欧洲基础设施依赖中国技术会带来风险,但并非每个国家都认真对待这一点。英国皇家联合军种研究所(RUSI)表示,欧盟需要做得更好,帮助成员国评估风险并采取适当行动,以保障整个欧盟的安全。
Depending on Chinese technology for European infrastructure poses risks that not every country takes seriously. So says the Royal United Services Institute (RUSI), which suggests that the EU needs to do better in helping members assess the risk and take appropriate action to safeguard the entire bloc.
这家总部位于英国的智库在今天发布的一份报告中表示,欧盟应制定一套适用于所有成员国的新风险评估框架,在加强自身权力的同时,不侵犯成员国自行制定国家安全政策的权利。欧盟必须在保障联盟安全的需要与保持灵活性之间谨慎取得平衡,既要让成员国能够制定国内政策,也要让立法者能够考虑不同部门之间的风险差异。电信领域面临的风险未必会以相同方式适用于其他行业。
The UK-based think tank said in a report today that the EU should develop a new risk assessment framework that applies to all members and strengthens its own powers, without encroaching on members’ rights to set their own national security policies. It must delicately balance the need to secure the union, while maintaining the flexibility that both allows members to set domestic policies and lawmakers to account for different risk profiles across different sectors. The risks affecting telecoms will not necessarily apply to other sectors in the same way.
说到电信,目前只有自愿性的“欧盟5G安全工具箱”框架——这里的关键在于“自愿”,因为自该框架于2020年1月启动以来,27个成员国中只有10个全面落实了相关措施。从纸面上看,它在一定程度上试图实现RUSI所呼吁的目标:制定一套协调一致的标准,以减轻影响成员国的5G相关安全风险。
Speaking of telecoms, currently there is only the voluntary EU Toolbox for 5G Security framework – voluntary being the operative word here, as only 10 of 27 members have fully implemented it since it launched in January 2020. On paper, it somewhat sets out to achieve what RUSI is calling for: a harmonized set of standards to mitigate 5G-related security risks affecting member states.
针对该框架采纳不足的问题,欧盟委员会今年早些时候提出对《网络安全法》(CSA)进行修订,建议允许其建立一份不受信任供应商名单,成员国必须将名单上的供应商排除在18个关键部门的网络之外。如果修正案获得通过,任何使用指定供应商设备的国家都将被迫在36个月内拆除并更换这些设备。欧盟委员会已经表示,如果修正案通过,将建议将华为和中兴列为不受信任供应商。
Addressing the frustration over the lack of adoption, the European Commission proposed amendments to the Cyber Security Act (CSA) earlier this year that would allow it to build a list of untrusted vendors that members must preclude from the networks of 18 critical sectors. If passed, any countries using equipment from designated vendors would be forced to rip and replace it within 36 months. The EC has already indicated that it would suggest Huawei and ZTE be listed, should the amendments pass.
不过,在欧盟忙于列出其认为的高风险供应商之前,首先需要明确高风险供应商究竟是什么。
But before the EU gets busy listing vendors it considers high-risk, it first needs to decide what a high-risk vendor even is.
目前,对于这类技术仍没有官方的明确定义,也没有相应的法律分类;因此各国可以灵活运用这些规定来购买自己想要的技术,从而规避《通信安全法》(CSA)修正案可能带来的审查。RUSI的研究人员以德国、西班牙和英国为例,说明了这三个国家在对待华为、中兴等外国技术供应商时的不同态度。德国最重要的贸易伙伴是中国,两国每年的贸易额高达2518亿欧元(2844亿美元);从历史上看,德国政府一直倾向于维护这些重要的经济关系,而非降低供应链风险。
There is still no official definition, nor is it a legal category, and at present, it allows countries to wangle their way around these descriptions to buy the tech they want, bypassing whatever scrutiny may come their way should the CSA amendments come into force. RUSI’s researchers used Germany, Spain, and the UK as examples of how three countries can treat foreign tech vendors, such as Huawei and ZTE, very differently. Germany’s most important trading partner is China, a relationship worth €251.8 billion ($284.4 billion) annually, and historically the Bund has opted to preserve these valuable economic ties in favor of reducing supply chain risk.
然而在弗里德里希·默尔茨总理的领导下,这种情况正在逐渐发生变化。据估计,2024年中国供应商在德国5G网络建设中的份额约为59%。在西班牙,2024年中国设备在5G网络建设中的份额约为32%,但这一比例预计会下降。去年的争议事件进一步加剧了这场争论——当时西班牙授予华为一项涉及存储司法监听记录的合同。
Under Chancellor Friedrich Merz, this is slowly changing, although RUSI does not expect to see a material shift in the makeup of Germany’s 5G RAN stack in the near future. Chinese suppliers accounted for an estimated 59 percent of the country’s 5G RAN in 2024. Chinese equipment accounted for an estimated 32 percent of Spain’s 5G RAN in 2024, although that share is expected to shrink. The debate intensified after last year’s controversy, when Spain awarded Huawei a contract involving the storage of judicial wiretap recordings.
西班牙过去的采购决策通常倾向于选择最具成本效益的供应商;其政府对中国的国家安全担忧程度远低于英国或美国。相比之下,英国计划在未来年底前彻底将中国技术从本国电信网络中清除,并完全屈从于美国的压力,认为华为对西方地缘政治安全构成威胁。RUSI指出,对 Chinese IT 供应商的担忧“是有根据的”,并且中国政府确实有能力迫使相关机构对华为等企业实施控制。
Spain’s past procurement decisions have shown it to often favor the most cost-effective option, and its government does not share the same national security concerns about China as the UK or US, or at least not to the same degree. The UK, meanwhile, looks set to completely eradicate Chinese technology from its telecoms network by the end of next year, and has bent to the US’ vehement demands that Huawei is bad, bad news for Western geopolitical security. Real security risks RUSI stated that concerns about Chinese IT vendors “are well-founded,” and that it is true that the Chinese government can empower authorities to exercise control over companies like Huawei.
这包括应要求向国家提供数据、接待中国共产党(CCP)代表,以及报告预示着国家安全威胁的活动。
This includes providing the state with data on demand, hosting Chinese Communist Party (CCP) representatives, and reporting activity that signals a threat to national security.
还有一项额外的法律要求科技公司不仅要在发现漏洞后48小时内向该国政府报告,还要对中国的海外对应机构隐瞒相同的披露信息,产品供应商除外。
There is an additional law that requires tech companies to not just report vulnerabilities to the country’s government within 48 hours of discovery, but also to withhold the same disclosure from China’s overseas counterparts, except for the product vendor.
皇家联合军种研究所(RUSI)表示:“这将中国私营部门的安全研究转变为一个国家控制的渠道,授予情报机构对可利用漏洞的优先早期访问权。”
“This converts China’s private sector security research into a state-controlled pipeline that grants intelligence services privileged early access to exploitable vulnerabilities,” RUSI said.
根据皇家联合军种研究所的说法,考虑到所有这些因素,该国还展示了对政治对手的关键国家基础设施发动网络攻击的意愿和能力。抛开技术安全不谈,中国的技术进步也带来了经济风险。
Factoring in all of this, the country has also demonstrated the willingness and capability to launch cyberattacks against the critical national infrastructure of political adversaries, according to RUSI. Technical security aside, China’s technological advancements introduce economic risks, too.
在某些情况下,其供应商开发出的产品比欧盟或美国的同类产品更强大,且以更具吸引力的价格出售。
In some cases, its vendors have developed more capable products than equivalents in the EU or US, and sold them at more attractive prices.
这种优势使得一些国家难以证明在非中国设备上额外支出的合理性。
This advantage makes it difficult for some countries to justify the extra expense on non-Chinese equipment.
皇家联合军种研究所指出,通过建立全球对其产品的依赖,中国随后可能引入“不受欢迎的依赖”,或将自己巩固为关键供应链中的主导参与者。
In building a global reliance on its products, China could then introduce “unwelcome dependencies,” or cement itself as a dominant player in crucial supply chains, RUSI noted.
中国近年来已表明愿意行使这种影响力,例如在2019年激烈的5G辩论期间,它曾威胁德国将对两国经济关系产生“后果”。高风险指定制度行得通吗?
China has shown in recent years that it is willing to exercise this influence, such as when it threatened Germany with “consequences” for the two countries’ economic ties during the heated 5G debate of 2019. Would a high-risk designation system work?
该智库呼吁欧盟建立一个更审慎的风险评估框架的原因之一是,无法保证欧盟委员会目前在其《网络安全法》(CSA)修正案中提出的措施会产生多大效果。
One of the reasons why the think tank is calling for a more considered risk assessment framework for the EU is that there is no guarantee that what the EC is currently proposing in its CSA amendments will have much of an effect.
对公司或国家实施全面禁令,并不能明确解决导致产品易受攻击的根本安全问题。
Issuing blanket bans on companies, or countries, does not explicitly address the underlying security issues that make products vulnerable to attack.
换言之,即便将中国完全排除在欧盟成员国的技术栈之外,来自“可信任”国家的其他供应商已证明其无法交付无懈可击的软件,这无论如何都会为攻击敞开大门。请记住,盐台风(Salt Typhoon)对美国电信网络的高调攻击发生在2024年。还应指出,类似CSA(网络安全法案)的认定也可能适用于美国公司,因为欧洲一些国家认为美国供应商同样存在风险,尽管理由不同。
In other words, even if China were excluded entirely from the EU members’ tech stacks, the other vendors from ‘trusted’ countries have proved that they are unable to deliver penetration-proof software, which would open the door to attacks regardless. Remember, Salt Typhoon’s high-profile attack on US telco networks took place as recently as 2024. It should also be said that CSA-esque designations could apply to US companies, as some countries in Europe see US vendors as similarly risky, albeit for different reasons.
例如,默茨领导的德国担忧美欧关系,针对中国技术依赖的类似担忧若关系恶化,极易被套用到美国供应商身上。在西班牙,美国云服务公司占据主导地位,但反美情绪比许多人意识到的更强烈,尤其是围绕监控担忧。这些因素加上部分非中国供应商的较高报价,降低了西班牙拆除他国视为高风险设备的意愿。“一位参与者甚至指出,一些官员认为美国《爱国者法》等法律工具造成的主权风险等同于中国《国家情报法》,这种说法在法律层面站不住脚,但在政治上却颇为方便,”英国皇家联合军种研究所(RUSI)指出。
Merz’s Germany is concerned about the relationship between the US and EU, for example, and similar concerns about dependence on Chinese technology could easily be applied to vendors in the US, should relations sour. In Spain, US cloud companies dominate, but anti-US sentiment is stronger than many realize, particularly around surveillance concerns. Those, along with higher prices from some non-Chinese suppliers, have reduced Spain’s appetite for ripping out equipment others deem high-risk. “One participant even noted that some officials view US legal instruments such as the Patriot Act as creating equivalent sovereignty risks to China’s National Intelligence Law, a narrative that is flawed when exploring the legislation, but politically convenient,” RUSI stated.
该智库建议,若欧盟欲通过政策推动变革,必须鼓起“更大的经济勇气”,并愿意将技术采购视为保障关键基础设施安全的手段,而非单纯的“合规练习”。®
The think tank suggested that if it wishes to enact change through policy, the EU must gather “greater economic courage” and a willingness to approach tech procurement as a means to secure its critical infrastructure, rather than “a compliance exercise.” ®