Skip to main content

Private 5G: A Trusted Foundation for Secure IoT

By Gaetan Antoniello, Thales

The Internet of Things (IoT) is connecting an ever-growing number of devices – from smart home products and energy systems to industrial equipment, connected vehicles and smart city infrastructure. These connected devices increasingly support services that we rely on in our everyday lives as well as important business and industrial processes.

As the number of connected devices grows, however, so does the importance of cybersecurity. It is no longer enough simply to connect a device to a network. Organisations need to know which devices are connecting, whether they can be trusted, and what they should be allowed to access.

Private 5G networks can provide an important foundation for building such trusted IoT environments.

5G was designed to connect large numbers of devices while providing fast, reliable communication. A private 5G network takes this one step further by creating a dedicated communication environment that can be operated and controlled by an organisation.

Unlike public mobile networks, a private 5G network can keep communication within a clearly defined environment. Organisations can determine which devices are allowed to connect, how they communicate and which services and resources they can access.

This makes private 5G particularly interesting for environments such as factories, energy systems, logistics centres, campuses or other locations where large numbers of connected devices need to communicate reliably and securely.

Private 5G provides several important advantages for IoT security:

  • Greater control: Organisations can define security and access policies according to their own requirements.
  • Better isolation: Critical devices, applications and services can be separated from other networks and systems.
  • Faster response: Suspicious behaviour can be detected and addressed close to where it occurs.
  • Improved data protection: Sensitive information can remain within the organisation’s controlled infrastructure.
  • Reliable connectivity: Communication can be designed around the specific requirements of the devices and services using the network.

Together, these capabilities create what can be considered a private 5G security bubble around connected devices and services.

Within this bubble, the organisation has much greater visibility and control over its connected environment. However, controlling the network itself addresses only part of the cybersecurity challenge.

Establishing trust in connected devices

A secure network still needs a reliable way of determining which devices are connecting to it.

This is particularly important for IoT environments. A factory, for example, may contain hundreds or thousands of connected sensors, controllers and machines. If an unauthorised or manipulated device gains access to the network, it could potentially compromise other systems or sensitive information.

Secure SIM and eSIM technologies can help address this problem by providing devices with a protected digital identity.

Instead of storing important security credentials in ordinary device memory, they can be protected within dedicated security hardware. This makes sensitive information such as cryptographic keys significantly harder to copy, manipulate or steal.

In this way, the secure SIM or eSIM can serve as a hardware-based root of trust for the connected device. The network can verify that it is communicating with an authorised device before providing access to services and resources.

But knowing the identity of a device is only the first step.

A device can have a valid identity and still present a cybersecurity risk. Its software may contain vulnerabilities, important security updates may be missing, or its configuration may no longer meet the security requirements of the environment in which it is being used.

The next question therefore becomes: How can we determine whether an authenticated device is also sufficiently secure to be trusted?
This is where private 5G can be combined with the security concepts developed within the DOSS project.

Connecting private 5G with the DOSS approach

DOSS develops solutions that help organisations establish trust in IoT products and make security information available where it is needed.

One of the project’s central concepts is the Device Security Passport (DSP). Just as a conventional passport provides information about the identity of a person, the Device Security Passport provides structured security information about an IoT device.

It can help provide answers to questions such as: What hardware and software does the device contain? What is known about its security? Has it been tested? Are there known vulnerabilities or other security issues that should be considered?

This adds an important additional dimension to the trusted identity provided by the secure SIM or eSIM.

Instead of asking only: “Is this the device it claims to be?”, an organisation can also ask: “What do we know about the security of this device, and should it be allowed to operate in our environment?”

DOSS also develops a Secure Onboarding approach to help ensure that devices can be securely introduced into an IoT environment. Security information can be considered when a device is connected and appropriate policies can be applied before it gains access to the services it needs.

Private 5G and DOSS therefore address complementary aspects of the same challenge.

A private 5G network creates a controlled communication environment. Secure SIM and eSIM technology provides a protected identity for connected devices. The DOSS Device Security Passport adds information about their security, while Secure Onboarding helps determine how a device should be introduced into the operational environment.

Together, these elements provide complementary layers of security:

  • Private 5G provides controlled and secure connectivity.
  • Secure device identities establish who the devices are.
  • The DOSS Device Security Passport provides information about their security.
  • DOSS Secure Onboarding helps ensure that devices are admitted to the environment in a controlled and security-aware way.

Bringing these elements together demonstrates how connectivity and cybersecurity can reinforce each other. Rather than treating the network, the device identity and the security of the device as separate issues, they can become different layers of a common trust framework.

For the rapidly expanding world of IoT, this is an important step forward: not simply connecting more devices, but creating connected environments in which devices can be identified, assessed and trusted before they become part of the network.

Leave a Reply