Privacy-Preserving and Standard-Compatible AKA Protocol for 5G

被引:0
|
作者
Wang, Yuchen [1 ,2 ]
Zhang, Zhenfeng [1 ]
Xie, Yongquan [3 ]
机构
[1] Chinese Acad Sci, Inst Software, TCA State Key Lab Comp Sci, Beijing, Peoples R China
[2] Alibaba Grp, Hangzhou, Peoples R China
[3] State Cryptog Adm, Commercial Cryptog Testing Ctr, Beijing, Peoples R China
基金
中国国家自然科学基金;
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The 3GPP consortium has published the Authentication and Key Agreement protocol for the 5th generation (5G) mobile communication system (i.e., 5G-AKA) by Technical Specification (TS) 33.501. It introduces public key encryption to conceal the so-called SUPIs so as to enhance mobile users' privacy. However, 5G-AKA is only privacy-preserving at the presence of passive attackers, and is still vulnerable to the linkability attacks from active attackers. An active attacker can track target mobile phones via performing these attacks, which puts the privacy of users at risk. In this paper, we propose a privacy-preserving solution for the AKA protocol of 5G system denoted by 5G-AKA'. It is resistant to linkability attacks performed by active attackers, and is compatible with the SIM cards and currently deployed Serving Networks (SNs). In particular, we first conduct an analysis on the known linkability attacks in 5G-AKA, and find out a root cause of all attacks. Then, we design a counter-measure with the inherent key encapsulation mechanism of ECIES (i.e., ECIES-KEM), and use the shared key established by ECIES-KEM to encrypt the challenges sent by a Home Network (HN). With this measure, a target User Equipment (UE) who receives a message replayed from its previously attended sessions behaves as non-target UEs, which prevents the attacker from distinguishing the UE by linking it with its previous sessions. Moreover, 5G-AKA' does not raise additional bandwidth cost, and only introduces limited additional time costs from 0.02% to 0.03%. Finally, we use a state-of-the-art formal verification tool, Tamarin prover, to prove that 5G-AKA' achieves the desired security goals of privacy, authentication and secrecy.
引用
收藏
页码:3595 / 3612
页数:18
相关论文
共 50 条
  • [1] A USIM compatible 5G AKA protocol with perfect forward secrecy
    Arkko, Jari
    Norrman, Karl
    Naslund, Mats
    Sahlin, Bengt
    [J]. 2015 IEEE TRUSTCOM/BIGDATASE/ISPA, VOL 1, 2015, : 1205 - 1209
  • [2] A privacy-preserving handover authentication protocol for a group of MTC devices in 5G networks
    Yan, Xiaobei
    Ma, Maode
    [J]. COMPUTERS & SECURITY, 2022, 116
  • [3] A Compatible and Identity Privacy-preserving Security Protocol for ACARS
    Li, Xinwei
    Zhang, Qianyun
    Xu, Lexi
    Shang, Tao
    [J]. 2022 IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS, TRUSTCOM, 2022, : 1048 - 1053
  • [4] Device-to-device group authentication compatible with 5G AKA protocol
    Braeken, An
    [J]. COMPUTER NETWORKS, 2021, 201
  • [5] Privacy-Preserving Decentralized Edge Caching in 5G Networks
    Zeng, Yiming
    Huang, Yaodong
    Liu, Zhenhua
    Liu, Ji
    Yang, Yuanyuan
    [J]. 2021 IEEE 14TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING (CLOUD 2021), 2021, : 189 - 199
  • [6] Research on privacy-preserving techniques in the era of the 5G applications
    Hamza, Rafik
    Minh-Son, Dao
    [J]. Virtual Reality and Intelligent Hardware, 2022, 4 (03): : 210 - 222
  • [7] Location Privacy, 5G AKA, and Enhancements
    Damir, Mohamed Taoufiq
    Niemi, Valtteri
    [J]. SECURE IT SYSTEMS, NORDSEC 2022, 2022, 13700 : 40 - 57
  • [8] From 5G Sniffing to Harvesting Leakages of Privacy-Preserving Messengers
    Ludant, Norbert
    Robyns, Pieter
    Noubir, Guevara
    [J]. 2023 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, SP, 2023, : 3146 - 3161
  • [9] The 5G-AKA Authentication Protocol Privacy
    Koutsos, Adrien
    [J]. 2019 4TH IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY (EUROS&P), 2019, : 464 - 479
  • [10] PPSE: Privacy Preservation and Security Efficient AKA Protocol for 5G Communication Networks
    Parne, Balu L.
    Gupta, Shubham
    Gandhi, Kaneesha
    Meena, Shubhangi
    [J]. 2020 IEEE INTERNATIONAL CONFERENCE ON ADVANCED NETWORKS AND TELECOMMUNICATIONS SYSTEMS (IEEE ANTS), 2020,