arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

CERTIoT-6G:面向5G/6G网络中物联网设备的持续网络安全认证

CERTIoT-6G: Continuous Cybersecurity Certification for IoT Devices in 5G/6G Networks

Evangelos Lempesis, Fabio Palmese, Hamed Haddadi, Anna Maria Mandalari

arXiv 2608.23339首次发表:更新:

AI 中文总结

针对物联网设备在5G/6G网络中面临的网络安全与监管认证难题,本文提出CERTIoT-6G安全即服务框架,可自动化认证与持续合规监控,经验证其影响可忽略且能识别合规缺口。

AI 中文摘要

物联网(IoT)设备在医疗、智慧城市、工业自动化及关键基础设施等关键领域的大规模应用,带来了重大的网络安全与监管挑战。当前及即将出台的欧洲法规,包括《网络弹性法案》(CRA)和《NIS2指令》,要求制造商、运营商及其他机构确保设备采用安全设计、实施持续漏洞管理,并在设备全生命周期内保持弹性运行。传统认证机制是静态、人工的,难以在异构物联网生态系统中扩展。本文提出CERTIoT-6G,这是一种安全即服务(SECaaS)框架,可对运行于5G及未来6G网络中的物联网设备实现自动化网络安全认证与持续合规监控。该框架整合了自动化合规分析、实时流量监控及对抗性测试能力。我们在一个先进5G测试床中运行的不同物联网设备类别上对CERTIoT-6G框架进行验证。评估结果显示存在关键合规缺口,尤其是在不稳定条件下的流量加密与可用性方面,且表明该框架能生成映射到异构设备类型监管要求的可操作判定。此外,我们还证明监控流水线对5G实时流量的影响可忽略不计。

英文摘要

The massive adoption of Internet of Things (IoT) devices across critical domains such as healthcare, smart cities, industrial automation, and critical infrastructure introduces significant cybersecurity and regulatory challenges. Current and forthcoming European regulations, including the Cyber Resilience Act (CRA) and the NIS2 Directive, require manufacturers, operators, and other organizations to ensure secure-by-design devices, continuous vulnerability management, and resilient operation throughout the device lifecycle. Traditional certification mechanisms remain static, manual, and difficult to scale across heterogeneous IoT ecosystems. This paper presents CERTIoT-6G, a Security-as-a-Service (SECaaS) framework that enables automated cybersecurity certification and continuous compliance monitoring of IoT devices operating in 5G and future 6G networks. The framework integrates automated compliance analysis, real-time traffic monitoring, and adversarial testing capabilities. We validate the CERTIoT-6G framework on different IoT device categories operating in an advanced 5G testbed. Evaluation results reveal critical compliance gaps, particularly in traffic encryption and availability under unstable conditions, and demonstrate that the framework produces actionable verdicts mapped to regulatory requirements across heterogeneous device types. Furthermore, we show that the monitoring pipeline has a negligible impact on live 5G traffic.

CommentsPaper accepted for publication at IEEE Conference on Standards for Communications and Networking 2026 (CSCN 2026)

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑