Analysis of privacy in mobile telephony systems

被引:0
|
作者
Myrto Arapinis
Loretta Ilaria Mancini
Eike Ritter
Mark Dermot Ryan
机构
[1] University of Edinburgh,
[2] University of Birmingham,undefined
关键词
Privacy; Automatic verification; ProVerif; Mobile telephony; Pseudonym;
D O I
暂无
中图分类号
学科分类号
摘要
We present a thorough experimental and formal analysis of users’ privacy in mobile telephony systems. In particular, we experimentally analyse the use of pseudonyms and point out weak deployed policies leading to some critical scenarios which make it possible to violate a user’s privacy. We also expose some protocol’s vulnerabilities resulting in breaches of the anonymity and/or user unlinkability. We show these breaches translate in actual attacks which are feasible to implement on real networks and discuss our prototype implementation. In order to countermeasure these attacks, we propose realistic solutions. Finally, we provide the theoretical framework for the automatic verification of the unlinkability and anonymity of the fixed 2G/3G procedures and automatically verify them using the ProVerif tool.
引用
收藏
页码:491 / 523
页数:32
相关论文
共 50 条