
Security and Privacy in Telecommunications
Code: 45643Credits: 6
| Degree programme | Type | Course |
|---|---|---|
| Telecommunication Engineering | OB | 1 |
Contact lecturer
- Name :
- Angeles Vazquez Castro
- Email :
- angeles.vazquez@uab.cat
Group languages
You can consult this information at the end of the document.
Prerequisites
Students are expected to have prior knowledge of communication systems.
Objectives
This course addresses security and privacy in telecommunications from an engineering perspective. It covers the principles and methods used to identify security requirements, characterize threats, vulnerabilities and risks, and select appropriate security and privacy mechanisms. Students will study how information security, cryptography, cybersecurity and communication security influence the specification, design, integration, assessment and operation of secure telecommunication systems and services.
By the end of the course, students will be able to:
- Describe the main concepts of security and privacy in telecommunication systems.
- Identify security, privacy and resilience requirements and their main regulatory and standardization sources.
- Analyze threats, vulnerabilities and risks in communication systems and infrastructures.
- Compare and select cryptographic, cybersecurity and communication-security mechanisms for secure system design.
- Design telecommunication systems and services incorporating security, privacy and resilience requirements.
- Evaluate emerging security challenges, including AI, hybrid threats, and critical terrestrial and space-based infrastructures.
Learning outcomes
- (CA11) Apply security and privacy solutions in current and emerging mobile communications systems, guaranteeing the quality and efficiency of the service.
- (KA11) Relate the fundamental concepts of security and privacy to their application to telecommunications systems and networks, including evaluation metrics.
- (KA12) Identify the applicable legislative framework and its impact on the design and operation of telecommunications systems and networks.
- (SA17) Develop deep learning models to improve the performance and efficiency of mobile networks.
- (SA18) Ensure security and privacy in the process of developing, scaling, and maintaining telecommunications systems and networks.
- (SA19) Give information about the operation and organisation of the internet, as well as next-generation technologies and protocols, component models, middleware, and services.
Contents
CONCEPTUAL CONTENT
A. CONTEXT AND STRATEGIC FOUNDATIONS
A.1 Security concepts and taxonomy
A.2 Legal, regulatory and standardization context
A.3 Application example: communication systems for critical infrastructures
B. PILLARS OF SECURITY IN TELECOMMUNICATIONS
B.1 Information security and confidentiality in networks and systems
B.2 Classical cryptography for secure communications
B.3 Cybersecurity applied to networks
B.4 Privacy in telecommunication systems and services
C. PHYSICAL SECURITY AND RESILIENCE IN COMMUNICATION INFRASTRUCTURES
C.1 Physical threats to the transmission layer
C.2 Physical protection measures
C.3 Operational resilience
D. POST-QUANTUM CRYPTOGRAPHY (PQC) AND SECURITY FOR THE QUANTUM ERA
D.1 Quantum computing
D.2 Post-quantum cryptography (PQC) and elliptic-curve cryptography
D.3 Quantum cryptography
D.4 Migration strategies
E. FUNDAMENTALS OF SECURITY-BY-DESIGN IN COMMUNICATION SYSTEMS
E.1 Fundamentals of Security-by-Design
E.2 Identification of security, privacy and resilience requirements in communication systems
E.3 Translation of requirements into technical specifications and architectural design decisions
E.4 Threat modelling
E.5 Assessment, validation and evolution of security design
PRACTICAL CONTENT
The laboratory consists of a series of practical security challenges illustrating how telecommunication systems can be attacked, compromised and protected, including classical and quantum-resistant security scenarios (PQC and QKD). Students are organized into Red Team (offensive) and Blue Team (defensive) groups to analyze, exploit and protect telecommunication systems, while complying at all times with the applicable regulations. Activities include vulnerability assessment — both logical and physical, including side-channel attacks — attack simulation, and analysis of the most appropriate defensive measures in on-premise and cloud environments.
The laboratory places particular emphasis on ethical and professional responsibility, Security-by-Design, physical and logical resilience, and preparedness for the impact of quantum computing, preparing students to assess and design secure, robust and future-proof communication systems.
Learning activities and methodology
| Title | Hours | ECTS | Learning outcomes |
|---|---|---|---|
| Type: Autonomous | |||
| Individual work | 60 | 2.4 | CA11, KA11, KA12 |
| Type: Guided | |||
| Lectures | 30 | 1.2 | KA11, KA12, SA17, SA18, SA19 |
| Student office hours | 10 | 0.4 | CA11, KA11, KA12, SA17, SA18, SA19 |
| Type: Supervised | |||
| Laboratory Sessions | 15 | 0.6 | CA11, KA11, KA12 |
The teaching methodology for this course will consist of:
- Weekly two-hour sessions focused on conceptual content.
- Five project-based practical learning sessions.
The practical learning sessions will be compulsory and must be attended in person.
The UAB Virtual Campus (https://cv.uab.cat/) will be used as the platform for communication and teaching support.
The use of artificial intelligence tools will be permitted and recommended as a learning aid. However, teaching staff may, at random, ask individual oral questions without access to AI tools, in order to verify students’ understanding and authorship of the work submitted.
For the practical learning sessions, each team must have access to at least one personal laptop, as no equipment will be provided.
Note: 15 minutes of one class session, within the schedule established by the centre or degree programme, will be reserved for students to complete the teaching evaluation and course/module evaluation surveys.
Assessment
Continuous assessment activities
| Title | Weight | Hours | ECTS | Learning outcomes |
|---|---|---|---|---|
| Assignments and activities proposed during the conceptual sessions | 33 | 16 | 0.64 | CA11, KA11, KA12, SA18 |
| Questionnaire on the conceptual content | 33 | 3 | 0.12 | KA12, SA17, SA18, SA19 |
| Reports corresponding to the practical sessions | 34 | 16 | 0.64 | CA11, KA11, KA12, SA17, SA18, SA19 |
ASSESSMENT
Assessment in this course will be continuous and will consist of three activities:
- A. Comprehension questionnaire on the conceptual content — 33%
- B. Assignments and activities proposed during the conceptual sessions — 33%
- C. Reports corresponding to the practical sessions — 34%
The final grade will be calculated using the weighted average above, provided that the grade obtained in each of the three activities is at least 3.0 out of 10. If any activity receives a grade below 3.0, the weighted average will not be applied and the course cannot be passed by compensation with the other activities.
Assessment activities corresponding to component A will be individual. Activities corresponding to components B and C may be carried out in groups when indicated.
Late submissions
Submissions made after the deadline will incur a penalty of 20% of the grade for each day of delay.
Resit assessment
Students who have participated in at least two thirds of the assessment activities may be eligible for the resit process, provided that they have obtained a minimum final grade of 3.5.
The resit process will consist of:
- an additional test or questionnaire for component A;
- a new submission deadline for recoverable activities corresponding to component B and/or C.
No differentiated treatment is envisaged for students repeating the course.
Not assessable
The final grade will be recorded as “Not assessable” only when the student has not participated in the assessment process under the terms established by the current academic regulations.
Honours
An Honours distinction may be awarded to students who obtain a final grade of 9.0 or higher, also taking into account their active participation and overall performance in the course, within the limits established by current regulations.
ACADEMIC INTEGRITY
1. Academic irregularities
Without prejudice to any other disciplinary measures that may apply, and in accordance with the current academic regulations, any irregularity that may alter the grade of an assessed activity may result in a grade of 0 for that activity.
Activities graded in this way will not be recoverable.
Academic irregularities include, among others:
- copying all or part of a practical assignment, report, or other assessed activity;
- allowing another student to copy;
- submitting as one’s own work carried out wholly or partly by persons outside the group;
- presenting third-party materials as one’s own without appropriate attribution;
- using unauthorized resources, documentation, devices, or tools during an individual assessment;
- communicating with other students during an individual assessment when this is not permitted;
- copying or attempting to copy during an assessment.
2. Use of artificial intelligence tools
The use of artificial intelligence tools will be subject to the conditions established for each activity.
When their use is permitted, students remain responsible for the authorship, accuracy, quality, and justification of the work submitted, and must be able to explain and defend their results orally when requested by the teaching staff.
3. Oral verification
Teaching staff may carry out random individual oral verifications of submitted activities.
Students must demonstrate a sufficient level of understanding and an ability to justify the work submitted. If the verification is considered insufficient, the grade for the corresponding activity will be reduced by 50%.
4. Academic consequences
In the event of academic irregularities, the final grade will be limited in accordance with the current academic regulations, and the course cannot be passed by compensation.
In summary, copying, allowing others to copy, plagiarizing, or using unauthorized resources in an assessed activity may result in failure of that activity and, where applicable, failure of the course.
Bibliography
Basic bibliography
- Anderson, R. Security Engineering: A Guide to Building Dependable Distributed Systems, 3rd ed., Wiley, 2020/2021.
- Stallings, W. Cryptography and Network Security: Principles and Practice, 8th ed., Pearson, 2024.
- Kaufman, C.; Perlman, R.; Speciner, M.; Perlner, R. Network Security: Private Communication in a Public World, 3rd ed., Pearson, 2022.
Complementary bibliography
- Katz, J.; Lindell, Y. Introduction to Modern Cryptography, Revised 3rd ed., CRC Press, 2025.
- ITU-T. Security in Telecommunications and Information Technology, 8th ed., 2024.
Standards and reference material
Relevant standards, recommendations and technical reports from organizations such as ITU-T, ETSI, 3GPP, ISO/IEC, NIST, ENISA, and other regulatory and standardization bodies will be provided throughout the course.
Reference material may include documents on security architectures, Zero Trust, post-quantum cryptography, privacy, resilience, and the security of telecommunication networks and systems.
Software
Matlab, Python
Course groups and languages
The information provided is provisional until November 30. After this date, you will be able to consult the language of each group through this link. To access the information, you will need to enter the course CODE
| Type of teaching | Group | Language | Semester | Shift |
|---|---|---|---|---|
| (TEmRD) Teoria (màster RD) | 1 | English | second semester | afternoon |
| (PLABmRD) Pràctiques de laboratori (màster RD) | 1 | English | second semester | afternoon |