Concealing IMSI in 5G Network Using Identity Based Encryption

Mohsin Khan,Valtteri Niemi
DOI: https://doi.org/10.48550/arXiv.1708.01868
2017-08-06
Abstract:Subscription privacy of a user has been a historical concern with all the previous generation mobile networks, namely, GSM, UMTS,and LTE. While a little improvement have been achieved in securing the privacy of the long-term identity of a subscriber, the so called IMSI catchers are still in existence even in the LTE and advanced LTE networks. Proposals have been published to tackle this problem in 5G based on pseudonyms, and different public-key technologies. This paper looks into the problem of concealing long-term identity of a subscriber and presents a technique based on identity based encryption (IBE) to tackle it. The proposed solution can be extended to a mutual authentication and key agreement protocol between a serving network (SN) and a user equipment (UE). This mutual authentication and key agreement protocol does not need to connect with the home network (HN) on every run. A qualitative comparison of the advantages and disadvantages of different techniques show that our solution is competitive for securing the long-term identity privacy of a user in the 5G network.
Cryptography and Security
What problem does this paper attempt to address?
The problem that this paper attempts to solve is to protect users' long - term identity (IMSI) privacy in 5G networks. Specifically, the paper focuses on how to prevent the IMSI from being eavesdropped by passive attackers (such as IMSI - catchers) or exploited by active attackers when the user equipment (UE) attempts to connect to the network. Although traditional mobile networks (such as GSM, UMTS, LTE) have improved the security of the IMSI to a certain extent, there are still vulnerabilities, especially the insufficient defense ability against IMSI - catchers. Therefore, this paper proposes a technique based on identity - based encryption (IBE) to solve this problem. The main contributions of the paper are as follows: 1. **Propose a new solution**: A technique based on identity - based encryption (IBE), which can not only hide the user's IMSI, but also achieve two - way authentication between the user equipment (UE) and the serving network (SN) without having to communicate with the home network (HN) every time. 2. **Security analysis**: A detailed comparison of different solutions has been carried out, including the pseudonym - based method, the certificate - based public key encryption method, the root - key - based encryption method and the IBE - based method, and the advantages and disadvantages of various methods have been evaluated from multiple perspectives (such as immunity against attackers, signal overhead, computational overhead, latency, etc.). 3. **Practical application prospects**: Demonstrate the feasibility and advantages of the IBE - based solution in 5G networks, especially achieving two - way authentication between the user equipment and the serving network without having to communicate with the home network every time. Through these contributions, the paper provides a new and effective technical solution for user privacy protection in 5G networks.