User Privacy, Identity and Trust in 5G 273
● Device Identity Privacy: The vulnerabilities that could exist concerning device identity privacy are that, subscribers do not wish to be tracked by their UE identifiers.
Likewise, as with subscriber identity privacy, users also do not want linkage between
their subscriber’s identifiers with device identifiers. This can be resolved by studying
the possible end‐to‐end anonymization approaches that provide a guard against the
unauthorized tracking of devices and preserve the disclosure of device identity. 5G
also ensures that only through a confidential protected message, the International
Mobile Equipment Identity (IMEI) should be sent [10].
12.4 Identity Management
The mechanism of handling the identity in a 5G system would be a crucial task for certain
reasons, such as keeping a high degree of security to ensure mutual authentication along
with maintaining the user’s friendliness and privacy. As 5G technology will become a
more multi‐vendor environment and comprise of various stakeholders, a strong identity
management mechanism is needed to protect the identity and network from unauthorized access of users. During the standardization process of 3G and 4G, when equipment
such as mobile devices show their specific identities, there is a serious threat regarding
International Mobile Subscriber Identity (IMSI) catching. At the moment, there is no
protection mechanism proposed, because that particular threat has not caused any serious trouble to the access network. It is not completely clear yet that whether this attack is
still valid for 5G technology and needs any further consideration [8].
The core reason behind an IMSI catching attack is that while in the unavailability of
Temporary International Subscription Identity (TMSI), User Equipment (UE) might be
unable to use IMSI as its identifiers. IMSI catching attacks can be both active and passive. In passive attacks, all IMSI can be captured and gathered by the IMSI catcher when
it eavesdrops in the neighborhood of the wireless traffic. On the other hand, in active
attacks, a fake base station is established that has strong signal strength and might be
considered as a legitimate base station. Mobile devices usually prefer the base station
with the highest signal strength. A message requesting the identity is sent to all mobile
devices within the specific area through this fake base station. Mobile devices send their
IMSI, as they consider it a valid base station, which have lost the connection to TMSI.
Catching IMSI is often supposed to be a starting point for more detailed eavesdropping
attacks in GSM [12]. An enhancement technique is mentioned in [12], which allows
home network operators to place their trust less on serving networks and guard against
IMSI catchers. The idea is to enhance the handling of identifiers and protocols, so that
the UE and home network can see IMSI in clear text.
The on‐going privacy preserving mechanisms do not guarantee protection against
the threats on air interface, because they act as a valid network that has lost temporary
identity and also when the request for IMSI is made, there is no proper protection for
passive eavesdroppers that possibly could be available there [12]. Several privacy
related attacks have been reported, such as in some cases when a fake base station is
plotted leading to the derivation of user’s personal information. IMSI attacks are mainly
focused on stealing IMSI of a mobile subscriber. The IMSI catcher requests the subscriber’s identity from the mobile subscriber for the longer term. This is considered as
a normal routine request and in reply, mobile devices send its IMSI using standard
● Device Identity Privacy: The vulnerabilities that could exist concerning device identity privacy are that, subscribers do not wish to be tracked by their UE identifiers.
Likewise, as with subscriber identity privacy, users also do not want linkage between
their subscriber’s identifiers with device identifiers. This can be resolved by studying
the possible end‐to‐end anonymization approaches that provide a guard against the
unauthorized tracking of devices and preserve the disclosure of device identity. 5G
also ensures that only through a confidential protected message, the International
Mobile Equipment Identity (IMEI) should be sent [10].
12.4 Identity Management
The mechanism of handling the identity in a 5G system would be a crucial task for certain
reasons, such as keeping a high degree of security to ensure mutual authentication along
with maintaining the user’s friendliness and privacy. As 5G technology will become a
more multi‐vendor environment and comprise of various stakeholders, a strong identity
management mechanism is needed to protect the identity and network from unauthorized access of users. During the standardization process of 3G and 4G, when equipment
such as mobile devices show their specific identities, there is a serious threat regarding
International Mobile Subscriber Identity (IMSI) catching. At the moment, there is no
protection mechanism proposed, because that particular threat has not caused any serious trouble to the access network. It is not completely clear yet that whether this attack is
still valid for 5G technology and needs any further consideration [8].
The core reason behind an IMSI catching attack is that while in the unavailability of
Temporary International Subscription Identity (TMSI), User Equipment (UE) might be
unable to use IMSI as its identifiers. IMSI catching attacks can be both active and passive. In passive attacks, all IMSI can be captured and gathered by the IMSI catcher when
it eavesdrops in the neighborhood of the wireless traffic. On the other hand, in active
attacks, a fake base station is established that has strong signal strength and might be
considered as a legitimate base station. Mobile devices usually prefer the base station
with the highest signal strength. A message requesting the identity is sent to all mobile
devices within the specific area through this fake base station. Mobile devices send their
IMSI, as they consider it a valid base station, which have lost the connection to TMSI.
Catching IMSI is often supposed to be a starting point for more detailed eavesdropping
attacks in GSM [12]. An enhancement technique is mentioned in [12], which allows
home network operators to place their trust less on serving networks and guard against
IMSI catchers. The idea is to enhance the handling of identifiers and protocols, so that
the UE and home network can see IMSI in clear text.
The on‐going privacy preserving mechanisms do not guarantee protection against
the threats on air interface, because they act as a valid network that has lost temporary
identity and also when the request for IMSI is made, there is no proper protection for
passive eavesdroppers that possibly could be available there [12]. Several privacy
related attacks have been reported, such as in some cases when a fake base station is
plotted leading to the derivation of user’s personal information. IMSI attacks are mainly
focused on stealing IMSI of a mobile subscriber. The IMSI catcher requests the subscriber’s identity from the mobile subscriber for the longer term. This is considered as
a normal routine request and in reply, mobile devices send its IMSI using standard
