A different future for telecoms in the UK

Semiconductors form the beating heart of modern life.
At one end of complexity and scale, you've got massive power control transistors in factories that control huge amounts of electrical power. At the other, you have the elegant and complex chips that form the brains of our smartphones, each with 5 billion transistors individually switching tiny amounts of electricity on and off very quickly and all working together in a complex electronic dance to power our daily lives.
Chips with everything
Chips are hard to design. That complex dance requires things across the chip to be synchronised to within a few tens of picoseconds. In order to build reliable and predictable chips, you need complex and capable design and simulation tools (called Electronic Design Automation [EDA] tools), that can help you understand how the chip will behave before it’s built. And that’s because making a chip is really complex and expensive. The number of transistors you can get on a chip is - obviously - related to their size, and that’s related to the ‘process node’ used to manufacture the chip. The most modern process nodes are called the 5nm and 7nm nodes. That doesn’t mean that each transistor is 5nm or 7nm across, but you do get around 100 million transistors per mm2 on a 7nm node, and between 150 and 200 million on a 5nm node.
Making things this small that work reliably is hard, and needs some proper physics wrangling. And that physics wrangling has some pretty hard rules that have to be met by the design tools. It’s also true that these tiny little transistors are quite vulnerable to random errors, being affected by - for example - alpha particles and cosmic rays. So the design of the chip has to understand how the manufacturing process works to cope with these errors, through error correction circuitry and the like. The characteristics of the manufacture and the design tools go hand in hand.
Most modern telecoms infrastructure relies on custom chips to make it work. Whether that’s the complex signal processing chip in a 5G radio to allow it to serve more devices while using less power, or the processor complex in the exchange equipment that provides your home broadband, the telecoms industry relies on chips. Lots and lots of chips. Some manufacturers get their competitive edge by designing and building their own custom chips for their kit. That includes Huawei.
Export control rules
In May, the US changed a subtle and detailed export control rule called the ‘Foreign-Produced Direct Product Rule’ (FDPR).
The amended rule says that no-one, anywhere in the world, can send Huawei-designed chips to Huawei if US technology was used in the design tools or manufacture processes. This doesn’t just mean that Huawei can’t use design tools that contain US technology. It also means:
- no-one else can take a Huawei design and turn it into chip manufacture instructions (usually something called a GDS2) using tools that contain US technology
- even if you’ve already got the GDS2 for a Huawei chip, you can’t actually turn it into a chip if your foundry process uses US technology (and for modern process nodes, US technology is pretty pervasive) or if the GDS2 was produced using US technology
Back in January, I wrote a blog outlining the government’s decision on the use of High Risk Vendors (HRVs) in the UK telecoms infrastructure. It was widely reported as ‘the Huawei decision’, but it’s important to remember that there were two parts to the decision; a generic policy around HRVs (of which Huawei is one, but not the only one), and a vendor specific mitigation strategy for each HRV (including one for Huawei). As ever, the NCSC's role was to provide unbiased, timely, expert technical analysis into a very complex policy area, based on evidence and the facts available at the time. That led to a particular view on the future of telecoms in the UK as outlined in the blog. Recent events have changed that future.
The FDPR change wasn’t in effect in January. It is now, and that’s a material change to the facts on the ground that has led us to revisit our analysis. The NCSC now believes that there are only three things that can happen to help Huawei in response to this action. In our recent consultations with them, Huawei haven’t disagreed with this analysis. Those options are:
- Someone breaks US law and continue to manufacture. This is pretty unlikely. Huawei have always publicly said that they’ll follow applicable law, but the impact on any design house or foundry that went this way would be huge. Also - given there’d be a reasonable expectation that the chips broke US law - any organisation buying the equipment would be taking a significant risk.
- Huawei switch chips in equipment designs to ones that aren’t Huawei-designed, but perform the same sort of function. This is a big task. Assuming you can find someone to design a chip that’s near enough to the original, the integration into the wider product is a very complex job. This can’t be a direct replacement for a Huawei-designed chip, because then at least some of the design will be Huawei’s, and so likely caught by the rule. This is a really complex engineering task. And given Huawei’s continued lack of security or engineering quality as described in the Oversight Board reports, this is highly likely to introduce security and reliability problems into the equipment for the next few years at least.
- Someone makes new design tools and manufacturing processes for chips that don’t use any US technology and so can provide Huawei what they need. Good luck doing that quickly. You need to invent some new ways of doing really complex things (extreme UV lithography, multi-patterning etc.) while being bound by the laws of physics. The precise mechanisms the foundry uses to make these tiny transistors dictate the design rules your EDA tools have to enforce. As a cartoon example, if the foundry process produces some fuzziness around the edges of transistors, your design tool will need to leave more space between them, or the performance of the chip could be affected. The performance and capability of your EDA tools dictate what the foundry can build reliably. If your EDA tools can't do lots of Maxwell's equation solving, you'll need to route wires differently round the chip and simplify your design. You don’t need to understand how a FinFET works or what a hi-K dielectric is to know that’s a ton of work that’s likely to fail a few times.
So, it seems that Huawei’s long term ability to build products using state-of-the-art technology has been severely affected. Huawei claims to have stockpiles of parts that they can use, but this obviously affects what the NCSC can say about their products going forward. We think that Huawei products that are adapted to cope with the FDPR change are likely to suffer more security and reliability problems because of the massive engineering challenge ahead of them, and it will be harder for us to be confident in their use within our mitigation strategy.
The future of telecoms network builds
Assuming Huawei can adapt over the next couple of years, these changes have serious implications for the NCSC's mitigation strategy, including the work HCSEC1 (also known as 'the Cell') does. HCSEC works hard to provide the NCSC and UK operators with technical information to help with our risk management.
We believe that it will be much harder to get the same level of information and confidence for new Huawei products in the future. Also, there will be lots of work to understand new toolchains that will be replacing the well-understood, global ones in use today. So, each product will take much more effort to analyse, and HCSEC won’t be able to look at as many products in the same depth as it does today. The details are in the summary analysis.
Today, we are publishing guidance, supported by government, as to what this all means for the future telecoms network builds and to help operators understand the impacts of this decision. The guidance says that:
- existing Huawei equipment in the UK can continue to be used, subject to the HRV policy and our mitigation strategy
- operators need to procure enough spares to maintain the equipment for the expected lifetime
- operators should seek to cease procuring and deploying Huawei 5G access equipment, all transport equipment, and other miscellany to manage the long-term risks of the newly designed products (practically, procurements are likely to cease by the end of 2020)
- operators should seek to cease procuring and deploying Huawei FTTP (Fibre to the Premises) access equipment. It may take a bit longer for rollouts to cease in this case, so DCMS are going to work with industry to establish a manageable timeframe2
This is a change to the Huawei mitigation strategy, rather than the HRV policy. When the Telecoms Security Bill comes into force, there will be a clear framework for handling issues like this. This is complex stuff that has many subtleties and nuances. Huawei may find ways around parts of the US restrictions, and the US may choose to make those restrictions more or less, well, restrictive.
As each significant change in the facts occurs, the NCSC will have to re-examine the impact. The telecoms sector has very long planning cycles and those plans demand certainty. One thing that is clear is that Huawei's equipment supply, security and resilience - and the concomitant impact that new equipment could have on the networks - will likely be very uncertain for the next few years.
The FDPR amendment will cause a significant shift in the global telecoms supply chain that will be felt for years. That makes the diversification strategy announced in July 2019 even more important. DCMS has been leading HMG work to define this strategy and more details should be coming out soon. But it’s clear that this work has become harder at a time when it’s needed most.
Providing resilient and secure national scale telecoms systems is a complex task, and soundbites hardly ever apply. The decision today is necessary for the long-term security and resilience of the UK networks, but comes with significant risks and costs. The long-term health and diversity of supply in the telecoms sector is a critical issue for all, and it will take concerted, sustained, international effort to fix it.
Ian Levy, Technical Director, NCSC
(1) Huawei Cyber Security Evaluation Centre (HCSEC). HCSEC is a security team, overseen and directed by the NCSC, which analyses Huawei products and provides information to operators to help them with their risk management of their use of Huawei. It's part of the overall mitigation strategy for Huawei in the UK.
(2) There will be a DCMS-led consultation with operators on a possible short transition period if necessary because there is only one other scale vendor in this sector. As we've said before, over-reliance on any vendor is bad from a security and resiliency point of view.

