Designing Dynamic Access Control Based on ZTA in A 5G MANO System
Hung-Ming Chen, Yung-Feng Lu, Yu-Lung Kuo, Yi-Ming Chuang · 2024
In recent years, with the emergence of diverse mobile network application requirements, today’s mainstream 4G mobile networks struggle to meet these varied application scenarios due to their architectural and hardware limitations. To address this situation, mobile networks are evolving towards a new type of 5G mobile network architecture.5G mobile networks provide various service types for mobile network applications through network slicing. To deploy and manage network slicing more effectively, 3GPP proposed a 5G MANO network slicing management and orchestration system in their specifications, allowing enterprises to build 5G private networks tailored to their specific needs. However, it is easy to overlook the design of information security. In recent years, Zero Trust Architecture has been acknowledged as a more secure method for system management and protection, leading to its widespread adoption and implementation. In the Enhanced Identity Governance (EIG), which is central to the Zero Trust Architecture, dynamic security access control is a mechanism that can adjust access permissions in real-time based on user behavior and situational context to ensure system security. Therefore, this study focuses on the needs of EIG within the core technology of Zero Trust Architecture and implements a dynamic security access control mechanism to protect the 5G MANO system, thereby enhancing its security.