信息安全研究 ›› 2021, Vol. 7 ›› Issue (5): 443-449.

• 5G安全专题 • 上一篇    下一篇

全球5G安全评估认证体系演进及现状

焦杨 韩文婷    

  1. (中国信息通信研究院 北京  100191)
  • 出版日期:2021-05-05 发布日期:2021-05-05
  • 通讯作者: 焦杨
  • 作者简介:焦杨,1995年出生,中国科学院大学硕士研究生,现为中国信息通信研究院助理工程师,主要研究方向:5G安全、网络与系统安全、软件安全。 jiaoyang@caict.ac.cn 韩文婷,1990年出生,大连理工大学硕士研究生,现为中国信息通信研究院助理工程师,长期从事5G安全相关工作。 hanwenting@caict.ac.cn

The evolution and current status of the global 5G security assessment and certification system

  • Online:2021-05-05 Published:2021-05-05

摘要: 5G安全引发全球热点关注,建立基于统一标准的5G安全评测认证体系以应对5G安全风险,已经成为信息通信领域各方的共同诉求。目前,5G安全领域认可度较高的国际评测认证体系主要包括通用准则(CC)和网络设备安全保障框架(NESAS)。通过深入分析CC评估认证体系和NESAS测试评估体系的内在关联与区别,研究全球5G安全评估认证体系现状及方法演进历程,梳理欧盟开展5G安全统一认证计划的工作思路,结合我国5G测评实际情况提出下一步建议。

关键词: 5G安全, CC, NESAS, SCAS, 安全评估, 安全认证

Abstract: 5G security has attracted global attention, and the establishment of a unified standard-based 5G security assessment and certification system to deal with 5G security risks has become a common demand of all parties in the information and communication technology (ICT) field. At present, there are two main international assessment and certification systems that are highly recognized in the field of 5G security, namely CC (Common Criteria) and NESAS (Network Equipment Security Assurance Framework). This article will deeply analyze the internal correlation and difference between the assessment and certification methodology of CC and NESAS, study the current status and methodology evolution of the global 5G security assessment and certification system, sort out the working ideas of the EU to carry out the 5G security unified certification plan, and put forward suggestions for the next step based on our actual situation.

Key words: 5G security, CC, NESAS, SCAS, security assessment, security certification