Defeating the downgrade attack on identity privacy in 5G

Mohsin Khan*, Philip Ginzboorg, Kimmo Järvinen, Valtteri Niemi

*Tämän työn vastaava kirjoittaja

    Tutkimustuotos: Artikkeli kirjassa/konferenssijulkaisussaConference article in proceedingsScientificvertaisarvioitu

    16 Sitaatiot (Scopus)
    265 Lataukset (Pure)

    Abstrakti

    3GPP Release 15, the first 5G standard, includes protection of user identity privacy against IMSI catchers. These protection mechanisms are based on public key encryption. Despite this protection, IMSI catching is still possible in LTE networks which opens the possibility of a downgrade attack on user identity privacy, where a fake LTE base station obtains the identity of a 5G user equipment. We propose (i) to use an existing pseudonym-based solution to protect user identity privacy of 5G user equipment against IMSI catchers in LTE and (ii) to include a mechanism for updating LTE pseudonyms in the public key encryption based 5G identity privacy procedure. The latter helps to recover from a loss of synchronization of LTE pseudonyms. Using this mechanism, pseudonyms in the user equipment and home network are automatically synchronized when the user equipment connects to 5G. Our mechanisms utilize existing LTE and 3GPP Release 15 messages and require modifications only in the user equipment and home network in order to provide identity privacy. Additionally, lawful interception requires minor patching in the serving network.

    AlkuperäiskieliEnglanti
    OtsikkoSecurity Standardisation Research - 4th International Conference, SSR 2018, Proceedings
    ToimittajatCas Cremers, Anja Lehmann
    KustantajaSpringer
    Sivut95-119
    Sivumäärä25
    ISBN (painettu)9783030047610
    DOI - pysyväislinkit
    TilaJulkaistu - 1 tammik. 2018
    OKM-julkaisutyyppiA4 Artikkeli konferenssijulkaisussa
    TapahtumaConference on Security Standards Research - Darmstadt, Saksa
    Kesto: 26 marrask. 201827 marrask. 2018
    Konferenssinumero: 4

    Julkaisusarja

    NimiLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
    Vuosikerta11322 LNCS
    ISSN (painettu)0302-9743
    ISSN (elektroninen)1611-3349

    Conference

    ConferenceConference on Security Standards Research
    LyhennettäSSR
    Maa/AlueSaksa
    KaupunkiDarmstadt
    Ajanjakso26/11/201827/11/2018

    Sormenjälki

    Sukella tutkimusaiheisiin 'Defeating the downgrade attack on identity privacy in 5G'. Ne muodostavat yhdessä ainutlaatuisen sormenjäljen.

    Siteeraa tätä