• Latest
  • Trending
  • All
Huawei controversy shows US need for robust supply chain security strategy

Huawei controversy shows US need for robust supply chain security strategy

November 26, 2019
Last Mile Delivery Market Worth Observing Growth | UPS, FedEx, SF Express

Last Mile Delivery Market Worth Observing Growth | UPS, FedEx, SF Express

April 23, 2024
Top 5 Spend Analysis Software ranked in 2024

Top 5 Spend Analysis Software ranked in 2024

March 1, 2024
How Tesla And BMW Are Leading A Supply Chain Renaissance With Blockchain

How Tesla And BMW Are Leading A Supply Chain Renaissance With Blockchain

January 19, 2024
LATAM Cargo strengthens European cargo links

LATAM Cargo strengthens European cargo links

April 14, 2020
Ford making reusable hospital gowns from airbag materials as efforts against coronavirus expand

Ford making reusable hospital gowns from airbag materials as efforts against coronavirus expand

April 14, 2020
Don’t Sweat NBC’s Decision to Cut Back on Television Ad Inventory

Don’t Sweat NBC’s Decision to Cut Back on Television Ad Inventory

April 14, 2020
Software firms sharpen focus on AI, big data as IT spending drops

Software firms sharpen focus on AI, big data as IT spending drops

April 14, 2020
Navigating turbulent times in your supply chain (TL:DR version)

Navigating turbulent times in your supply chain (TL:DR version)

April 14, 2020
Last Mile Delivery by Drones Market is Booming Worldwide

Last Mile Delivery by Drones Market is Booming Worldwide

April 14, 2020
AIR CARGO MARKET SIZE, SHARE, DEMAND, TREND, LATEST INNOVATIONS & APPLICATION ANALYSIS AND INDUSTRY GROWTH FORECAST 2027 – Science In Me

AIR CARGO MARKET SIZE, SHARE, DEMAND, TREND, LATEST INNOVATIONS & APPLICATION ANALYSIS AND INDUSTRY GROWTH FORECAST 2027 – Science In Me

April 14, 2020
Wheat procurement in Patiala: 6,500 coupons issued to farmers – cities

Wheat procurement in Patiala: 6,500 coupons issued to farmers – cities

April 14, 2020
Pandemic, Plastics And The Continuing Quest For Sustainability

Pandemic, Plastics And The Continuing Quest For Sustainability

April 14, 2020
  • Supply Chain
  • Logistics
  • Warehousing
  • Procurement
  • Shipping
  • More
    • Strategic Sourcing
    • Spend Analysis
    • Inventory
    • Contact Us
No Result
View All Result
United States International Supply Chain Commission
United States International Supply Chain Commission
Home Supply Chain

Huawei controversy shows US need for robust supply chain security strategy

by usiscc
November 26, 2019
in Supply Chain
0
Huawei controversy shows US need for robust supply chain security strategy
492
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter

5G technology, through enabling greater digital connectivity at faster speeds, promises to revolutionize everything from smart city internet of things devices to self-driving car communication. And as with any new technology, there are notable cybersecurity threats to be addressed. This includes some of the risks underscored by U.S. government concern about Chinese telecommunications company Huawei, a privately owned but state-subsidized firm that is widely considered to be a global leader in providing 5G technology.

There are real national security and cybersecurity risks presented by 5G technology in general, and in particular with respect to Huawei’s 5G technology. But the U.S. government’s mishandling of these risks and the diplomatic messaging around them underscores something much bigger than Huawei, and something much bigger than 5G: the need for the United States to develop a better supply chain cybersecurity strategy in our increasingly data-driven world.

Huawei’s 5G technology poses national security risks, as does its potential global market dominance in this space. The United Kingdom’s Huawei Cyber Security Evaluation Centre has found Huawei code to be extremely buggy, as have other analyses of Huawei systems. And Nicholas Weaver has argued these vulnerabilities are in fact the “dirty secret” of most computing infrastructure and are not unique to Huawei. However, not every vulnerability is a backdoor — this fact has been missed or misunderstood in commentary about Huawei 5G cybersecurity and adds to the complexity of understanding this technology in which the United States is not dominant.

Some vulnerabilities are just vulnerabilities, there accidentally as a result of human error in the coding process. Other vulnerabilities could theoretically be bugdoors, meaning vulnerabilities that a government finds already there and tells the company to leave in place for exploitation; and others yet could theoretically be backdoors, where the government deliberately plants a hole to be exploited. But without publicly shared evidence of intent, it is difficult to know that any security holes in Huawei systems are bugdoors or backdoors.

Beyond cybersecurity risks with Huawei’s 5G software and hardware itself, there are also national security risks, as in many cases, with incorporating Huawei’s telecommunications equipment into American infrastructure. For instance, during a crisis scenario, it’s possible that Beijing could turn to Huawei to hand over data, provide access to foreign 5G systems, manipulate foreign 5G systems, or even shut down foreign 5G systems entirely. It is not unheard of for governments, including Beijing and others, to leverage the resources of telecoms incorporated within their borders during times of crisis. Many have argued that China’s weaker rule of law, and thus weaker checks and balances on such government powers, make it more likely the government could exert such influence.

All of this said, the U.S. government has blended discussion of national security concerns around Huawei, like Chinese espionage, with economic concerns about Huawei’s global market dominance. In light of the fact that neither the United States nor its European allies have any companies that can seriously compete with Huawei in 5G — at least across the entire “tech stack,” from 5G smartphones to 5G radio towers, all of which Huawei produces — many countries have understandable reservations that the U.S. position is not about real cybersecurity risks, but is in fact about using Huawei as political leverage in the ongoing trade war. Australia and New Zealand have banned Huawei from their 5G systems, but Canada and India, among others, have not and continue to send mixed messages.

This mishandling of the policy around and communication of Huawei 5G risks underscores the United States’ much broader need to rethink, and redevelop, a better supply chain security strategy in an increasingly data-driven age. While supply chain security questions aren’t new, notable changes over the last several years explain why the international context has changed.

The global internet has broader and deeper reach today than it did a decade ago, and the world is more digitally and economically interconnected. Consumer products like the iPhone, for example, contain hardware and software from many different countries. Moreover, software is increasingly running the hardware of our lives. With 5G, for instance, more computing is moving to the “edge,” meaning functions that were previously less software-driven in 4G systems will be increasingly software-driven in 5G counterparts. Global contestation over data access and exploitation is also intensifying, as more countries seek to regulate access to and derive value from data that powers technologies like machine learning.

Know all the coolest acronyms
Sign up for the C4ISRNET newsletter about future battlefield technologies.

Enter a valid email address

Thanks for signing up!

By giving us your email, you are opting in to the C4ISRNET Daily Brief.

C4ISRNET Logo

With all of this comes greater concern about supply chain cybersecurity in the modern age, particularly when it comes to software that could be remotely accessed and updated and could thus leave systems and data vulnerable. In 2017, for instance, the U.S. government banned the software produced by Russian antivirus company Kaspersky Labs from use on federal government systems. Russia itself is pushing for greater software independence from the West. The European Union’s executive branch, meanwhile, recently circulated an internal policy document outlining a proposal for “technological sovereignty” that would essentially work to reduce E.U. reliance on software and hardware manufactured abroad.

Many countries are concerned about supply chain cybersecurity. The contention about Huawei in particular highlights this problem in the United States, where the government has not established clear and objective criteria by which to evaluate the security of digital systems made abroad. The United States has talked about Huawei’s security risks while blurring them with economic risks; American officials, despite claiming they have evidence to this end, have also yet to publicly release information that indicates Huawei is a security threat. Several U.S.-incorporated companies say this data has not been provided privately by the government either.

Currently, an approach that deems literally every Chinese technology company an inherent national security threat is overly sweeping and questionable at best, including because it would be undesirable and difficult to “decouple” two digital economies that are so greatly intertwined. The Kaspersky case also provides an interesting example of how foreign-based software was deemed a national security threat through a process that could be described as less than transparent.

What the United States needs instead is a clear strategy and plan to help manage the relationship between national security and modern economic risks in supply chain management, particularly related to digital infrastructure. The U.S. government should establish, in cooperation with industry, academic experts, and global partners, consensus “objective” criteria by which to evaluate levels of trust in both hardware and software products developed and/or maintained by foreign-incorporated companies. For instance, should other countries replicate a United Kingdom-style vulnerability assessment on telecommunications equipment?

What about something similar on the legal side? Germany’s foreign minister has discussed evaluating if a company would be compelled by law to pass sensitive data to a government. And what about establishing standard technical and policy mitigation options through similar mechanisms? For example, are there cases in which encrypting communications on a network would shield user data from a 5G supplier, or does that not matter if the supplier can remotely apply patches?

As the world becomes increasingly software-driven, and as the global digital supply chain becomes more interconnected, the U.S. needs an established and repeatable process to handle and communicate supply chain security risks. For the case of Huawei’s 5G technology and American messaging and policy around it may not exactly be a precedent the U.S. wants to set.

Justin Sherman is a cybersecurity policy fellow at public policy think tank New America.

Share197Tweet123
usiscc

usiscc

  • Trending
  • Comments
  • Latest
Escape From Tarkov – How to Rotate Items

Escape From Tarkov – How to Rotate Items

February 5, 2020
Supply chain examination: Planning for vulnerabilities you can’t control

Supply chain examination: Planning for vulnerabilities you can’t control

December 7, 2019
Procurement Project Manager job with Camden London Borough Council

Procurement Project Manager job with Camden London Borough Council

February 17, 2020
Art Battle Wichita Falls III at The Warehouse, 1401 Lamar.

Art Battle Wichita Falls III at The Warehouse, 1401 Lamar.

0
Global Industry Analysis, Size, Share, Growth, Trends, and Forecasts 2016–2024 – ZMR News Reports

Global Industry Analysis, Size, Share, Growth, Trends, and Forecasts 2016–2024 – ZMR News Reports

0
PHOTOS: Ottawa firefighters respond to warehouse fire

PHOTOS: Ottawa firefighters respond to warehouse fire

0
Last Mile Delivery Market Worth Observing Growth | UPS, FedEx, SF Express

Last Mile Delivery Market Worth Observing Growth | UPS, FedEx, SF Express

April 23, 2024
Top 5 Spend Analysis Software ranked in 2024

Top 5 Spend Analysis Software ranked in 2024

March 1, 2024
How Tesla And BMW Are Leading A Supply Chain Renaissance With Blockchain

How Tesla And BMW Are Leading A Supply Chain Renaissance With Blockchain

January 19, 2024
  • Privacy Policy
  • Terms of Use
  • Disclaimer
  • DMCA
  • Contact Us

Copyright © 2024 United States International Supply Chain Commission (usiscc.org)

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled

Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.

Non-necessary

Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.

SAVE & ACCEPT
No Result
View All Result
  • Supply Chain
  • Logistics
  • Warehousing
  • Procurement
  • Shipping
  • More
    • Strategic Sourcing
    • Spend Analysis
    • Inventory
    • Contact Us

Copyright © 2024 United States International Supply Chain Commission (usiscc.org)