Source-linked AI summary

Intelligent Zero Trust Architecture for 5G/6G Networks: Principles, Challenges, and the Role of Machine Learning in the context of O-RAN

Keyvan Ramezanpour, Jithin Jagannath

arXiv:2105.01478v3cs.NIcs.LG

TL;DR

Future 5G/6G networks combine large-scale connectivity, mobility, virtualization, and untrusted infrastructure, challenging perimeter-based security and strong trust assumptions. This position paper proposes an AI-enabled intelligent zero trust architecture using O-RAN, dynamic monitoring, risk assessment, and access authorization. It presents the architecture as a framework and research direction for information security in untrusted 5G/6G networks.

  • Problem

    5G/6G networks operate with heterogeneous devices, virtualized functions, and untrusted infrastructure, while existing security models rely on boundaries and strong trust assumptions.

  • Method

    The paper proposes an O-RAN-compliant intelligent zero trust architecture with AI engines, dynamic policy enforcement, and GNN-based network-state modeling for risk assessment.

  • Results

    The paper presents i-ZTA as a conceptual framework for applying AI engines to information security and enforcing zero trust principles in untrusted 5G/6G networks.

  • Takeaways & Limitations

    The architecture provides research directions for machine-learning-based zero trust components and may support security for tactical and commercial 5G/6G applications.

Abstract

from arXiv · show

In this position paper, we discuss the critical need for integrating zero trust (ZT) principles into next-generation communication networks (5G/6G). We highlight the challenges and introduce the concept of an intelligent zero trust architecture (i-ZTA) as a security framework in 5G/6G networks with untrusted components. While network virtualization, software-defined networking (SDN), and service-based architectures (SBA) are key enablers of 5G networks, operating in an untrusted environment has also become a key feature of the networks. Further, seamless connectivity to a high volume of devices has broadened the attack surface on information infrastructure. Network assurance in a dynamic untrusted environment calls for revolutionary architectures beyond existing static security frameworks. To the best of our knowledge, this is the first position paper that presents the architectural concept design of an i-ZTA upon which modern artificial intelligence (AI) algorithms can be developed to provide information security in untrusted networks. We introduce key ZT principles as real-time Monitoring of the security state of network assets, Evaluating the risk of individual access requests, and Deciding on access authorization using a dynamic trust algorithm, called MED components. To ensure ease of integration, the envisioned architecture adopts an SBA-based design, similar to the 3GPP specification of 5G networks, by leveraging the open radio access network (O-RAN) architecture with appropriate real-time engines and network interfaces for collecting necessary machine learning data. Therefore, this work provides novel research directions to design machine learning based components that contribute towards i-ZTA for the future 5G/6G networks.

1. Introduction

5G/6G networks expand connectivity, heterogeneity, mobility, and virtualization beyond the assumptions of perimeter-based security. The paper motivates intelligent zero trust architecture (i-ZTA) as an AI-enabled framework for dynamic risk assessment, monitoring, and authorization in untrusted networks.

  • 1. Introduction: 5G/6G networks connect heterogeneous devices across agile radio environments, including satellite and UAV communications, while traditional security frameworks provide weak assurance in this complexity.The expanded environment includes autonomous vehicles, V2X networks, smart infrastructure, and IoT devices.
  • 1. Introduction: Perimeter-based models struggle to identify a network boundary in mobile, heterogeneous environments and permit lateral movement after authentication.These models treat authenticated and authorized subjects inside the trust zone as trusted.
  • 1. Introduction: Strong trust assumptions among network entities can expose existing protocols to privacy, denial-of-service, man-in-the-middle, and impersonation attacks.The paper contrasts these assumptions with the requirements of untrusted next-generation networks.
  • 1. Introduction: Zero trust architecture individually authorizes and monitors every access request using dynamic trust evaluation, rather than authorizing a subject once.This approach addresses security requirements in networks with untrusted infrastructure.
  • 1. Introduction: The proposed i-ZTA uses AI engines, O-RAN integration, and MEC support to enforce zero trust principles in next-generation 5G networks.The architecture is intended to support information security in untrusted networks and resource-constrained devices.

2. Impact statement

The paper frames zero trust as necessary for protecting data and critical network-dependent technologies in future wireless networks. It introduces an O-RAN-compliant intelligent ZTA based on AI engines as a research direction for 5G/6G cybersecurity.

  • 2. Impact statement: 5G networks manage data from smartphones, autonomous vehicles, smart buildings, cities, and infrastructure, while critical technologies rely on network-based data management and processing.The paper emphasizes personal sensitive data, public safety, and national security.
  • 2. Impact statement: The paper presents an O-RAN-compliant conceptual intelligent ZTA and discusses exploiting existing AI algorithms to realize zero trust premises.Its stated goal is to open and accelerate research on AI for next-generation zero trust cybersecurity systems.

3. Why Intelligent Zero Trust Architecture

Beyond-5G networks dilute traditional perimeters through virtualization, disaggregation, mobility, and untrusted infrastructure, while expanding attack surfaces and enabling lateral movement. The paper therefore proposes comprehensive, AI-enabled ZTA controls integrated across O-RAN network layers.

  • Authenticated subjects can still move laterally or obtain unauthorized access because perimeter-based frameworks remain static in dynamic, heterogeneous networks.
  • 5G/6G virtualization, SDN, and cloud deployment dilute network perimeters and place network functions on shared infrastructure with untrusted third parties.
  • Existing ZTA proposals often focus on IDS/IPS and continuous authentication at the application layer, leaving comprehensive lifecycle control an open problem.
  • O-RAN’s open, disaggregated architecture broadens attack surfaces across availability, integrity, confidentiality, and AI/ML security.
  • The paper proposes integrating comprehensive ZT mechanisms with 5G O-RAN to protect network infrastructure across the access chain.
  • The proposed i-ZTA introduces AI engines for real-time monitoring, risk assessment, trust evaluation, and dynamic policy decisions across the seven ZT pillars.

4. Challenges and Opportunities

Next-generation networks require real-time monitoring and security evaluation because dynamic multi-RAT connectivity, heterogeneous devices, and distributed assets expand the attack surface. The proposed integration uses O-RAN data interfaces and MEC resources to support i-ZTA components in this environment.

  • Network challenges: Multi-RAT connectivity and heterogeneous devices make real-time monitoring and security evaluation necessary for every participating device.Devices differ in security specifications, credentials, privileges, and computing resources.
  • Network challenges: Dynamic access and distributed assets broaden the attack surface, enabling device manipulation, hostile environments, and unintrusive precision attacks.These attacks can exploit authorized user equipment or avoid privileged network access.
  • Enabling technologies: O-RAN supplies E2, O1/O2, and remote interfaces for collecting monitoring and machine-learning data from network nodes, remote devices, and VNFs.The interfaces support analysis of traffic from UEs to network assets.
  • Enabling technologies: MEC places computing resources near the network edge, giving mobile devices low-latency access to high-performance processing.This is intended to address the limited computational resources of IoT and sensor devices.
  • Enabling technologies: MEC follows a 5G SBA model in which an application function interacts with core functions and MEC hosts are managed through the network exposure function.The 5G core can steer traffic to applications in a local area data network.
  • Enabling technologies: MEC can host intelligent MED components while the i-ZTA core supplies dynamic protection alongside the 5G core’s static security functions.The architecture positions MEC at the edge and uses core functions for authentication, authorization, service continuity, and traffic steering.

5. Envisioned Intelligent Zero Trust Architecture and Research Directions

The envisioned i-ZTA is a unified AI-enabled framework that realizes zero-trust functions through intelligent policy, network-state analysis, and agent or portal components. It combines reinforcement learning, graph neural networks, federated learning, adversarial learning, and O-RAN/MEC integration to support dynamic authorization and network assurance.

  • Architecture: The i-ZTA introduces a unified framework with AI engines for information security in untrusted networks.Its key elements are the IPE, INSSA, and IGP components.
  • Architecture: The IPE uses an AI trust algorithm to authorize requests from privileges, security state, policies, network state, and access-confidence scores.Reinforcement learning is envisioned to maximize usability with least privileges.
  • Architecture: IGP models a subject’s security state, analyzes traffic posture, and provides environmental awareness to support confidence in resource access.Higher environmental-awareness values may yield higher confidence scores in IPE risk assessment.
  • Integration: The O-RAN-integrated design uses O-RAN processing and data collection for IPE and INSSA, while MEC supports IGP components and near-real-time monitoring.The PEP is divided into agent, portal, and gateway components, including support for resource-constrained devices.
  • Learning components: Federated learning aggregates experience across agents, increases individual-agent visibility, and supports detection of distributed attackers.The portal supports federated learning for agents that collaboratively model the network environment.
  • Architecture: INSSA uses graph neural networks for network security-state risk assessment and anomaly detection.A recurrent GNN is proposed to model 5G communication patterns across space and time.
  • Learning components: Adversarial learning trains network risk assessment and anomaly detection while balancing least privileges, usability, and compliance with security policies.The GNN maximizes usability with least privileges while an adversarial network maximizes policy-compliant privileges.
  • Research directions: The framework is intended to meet enhanced security needs of future military and commercial 5G/6G networks without compromising information security.The authors present this as an envisioned benefit of the combined components and AI engines.

6. Conclusion

The paper concludes that untrusted 5G/6G environments require dynamic authorization, risk assessment, and asset monitoring supported by real-time big-data processing. It proposes an SBA-based i-ZTA core using IPE and IGP, with reinforcement and federated learning as central mechanisms.

  • Conclusion: Network assurance in untrusted 5G/6G environments demands dynamic authorization, risk assessment, and monitoring of network assets.The paper links these requirements to real-time processing of network big data.
  • Conclusion: The i-ZTA adopts an SBA-based design with AI engines to realize zero-trust principles in untrusted networks.The architecture leverages distinct 5G technologies as enablers.
  • Conclusion: The i-ZTA core includes IPE and IGP for dynamic access-request authorization.IPE uses reinforcement learning to maximize an assurance score, while IGP uses federated learning.
Loading 2105.01478v3…