Valid

GB/T 42126.4-2026Industrial wireless communication specification based on cellular networks - Part 4: Security requirements (English PDF)

基于蜂窝网络的工业无线通信规范 第4部分:安全要求

Open the GB/T 42126.4-2026 preview as PDF

Preview — first pages of GB/T 42126.4-2026 (full document: 37 pages)

This is a limited preview

Buy now to download the full PDF (37 pages)

Issued by

SAMR; SAC

Level / Type

National · Recommended

Issue date

May 25, 2026

Implementation date

December 1, 2026

Scope

GB/T 42126.4-2026 is the English-translated version of 基于蜂窝网络的工业无线通信规范 第4部分:安全要求.

GB/T 42126.4-2026 is the Chinese national standard covering the security of industrial communication over a cellular network - the authentication of devices and of the network to them, the protection of the traffic, the isolation between the industrial slice and everything else, and the key management across thousands of long-lived devices. Part 4 of the series, first edition of this part, in force from 1 December 2026. It was issued on 25 May 2026 and takes effect on 1 December 2026, as a first edition. The document is under the responsibility of the China Machinery Industry Federation. This page is published from the official record of the 2026 edition; the clause text of a standard this recent is not yet in circulation, and the figures, limits and tables it contains are those of the document itself, delivered in full with the English translation.

Document preview — GB/T 42126.4-2026

National Standard of the People's Republic of China

ICS
25.040
Classification
N 10

Issued by: State Administration for Market Regulation; Standardization Administration of the PRC

Contents

  • 4 Safety Requirements
  • 5 Security Risk Analysis
  • 6 General Safety Design Requirements
  • 7 Safety Function Requirements
  • 7.1 Access Security
  • 7.2 Edge Security of Cellular Networks
  • 7.4 Cellular Network Capabilities. Open Security
  • 7.5 Data Security
  • 8 Deployment Requirements
  • 8.2 Management Requirements

Foreword

This document complies with the provisions of GB/T 1.1-2020 "Standardization Work Guidelines Part

1.Structure and Drafting Rules of Standardization Documents". Drafting. This document is Part 4 of GB/T 42126, "Industrial Wireless Communication Specifications Based on Cellular Networks". GB/T 42126 has been published. The following parts were included.

1.General Technical Requirements;

4.Safety Requirements;

5.Application Specifications;

6.Acceptance Specifications. Please note that some content in this document may involve patents. The issuing organization of this document assumes no responsibility for identifying patents. This document was proposed by the China Machinery Industry Federation. This document is under the jurisdiction of the National Technical Committee on Standardization of Industrial Process Measurement, Control and Automation (SAC/TC124). This document was drafted by: the Institute of Comprehensive Technical and Economic Research on Instrumentation and Meter of the Machinery Industry, Southeast University, and Fujian Shunchang Hongrun Precision Instruments Co., Ltd. The company, Beijing Institute of Printing, Guoneng Zhishen Control Technology Co., Ltd., Guoneng Jilin Longhua Thermal Power Co., Ltd. Jilin Thermal Power Plant, State Grid Liaoning Ningxia Electric Power Research Institute, Nanjing Shenye Intelligent Technology Co., Ltd., Huawei Technologies Co., Ltd., and Xi'an Huayun Zhilianxin Information Technology Co., Ltd., Hangzhou Meiyi Automation Technology Co., Ltd., Beijing University of Technology, Beijing Topsec Network Security Technology Co., Ltd. Company, Dalian University of Technology, China Academy of Information and Communications Technology, Shenyang University of Technology, Shenyang Huaruibo Information Technology Co., Ltd., Hebei University of Technology Northeastern University, Chongqing University of Posts and Telecommunications, North China Electric Power Research Institute Co., Ltd., Tianjin Xinhai Petroleum Engineering Technology Co., Ltd., Zhongyingqing Chuang Technology Co., Ltd., Guoneng Sichuan Tianming Power Generation Co., Ltd., Beijing Dingcheng Hongan Technology Development Co., Ltd., Shenzhen Maiteng Electronics Co., Ltd. The company, Beijing Guanyu Information Technology Co., Ltd., Ningbo City Vocational College, Taicang Tongwei Electronics Co., Ltd., Guizhou Open University Guizhou Vocational and Technical College, Beijing University of Posts and Telecommunications, Beijing Jinshui Information Technology Development Co., Ltd., Suzhou Future Network Research Institute Co., Ltd. Company, Yanchang Oilfield Co., Ltd., Beijing Baizhuo Network Technology Co., Ltd., Jiangsu Dongxu Communication Technology Co., Ltd., Hunan University of Science and Technology School, State Grid Liaoning Electric Power Co., Ltd. Information and Communication Branch, Rockwell Automation (China) Co., Ltd., Schneider Electric (China) Co., Ltd. Limited Company, State Grid Beijing Electric Power Research Institute, Fujian Shangrun Precision Instruments Co., Ltd., China Software Testing Center (Industrial and...) The Software and Integrated Circuit Promotion Center of the Ministry of Information Technology, Beijing Municipal Institute of Product Quality Supervision and Inspection, Liaoning Provincial Inspection and Testing Certification Center, and North China... Electric Power University. The main drafters of this document are. Shang Yujia, Lu Tielin, Mei Ke, Li Guyue, Chen Zhiyang, Liu Xiaojing, Zhai Wanbo, Li Tong, Zhang Linguang, and Liu Jinfeng. Guo Yanfei, Ren Zhigang, Ge Jian, Han Yuwei, Li Yong, Sui Tianju, Yang Hongmei, Zhang Xiaoling, Shao Hua, Liu Jing, Yao Yucai, Li Zhigang, Yao Yu, Wang Hao Zhu Junxin, Meng Fanhong, Xing Jitao, Yu Dapeng, Peng Xinyu, Cao Xianghui, Li Yifei, Huang Wei, Sun Yue, Kou Feng, Wan Xucheng, Ye Hongwu, Gu Pingping Ma Tingting, Kou Feifei, Li Guangqing, Zheng Zhanwei, Song Lin, Cheng Jixun, Zhu Jingling, Yang Chao, Gao Jingmei, Yan Xinhua, Wang Bao, Sun Feng, Li Zhuoqun Lin Renxiang, Guo Yongzhen, Yu Xuefei, Wei Wei, Hou Cong, Gong Gangjun.

Cellular wireless communication technology (hereinafter referred to as cellular network) has been continuously evolving and has now reached its fifth generation. Industrial wireless communication based on cellular networks... Communication systems (referred to as industrial cellular networks) are gradually meeting the application requirements of low latency, high bandwidth, wide connectivity, and flexible networking in industrial scenarios. For example, manufacturers can connect assets such as manufacturing equipment sensors, controllers, tools, and materials through industrial cellular networks, and can also share information. The system connects with equipment, providing all relevant parties with richer, more operable, traceable, and location-based information, thus helping industry move towards digitalization and informatization. And the transformation towards intelligence. With the continuous evolution of cellular network wireless communication technology, industrial cellular networks are facing challenges in bandwidth, latency, and availability. Continue to improve and empower more industrial application scenarios. GB/T 42126, "Industrial Wireless Communication Specification Based on Cellular Networks," is a fundamental standard guiding the application of cellular networks in industrial settings. To ensure that the industrial cellular network can adapt to the application needs of industrial scenarios, it is proposed to consist of 6 parts.

1.General Technical Requirements. The purpose is to establish general technical requirements applicable to various industrial sites.

2.Protocol Standards. The purpose is to establish communication protocol requirements applicable to industrial environments.

3.Test Specifications. The purpose is to establish industry-standard test specifications for communications.

4.Security Requirements. The purpose is to ensure the secure operation and management of cellular networks.

5.Application Requirements. The aim is to better apply cellular networks in industrial settings and facilitate widespread adoption by all stakeholders.

6.Acceptance Requirements. The purpose is to ensure that the cellular network, once established according to the requirements of GB/T 42126.1~GB/T 42126.5, meets the following standards. It meets the actual requirements of all relevant parties. Cellular network-based industrial wireless communication specifications Part

4 Safety Requirements

1.Scope This document specifies the security requirements for industrial wireless communication systems based on cellular networks, including security risk analysis and overall security design requirements. Requirements, security features, and deployment requirements. This document applies to industrial wireless communication systems based on cellular networks, especially 5G-related security planning, construction, operation management, and testing. Evaluate.

4.Abbreviations The following abbreviations apply to this document. AES. Advanced Encryption Standard AGV. Automated Guided Vehicle AKA. Authentication and Key Agreement AMF. Access and Mobility Management Function API. Application Programming Interface APP. Application AS. Access Layer AUSF. Authentication Server Function AUSF. Authentication Server Function CPE (Customer Premise Equipment) CPF. Control Plane Function DDoS. Distributed Denial of Service EMS. Energy Management System ERP. Enterprise Resource Planning FlexE. Flexible Ethernet gNB. Next Generation NodeB GNSS. Global Navigation Satellite System GPS. Global Positioning System HMI. Human Machine Interface HTTP Hypertext Transfer Protocol IPsec. Internet Protocol Security LIMS (Laboratory Information Management System) MEC. Multi-access Edge Computing MEP. Multi-access Edge Security Platform MES. Manufacturing Execution System NAS. Non-Access Stratum NEF. Network Exposure Function NF. Network Function NRF. Network Repository Function NSSAI. Network Slice Selection Assistance Information PCF. Policy Control Function PDU. Protocol Data Unit PLC. Programmable Logic Controller QMS. Quality Management System QoS. Quality of Service RAN. Radio Access Network RB. Resource Block SCADA. Supervisory Control and Data Acquisition System SLA. Service Level Agreement SMF. Session Management Function TLS. Transport Layer Security UDM. Unified Data Management UE. User Equipment UPF. User-Plane Function VLAN. Virtual Local Area Network VPN. Virtual Private Network WMS. Warehouse Management System 3GPP. 3rd Generation Partnership Project 5G. The Fifth Generation Mobile Communication Technology

5 Security Risk Analysis

5.1 Security Risks of Cellular Network Access Cellular network access introduces new risks to existing security systems. Figure 1 illustrates the risk points of cellular network access in industrial sites. As shown. Figure

1.Schematic diagram of risk points in industrial sites for cellular network access. In Figure 1, risk points can be divided into three categories.

---Risk Point A. The access point is outside the industrial site security boundary, and existing protective measures (such as firewalls) are effective;

---Risk Point B. The access point is located within the application domain security boundary, where existing protective measures are partially ineffective or introduce internal security risks;

---Risk Point C. The access point is within the security boundary of the control domain, and some of the original protective measures have failed, posing a direct security risk to the production equipment.

5.2 Other Risk Analysis The introduction of cellular networks should be analyzed to assess the additional security risks it poses to the control and application domains of industrial sites, including operational, economic, and health risks. Health, environment, and other factors are considered. Assessment principles and methods are detailed in IEC 62443 and GB/T 30976.1.

6 General Safety Design Requirements

6.1 Integration Requirements Cellular networks should be integrated with industrial communication network security through security measures such as authentication, data encryption, and data integrity protection to form a unified network. Unified security measures.

6.2 Functional Requirements Security requirements for cellular network access in industrial settings include access security, edge security, slicing security, capability exposure security, and data security. Requirements for transmission security and management safeguards, etc.

6.3 Safety Capability Allocation Requirements Based on the security risk analysis in Chapter 5, the security capabilities of the cellular network can be determined, and the specific requirements for allocation are as follows:

---If the analysis results are within an acceptable range, only the basic security functions of the cellular network may be retained;

---If the analysis results are within an unacceptable range, the security features of the cellular network should be enhanced to prevent the introduction of security threats. The cellular network must be able to meet the performance and quality requirements of industrial applications even with the required security features enabled. If this cannot be guaranteed... If necessary, some security functions should be disabled to prioritize the communication requirements of industrial applications, and compensation measures should be introduced.

7.1 Access Security

7.1.1 General Requirements When industrial field devices access the industrial field through the AS layer, NAS layer, and core network of a cellular network, the security function requirements are illustrated as follows: As shown in Figure 2, a specific operational plan example is provided in Appendix A, and its general requirements are as follows:

---Access authentication for cellular terminal devices should be supported;

---It is advisable to make dynamic judgments based on identity, permissions, trust level, and security policies. Figure

2.Schematic diagram of safety function requirements when industrial field equipment is connected.

7.1.2 Trusted Authentication When data is communicated between cellular networks and industrial communication networks, the specific requirements for trusted authentication are as follows:

---Develop corresponding access authentication policies on both the industrial communication network side and the cellular network side to ensure network access security;

---On the industrial communication network side, a trusted verification mechanism should be adopted to verify the trusted devices and users accessing the industrial communication network. Verification is required to ensure the authenticity and trustworthiness of devices and users accessing the industrial communication network;

---On the cellular network side, a network authentication mechanism should be used to verify the terminal's identity, see 3GPP TS

33.501 to determine whether the user is trusted. The authority is responsible for identifying or restricting the connection of unauthorized devices to the industrial network. Users should enhance the authentication of industrial field equipment through security authentication mechanisms, such as passwords, biometrics, or device hardware characteristics. Multi-factor authentication is performed to ensure reliable verification of the terminal's identity. An example of an authentication design based on the radio frequency fingerprint mechanism is shown in Appendix B.

7.1.3 AS Layer Signaling Security The AS layer exists only between industrial terminals and the industrial cellular access network, and is responsible for air interface access signaling and data security. AS layer signaling security The specific requirements are as follows:

---AS layer signaling confidentiality and integrity protection should be enabled for industrial cellular private network gNBs;

---Industrial cellular private network gNBs should support priority configuration of confidentiality and integrity protection algorithms;

---Industrial cellular private network gNBs should support detection and defense against wireless air interface DDoS attacks.

---Industrial cellular private network gNBs should reduce the risk of air interface interference through methods such as interference monitoring and interference cancellation;

7.2 Edge Security of Cellular Networks

7.2.1 Hardware Environment Security The specific requirements for hardware environment security are as follows:

---Electronic access control systems should be installed at the entrances and exits of the edge computing system server room to control, identify, and record personnel entering. Server racks should be equipped with power... The anti-tampering function should record and audit the opening and closing of the cabinet;

---MEC servers should be booted securely based on a hardware root of trust to ensure a secure boot chain and prevent backdoors from being implanted;

---The edge system should ensure that the data center environment always meets the equipment's operating requirements and that the power supply is redundantly designed to ensure system stability. run.

7.2.2 Virtualization Security When using virtualization technology in cellular network MEC, proper virtualization security measures should be implemented, including host machine security, image security, and virtual machine security. The specific requirements for mechanical safety and container safety are as follows:

---Stability and reliability of components such as host machines, virtual machines, containers, and images should be maintained; Resource isolation should be implemented between different virtual machines and containers, as well as with the host machine;

---Strict identity authentication and authorization management should be implemented for entities (users, processes, etc.) accessing the virtualized environment and components;

---The confidentiality and integrity of sensitive data (data in static storage or dynamic transmission) in the virtualization environment should be guaranteed.

7.3.3 Slice Access Control The specific requirements for slice access control are as follows:

---Terminal access request security should be supported to ensure that the UE can initiate slice requests according to the slices that the network allows to access;

---In-slice NF secure access control mechanism should be supported;

---Security domain partitioning should be supported, and security domains should be established between slice management domain, slice operation and maintenance domain, slice and enterprise campus, and slice and MEC. Implement isolation and access control measures.

7.3.4 Slice Identity Authentication The specific requirements for slice identity authentication are as follows:

---Should support protection against terminal NSSAI tampering attacks, unauthorized cross-slice access attacks by UEs, and cross-slice packet replay attacks by UEs. attack.

7.4 Cellular Network Capabilities. Open Security

7.4.1 Access Control Security isolation and access control measures should be configured between the capability open platform or capability open network element and the industry network.

7.4.2 Differentiation Mechanism A differentiated network capability opening mechanism should be established, which can provide differentiated cellular network capabilities to industry users based on the actual application scenario requirements. The specific requirements for granting permissions to capabilities (including security capabilities) are as follows: Open network resources should be allocated differently based on the importance and urgency of different industrial applications;

---It should support flexible access control, allowing authorized devices and users to access the cellular network under specific conditions;

---It is advisable to provide differentiated security protection based on the sensitivity of open data.

7.4.3 Interface Protection It should possess security protection capabilities for open interfaces of cellular network capabilities, and establish relevant security mechanisms and defenses for open interfaces of cellular network capabilities. Protective measures, such as API authentication, encrypted transmission, and log auditing.

7.5 Data Security

7.5.1 Access Authentication After the primary authentication performed when a user accesses the network, a secondary authentication mechanism should be adopted to establish a data channel for accessing specific services. as follows:

---Primary authentication should verify the identity and permissions of users and devices to ensure that only legitimate users can access the network;

---Based on primary authentication, a secondary authentication mechanism should be adopted to establish data channels for specific business access, ensuring business security and Isolation.

7.5.2 Access Control The principle of least privilege should be followed, assigning different data operation permissions to different users. Specific requirements are as follows:

---The principle of least privilege should be strictly followed, granting only the minimum set of permissions required for the business logic, and avoiding excessive granting of permissions;

---It is advisable to use a secondary authentication mechanism to grant specific permissions for application data;

---Strict permission boundaries should be set to ensure that access is only permitted to data resources and services within the authorized slice.

8 Deployment Requirements

8.1 General Requirements Cellular networks should adopt different network deployment schemes to meet different production and business needs, including at least. For enterprises that only require user plane security, it is advisable to move the core network user plane down to the factory area to achieve local business offloading. Access to the enterprise intranet ensures that business operations do not leave the factory area;

---For enterprises that require network control signaling to remain within the factory premises, it is advisable to dedicate the entire cellular core network, including the user plane and control plane, to a dedicated system. Network deployment;

---For secure transmission requirements between different domains or different services, it is advisable to ensure this through the deployment of security isolation measures such as data slicing;

---For security needs during autonomous operation and maintenance, it is advisable to deploy measures such as security status monitoring.

8.2 Management Requirements

8.2.1 Centralized Management and Control The specific requirements for centralized management and control are as follows:

---A separate security operation and maintenance area should be designated, a secure information transmission path should be established, and security devices in the network should be centrally managed;

---Monitor and issue alerts regarding the operational status of links, network devices, servers, and industrial field equipment;

---Centralized management of security policies, malicious code, and patch upgrades; effective identification, timely early warning, and dynamic monitoring of security incidents. Analysis reveals the overall network security situation.

8.2.2 Secure and Configurable The specific requirements for security and configurability are as follows:

---Authorized security administrators should be allowed to configure specific UEs via either the industrial network intranet or the cellular network. Safety rules;

--- Users with the appropriate permissions should be allowed to use additional security configuration features or specific security rules.

8.2.3 Security Operations and Maintenance Basic configuration information and updates related to industrial applications should be recorded and saved, including network topology and the software packages installed on each device. Version and patch information of components and software components, configuration parameters of each device or software component, etc.

8.2.4 Account Permission Management For industrial application-related management/operation systems, an account access control mechanism should be established, and a dedicated department or personnel should be designated to manage accounts. manage.

8.2.5 Emergency Response Mechanism Enterprises should develop contingency plans for different events such as cellular network outages in industrial applications, and establish corresponding emergency management teams and related resources. To prevent obstacles, regular emergency response training and drills should be conducted.

......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 37 pages — is available in the English PDF.

How to Buy GB/T 42126.4-2026

  1. 1Add to cart. Click the "Buy GB/T 42126.4-2026" button on this page. You can add more standards before checkout.
  2. 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
  3. 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
  4. 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.

Related Standards

English PDF
37 pages
Instant delivery (0–9 sec)
Invoice included
View Cart

Secure payment via Stripe

Payments accepted

VisaMastercardAmerican ExpressApple PayGoogle PayStripe

GB/T 42126.4-2026

$305.00

$260.00for partners