User Privacy, Identity and Trust in 5G 269
Identity (IMSI) catchers, due to lack of authentication mechanisms and thus can be
used to trace and monitor users. The next major transition is the 3GPP (Third
Generation Partnership Project), which increased the level of security as compared to
the 2G systems. The security specifications in 3GPP also included the mutual authentication mechanisms [2,3]. Furthermore, with the increase in the amount of mobile data,
along with the evolution of new applications, the motivation growed to move from
3GPP towards the fourth‐generation. LTE is designed to allow strong cryptographic,
encryption and mutual authentication mechanisms [3,4].
The techniques to tackle the identity management challenges are an essential part of
5G, due to the fact that the security requirements will be high in this case. Threats such
as International Mobile Subscriber Identity (IMSI) catching were also discussed during
the standardization of 3G and 4G and thus it is also considered as a focal point in 5G
systems [5]. There is not yet any complete or exact document/specification available (at
least not in the technical specification for 3GPP) regarding trust models for on‐going
mobile networks (2G‐4G). But considering the trend of security requirements, which
has evolved from 2G‐4G, the current trust model for mobile networks can also be analyzed. However, in the case of 5G networks, the trust model among various stakeholders
would be even more complex, because additional entities will also become involved.
12.3 User Privacy
5G technology will enable several novel applications that will potentially open doors for
a large number of vertical industries. This leads us to the fact that a large amount of
personal information will be carried out over the 5G networks. With the introduction
of data‐mining techniques, it is easier to retrieve the data privacy information and thus
the data is at huge risk. The 5G system must provide security mechanisms for protection of a variety of trusted information, regarding humans as well as for machine‐users
(e.g. identity, subscribed services, location/presence information, mobility patterns,
network usage behavior, commonly invoked applications, etc.).
5G technology would also offer customized network services for consumers by realizing the characteristics of particular services. Thus, the privacy requirements in the 5G
network may vary from service to service. 5G technology will also enable service‐oriented privacy requirements. For example, health information of the users in certain
healthcare applications will require a higher degree of privacy. Also in the case of some
critical industrial tasks, equally higher level of privacy protection is required. But applications like searching for some kind of location information may require a smaller degree
of privacy. For more focused understanding, we have split the user privacy concepts into
three parts, that are; data, location and identity privacy, as shown in Figure 12.1.
12.3.1 Data Privacy
There will be heaps of smart and heterogeneous devices connected through 5G technology, thus the chances of leakage of the user’s personal data is very high. Service
providers/companies store and use the private information of consumers without their
permission. In some cases, the service provider stores the user data for their own product, but later shares them with other companies so that they can analyze the data and
find some trends that, which of their own product is more suitable for that particular
Identity (IMSI) catchers, due to lack of authentication mechanisms and thus can be
used to trace and monitor users. The next major transition is the 3GPP (Third
Generation Partnership Project), which increased the level of security as compared to
the 2G systems. The security specifications in 3GPP also included the mutual authentication mechanisms [2,3]. Furthermore, with the increase in the amount of mobile data,
along with the evolution of new applications, the motivation growed to move from
3GPP towards the fourth‐generation. LTE is designed to allow strong cryptographic,
encryption and mutual authentication mechanisms [3,4].
The techniques to tackle the identity management challenges are an essential part of
5G, due to the fact that the security requirements will be high in this case. Threats such
as International Mobile Subscriber Identity (IMSI) catching were also discussed during
the standardization of 3G and 4G and thus it is also considered as a focal point in 5G
systems [5]. There is not yet any complete or exact document/specification available (at
least not in the technical specification for 3GPP) regarding trust models for on‐going
mobile networks (2G‐4G). But considering the trend of security requirements, which
has evolved from 2G‐4G, the current trust model for mobile networks can also be analyzed. However, in the case of 5G networks, the trust model among various stakeholders
would be even more complex, because additional entities will also become involved.
12.3 User Privacy
5G technology will enable several novel applications that will potentially open doors for
a large number of vertical industries. This leads us to the fact that a large amount of
personal information will be carried out over the 5G networks. With the introduction
of data‐mining techniques, it is easier to retrieve the data privacy information and thus
the data is at huge risk. The 5G system must provide security mechanisms for protection of a variety of trusted information, regarding humans as well as for machine‐users
(e.g. identity, subscribed services, location/presence information, mobility patterns,
network usage behavior, commonly invoked applications, etc.).
5G technology would also offer customized network services for consumers by realizing the characteristics of particular services. Thus, the privacy requirements in the 5G
network may vary from service to service. 5G technology will also enable service‐oriented privacy requirements. For example, health information of the users in certain
healthcare applications will require a higher degree of privacy. Also in the case of some
critical industrial tasks, equally higher level of privacy protection is required. But applications like searching for some kind of location information may require a smaller degree
of privacy. For more focused understanding, we have split the user privacy concepts into
three parts, that are; data, location and identity privacy, as shown in Figure 12.1.
12.3.1 Data Privacy
There will be heaps of smart and heterogeneous devices connected through 5G technology, thus the chances of leakage of the user’s personal data is very high. Service
providers/companies store and use the private information of consumers without their
permission. In some cases, the service provider stores the user data for their own product, but later shares them with other companies so that they can analyze the data and
find some trends that, which of their own product is more suitable for that particular
