Huawei has been defending its โ€œtrustworthinessโ€ amid comments from Germanyโ€™s spy chief, though the countryโ€™s government has already drafted new security guidelines allowing the Chinese equipment maker to supply equipment for Germanyโ€™s future 5G network.

Bruno Kahl, head of the German Federal Intelligence Agency, claimed that Huawei canโ€™t be fully trusted. In response, Huawei Germany issued a statement repeating that it is independent of Chinaโ€™s Communist Party and has a good track record working with network operators worldwide.

In an ironic twist, German authorities drafted new security guidelines issued on October 15, calling for would-be suppliers to 5G network operators to submit a document self-declaring their trustworthiness, a similar sentiment to Huaweiโ€™s statement.

Equipment vendors, such as Huawei and ZTE, would produce the document confirming that they are not obliged to reveal personal data, equipment design, or any other critical information to third parties.

โ€œCertain telecommunications providers and network operators with increased risk potential may only use certain critical system components if they have been purchased from trusted sources,โ€ Michael Reifenberg, a representative for German regulatory office, the Federal Network Agency (FNA), told TechNode by email.

Reifenberg referred to the trustworthiness document as a โ€œno-spy declarationโ€ for dealings between equipment suppliers, such as Huawei, and network operators, such as Deutsche Telekom. Operators would then submit the declaration to the FNA. The document binds the supplier or manufacturer with the network operator in case of data breaches, meaning that they will bear joint liability in case of a leak.

โ€œIt is the weakest link in this entire document,โ€ said Jan-Peter Kleinhans, Project Director of Security and the Internet of Things at Stiftung Neue Verantwortung, a think-tank in Berlin. The certification will be based on technical standards, but the vendorsโ€™ declaration of trustworthiness โ€œis not double-checked by [cybersecurity agency] BSI , it is not evaluated. It is not enforced, there are no sanctions,โ€ he said.

โ€œDetails of the implementation are not yet specified,โ€ Reifenberg said. When a declaration is breached, the Agency โ€œmay give orders, take other measures to secure compliance and may set penalty paymentsโ€ on an ad hoc basis, he said.

The draft guidelines also provide for the certification of 5G network equipment, which will be issued by Germanyโ€™s cybersecurity authority, known as the Federal Office for Information Security.

Regulators have yet to decide whether the certification, based on an upcoming technical guideline, will be a mandatory process for suppliers.

Germany is one of many countries worldwide facing pressure from the US to exclude Chinese firms from the development of 5G networks. Washington claims that Chinese vendorsโ€™ have a close relationship with the government, which may force them to turn over critical information.

Back in May, US Secretary of State Mike Pompeo issued a veiled threat during an official visit to Berlin, saying there is โ€œa risk we will have to change our behavior in light of the fact that we canโ€™t permit data on private citizens or data on national security to go across networks that we donโ€™t have confidence (in).โ€

โ€˜Hostile third countriesโ€™

Days before Germany released the guidelines, the EU Commission released a risk assessment on 5G, warning โ€œhostile third countriesโ€ against colluding with 5G equipment vendors to conduct cyberattacks on member states. But the German agencies which drafted the security catalog are not trained to account for political risk, โ€œin the eyes of the BSI, the origin of the vendor doesnโ€™t matter,โ€ said Kleinhans.

EU report warns of 5G threat from โ€˜hostileโ€™ states

โ€œIn a way, you are asking the wrong question to the wrong person,โ€ he said. โ€œYou have two completely technocratic agencies that are very much focused on technical aspects, drafting a technical document, which suddenly the world and some Germans included, expect that will have geopolitical impact.โ€

This is in line with Angela Merkelโ€™s overall approach to the security of 5G, which has โ€œpushed the debate into the technical realm,โ€ Kleinhans said. Analysts say that Merkelโ€™s government is trying to protect Germanyโ€™s industrial prowess, which relies heavily on access to the Chinese market.

The guidelines have caused controversy within the German Parliament, not only because of the content. The draft neednโ€™t be voted on by parliamentarians before it is enacted, since it is not a new law but an updated version of technical guidelines created by the responsible agencies.

โ€œA question of such strategic meaning should not be being decided at the administrative level,โ€ said Norbert Rรถttgen, a member of Merkelโ€™s party, the Christian Democrats.

The draft will be open for public comment until 13 November 2019.

Eliza was TechNode's blockchain and fintech reporter until July 2021, when she moved to CoinDesk to cover crypto in Asia. Get in touch with her via email or Twitter.

Leave a comment

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.