0  Introductionp. 9

The architectural study captured in TR 23.724 considers alternatives for supporting WB-EUTRA (eMTC) and/or NB-IoT in 5GS. The main assumption of the architectural study is that no new RAT for 5G massive MTC would be introduced but rather that the existing E-UTRAN radio technologies would be also used with 5GS. The 5GS already supports certain features that are useful for IoT, e.g. the UE can register to the system without necessarily establishing a PDU session and can use non-IP-type PDU sessions for data delivery. However, EPS provides also other features that are useful for IoT/MTC., e.g. power saving functions, overload control, high latency communication, monitoring, service capability exposure, etc. The extension of these EPS features to 5GS system is the main goal of the architectural study. Several of these features have security aspects.

1  Scopep. 10

The present document studies the following:
  • Capture massive MTC related 5G requirements in other 3GPP documents and further analyse them from security point of view.
  • Study security for supporting EPS CIoT/MTC functionalities in 5GS, e.g.:
    • security for infrequent and frequent small data transmission
    • security for inter-RAT mobility to/from NB-IoT or modifications in the EPC-5GC interworking security specific to CIoT.
  • Study security enhancements based on the architectural study in TR 23.724, e.g.:
    • security for transport of user plane over 5G NAS; or
    • termination of user plane security in 5GC.
  • Study the security aspects of the architectural enhancements addressing the 5G service requirements in TS 22.261 and TR 38.913.
  • Study the need for additional mechanisms to improve protection of the network from maliciously behaving IoT devices

3  Definitions of terms, symbols and abbreviationsp. 11

Misbehaving UE:
A UE that is controlled by an attacker with malicious application running.
Narrowband-IoT (NB-IoT):
see definition in TS 23.401
See definition in TS 38.300.

3.3  Abbreviationsp. 11

5G Access Network
5G Radio Access Network
Access and Mobility Management Function
Cellular Internet of Things
Control Plane
Denial of Service
Distributed Denial of Service
NR Node B
Internet of Things
Machine Type of Communications
Narrow Band Internet of Things
Next Generation
Next Generation Evolved Node-B
New Radio
User Plane Function

4  Security aspects of the CIoT features in the 5G Systemp. 12

4.1  Backgroundp. 12

The architectural study in TR 23.724 addresses two new 5G features related to service delivery for CIoT capable UEs. The first feature is for the infrequent transmission of small data. It is targeted at constrained, low power and low rate UEs. The solution for this feature makes use of the NAS signalling to transport the data similarly to the Data over NAS (DoNAS) feature in EPS. The second feature is for the frequent transmission of small data and is targeted at more active UEs. It is expected that the final solution for this feature will be based on a mixture of an enhanced version of RRC inactive with early data and the EPS resume suspend feature for Narrow Band IoT (NB-IoT). Since both features are based on the EPS ones, it is natural to expect similar security impact on the 5GS to support them.

4.2  High level potential security requirementsp. 12

The security aspects shall be based on the CIoT architecture referring to TR 23.724 where E-UTRAN (i.e. both WB-E-UTRA and NB-IoT) is connected to 5GC via N2/N3.
UEs used for CIoT in 5GS shall comply with the security features and security requirements in TS 33.501.

