Zero Trust Security Framework for ePDG in 5G Untrusted Wi-Fi Access Networks

Authors

  • Saiprasad Charudatta Shrikhande

Keywords:

ePDG, Zero Trust Architecture, NIST SP 800-207, 5G non-3GPP access, untrusted Wi-Fi, IPSec, IKEv2, EAP-AKA, continuous authentication, micro-segmentation, behavioral analytics, dynamic risk scoring, policy enforcement point, 3GPP TS 23.402.

Abstract

The integration of untrusted Wi-Fi networks into 5G architecture introduces significant security challenges because the access layer is, by definition, beyond the operator’s trust boundary. The Evolved Packet Data Gateway (ePDG) provides secure connectivity from Wi-Fi to the 5G core using IKEv2/IPSec tunnels and EAP-AKA authentication, but its trust model remains essentially perimeter-based: once a device completes EAP-AKA, it is implicitly trusted for the lifetime of the session. Modern attack vectors — rogue access points, man-in-the-middle downgrades, replayed EAP-AKA nonces, credential theft, session hijacking, and device spoofing — are increasingly able to defeat that one-time, static model.

This paper proposes a Zero Trust Security Framework for ePDG that replaces perimeter trust with continuous verification, dynamic policy enforcement, and context-aware authentication. The framework introduces five concentric layers — Identity & Trust, Behavioral Analytics, Policy Decision Point (PDP), Micro-segmentation Policy Enforcement Point (PEP), and a Crypto Plane — wrapped around the ePDG core. A composite risk model R = α(1 − U) + β(1 − D) + γN + δB combines user trust, device posture, network condition, and behavioral anomaly to drive per-session decisions in real time. Re-authentication, step-up MFA, and micro-segmentation isolation are triggered when the score crosses configurable thresholds. Across a six-attack benchmark (rogue AP, MITM, replay, credential theft, session hijack, device spoofing), the proposed framework lifts the mean detection rate from 46% (traditional ePDG) to 94% while adding only ≈ 34 ms of mean authentication latency. The design is standards-compliant (3GPP TS 23.402, NIST SP 800-207) and incrementally deployable on existing ePDG infrastructure.

Downloads

Published

2026-09-28

How to Cite

Shrikhande, S. C. (2026). Zero Trust Security Framework for ePDG in 5G Untrusted Wi-Fi Access Networks. International Journal of Artificial Intelligence and Machine Learning, 6(12s), 205–212. Retrieved from https://www.svedbergopen.com/index.php/ijaiml/article/view/2410