisco Systems (USA), Dell EMC (USA), Hewlett Packard Enterprise/ Aruba (USA) and Lenovo (China). These manufacturers supply products for the core and network edge.
2.1. The UK’s MNOs are constrained to purchase equipment from overseas (see section 1). The primary motivations during the tendering process are cost versus quality in terms of hardware and, importantly, software (reliability, scalability, functionality and integration).
2.2. Telecoms equipment is used in the network for relatively long periods of time with software upgrades being common. Therefore, operating a 5G network requires constant development and maintenance. The initial purchase of network equipment often represents a long-term relationship and dependency on the vendor’s technology.
3.1. The UK government has funded significant activities focused on supporting how 5G technologies could be used in vertical markets through DCMS’s 5G Testbed and Trials programme. The UK’s primary support for 5G has been one of facilitating its adoption with some support for evaluating its security and resilience.
3.2. HCSEC has focused on the reliability and safety of Huawei software including the evaluation of its source code in telecoms products. The support has largely focused on evaluating existing commercially deployable equipment. The expectation is that this would continue with the deployment of 5G. Skills learned in this process could be applied beneficially to assess different vendors’ products.
4.1. The greatest strength in the UK telecoms industry resides with ARM Holdings, which produces chip designs for mobile handsets and is a world leader in terms of market share and innovation. The application of ARMs technology in 5G, IOT and AI holds substantial potential for the future.
4.2. The UK has a vibrant telecoms software industry. The scale of this activity should be charted. With 5G software technologies associated with core and edge computing, network function virtualization, network management and orchestration, AI and machine learning, and cyber security there are significant innovations arising from UK companies, academic research funded by EPSRC and trials funded by DCMS.
4.3. The UK has a small but impactful RF industry, which manufactures radio equipment for mobile, IoT and wireless connectivity. The nurturing of this market in relation to 5G would depend strongly on the opportunity to sell technology to single-purpose vendors, for example.
4.4. The UK has an excellent SME supply sector in photonics for telecoms systems, which is fundamental to 5G services. Many single-purpose vendors invest in UK R&D in this area. There is also an emerging trend driving the integration of quantum security into 5G.
5.1. The principle documents in the public domain and familiar to members of the CommNet community are: “Next Generation Mobile Technologies: A 5G Strategy for the UK” published by DCMS in March 2017; “Future Telecoms Infrastructure Review” published by DCMS in July 2018; and recently “UK Telecoms Supply Chain Review Report” published by DCMS in July 2019.
5.2. The former two reports are regarded as high-level analyses of telecoms infrastructure requirements, which do not address security issues and leave much of the implementation detail to industry. The third report represents a more thorough analysis of the security and resilience threat to UK telecoms infrastructure while proposing a pathway to improving the situation.
5.3. The “UK Telecoms Supply Chain Review Report” and the 2019 “Huawei Cyber Security Evaluation Centre (HCSEC)” report provide a comprehensive evaluation of the issues faced by UK MNOs. However, these reports do not analyse significant new technologies. For example, the conclusions of the HCSEC report cover 4G LTE technology. Given the role of software control in 5G, the role of AI/machine-learning software has not been addressed, when there is evidence of this technology already gaining use in vendors’ equipment. While the “UK Telecoms Supply Chain Review Report” identifies that the greatest security and resilience risks are associated with the core network, there is no analysis of the vulnerabilities from cyber attacks initiated in the edge computing fabric. Edge IoT devices may pose a greater threat to security than core network switches and routers owing to the poor quality of software, firmware and operating systems as well as applications. More generally, there appears to be a need to evaluate security and resilience vulnerabilities at the overall system level.
6.1. The introduction of 5G to telecoms networks addresses numerous vertical markets (see section 1). This brings a further sensitivity to the interrelation of telecom services, operators and suppliers with diverse national assets, which have varying degrees of ownership and inward investment. It is unclear from the 2018 White Paper on National Security and Investment if the analysis there is sufficient to ensure a consistent security and resilience framework to safeguard all contexts of UK telecoms networks based on 5G. Current concerns mostly address broadband access whereas pathways to protect IoT and low latency high reliability networks remain largely unknown.
7.1. The government bodies that oversee the issues raised in this Inquiry are not readily identifiable to a practicing engineer. While there is a common understanding that telecoms networks are of vital importance to the UK’s prosperity there appears to be no one government office responsible for coordinating a national strategy for ICT per se. A broad coordination is desired encompassing ICT research through to full commercial telecoms network deployment. This point also relates to the broader issue of entry barriers for new actors such as micro-operators and UK suppliers of 5G technologies where R&D costs are prohibitive. The UK’s industry strategy would benefit from a recognisable ICT theme with funding to sustain a national ICT strategy, which could incorporate the safeguarding aspects of this Inquiry.
8.1. The UK has demonstrated a concerted effort to provide evidence-based analysis of the threat to telecoms systems drawing on expertise from across the government, industry and academic base. When viewed from the outside, there is a lack of clarity regarding how the processes to do this are established and maintained. For example, other than DCMS reports, access to reports relevant to telecoms matters from other Government departments is unclear. Also, the role of Scientific and Engineering Advice within the Government does not appear to have a clear ICT pathway. As mentioned in section 7, the vital role of ICT in the UK’s prosperity would benefit from greater connection between Government offices responsible for ICT as well as the formulation of a national ICT strategy to draw the various strands of expertise together.
9.1. Compared with our like-minded partners, the UK approach is relatively leading in the sense that since 2010 the HCSEC has provided a template for security risk mitigation in complex telecoms equipment. This represents an engagement with the issue and recognition that a balance can be obtained between safeguarding the infrastructure while allowing market entry for compliant high-risk vendors, which helps to stimulate competition in the supply chain when managed correctly. Extending this approach to all vendors while enhancing the checks on high-risk vendors coupled with a legal framework, as described in the “UK Telecoms Supply Chain Review Report” is a step in the right direction. The criteria for defining a high-risk vendor are another matter that requires careful consideration, as the criteria may not be purely technical.
9.2. The MNO business model has contributed to the consolidation of suppliers leading to a relatively small number of global vendors and the dependencies that have created the security risks identified. Instead, the diversity, lowering of entry barriers and the high security and resilience sought require new regulations and business models that go well beyond traditional network operator roles.
9.3. While our like-minded partners are characterised by being either (understandably) cautious or slow to reform, the UK is quite well placed to lead on this issue. The recommendation in the “UK Telecoms Supply Chain Review Report” to explore the need for a national telecommunications laboratory should be complemented by the need to create national R&D programmes that underpin the long-term development of ICT in the UK.
10.1. The UK has a vibrant academic community in telecoms. Many of the UK’s academic researchers collaborate with international partners often by engaging with the EU framework research programmes. Also, they collaborate through bespoke projects with universities, agencies and industry in the EU, USA, Australia, Japan and South Korea. Further, a number of academics collaborate with universities and industry in China. CommNet has held joint events, which aim at fostering research collaboration between UK and Chinese academics, with a similar organisation in China called “China Future Mobile Communication Forum”.
10.2. Assuming the UK leaves the EU, there is a need to sustain opportunities for international cooperation with former partners based in the EU. In respect of telecoms infrastructure and its safeguarding, the EU countries experience and share the same risks and so have a common interest in mitigating these risks cooperatively. A considerable amount of shared telecoms network infrastructure has been developed to support research on EU framework projects and it would benefit the UK to maintain its association with these facilities.
10.3. The UK telecoms community possesses a very diverse range of skills in most aspects of 5G spanning hardware and software. However, the national research effort in this sector tends to be ad hoc and one perceived reason is the absence of UK vendors of scale, which could provide a national focus and investment scale to champion new technology developments. One of CommNet’s roles is to inform its members of the relevant research landscape, which reflects a strong desire within the community to have access to strategic funding and resources. International cooperation through building science bridges is important to this community as a way of identifying relevant research challenges.
Further Comments
In this section, I provide evidence from contributors who would like their statements to be read directly.
Item-1
"There are numerous security concerns associated with untrusted equipment vendors, which are detailed in https://ieeexplore.ieee.org/document/7467419, https://ieeexplore.ieee.org/document/7498103 and summarised as follows:
Eavesdropping - this can be addressed by end-to-end encryption and authentication. It is possible to impose an extra security layer on top of the existing one at the cost of slowing down authentication. Other techniques include physical layer security and quantum key distribution, which are areas of strength for UK research.
Phishing - there is concern that equipment could report logs and/or statistics about traffic and connectivity to third parties, which could be used for large-scale population monitoring. This could be addressed by imposing strict limitations of what data can be extracted from equipment by parties other than the operator.
Denial of service - there is a concern that kill-switches could be introduced into equipment, allowing it to be turned off by a third party. This could be addressed by imposing strict requirements on the separation between the data plane and the control plane of this equipment.
A challenge for the UK is that is relies to a large degree on equipment sourced from outside of the UK and its allies. It may be prohibitively expensive to migrate existing and (to a lesser degree) future deployments to new vendors. There is an opportunity to address this by supporting UK operators to build their own equipment, by embracing open-RAN architectures, which allow equipment to be constructed based on components sourced from a variety of suppliers, of various size and location. This approach makes it more difficult for a malignant supplier to have any capability to implement the attacks listed above, because they would not have the cooperation of the components provided by other suppliers and because the open-RAN architectures enforce strict separation and standardisation of the interfacing between components. However, it may be expected that the initial wild-west of open-RAN architectures may come with its own security challenges, which may not be addressed until the solutions reach maturity.”
Item-2
"What is most required is the need for some joined up thinking about security and infrastructure and who is responsible for different aspects of the infrastructure. This should be targeted at three entities: the mobile user, server and infrastructure security. That is, collectively how can the mobile devices manufactured by handset vendors, servers deployed by ISPs and infrastructure purchased by MNO be made secure by working with the government.”
Item-3
"An important additional topic that Commnet2 wishes to bring to the attention of the Committee derives from an analysis of the oral evidence session (HC2200) and the paragraphs below from the letter of Norman Lamb to Jeremy Wright on 10th July 2019, which is partially reproduced below:
“Nevertheless, we acknowledge that the security of the UK’s telecommunications infrastructure is critical, and ...”
The importance of the statements above cannot be over-emphasised. However, “to operate safely” gives the wrong emphasis; this is not the only concern. Safety is indeed vital in the case of 5G-based applications such as autonomous vehicles – as also is security – but so is resilience. It would therefore be appropriate to say instead “to operate safely and securely, and to be resilient”. Resilience needs to become a fundamental attribute of 5G networks and essential services – and assured by the way they are designed and operated.
Resilience is the ability of a network or system to continue to offer satisfactory service even in the face of the challenges that it experiences. Resilience is complementary to safety and security; its importance urgently needs to be recognised as part of the systematic design and operation of future complex systems – in particular, in future 5G-based systems such as autonomic vehicles, smart cities, and heath applications. As hinted in Q48 in “Oral evidence: UK telecommunications infrastructure, HC 2200”, resilience management is not just about technology, but needs to embrace organisational and human factors as sources of risk and as contributors to its solution.”
End of Response
13 September 2019