Kumar, Liyanage, Ahmad, Braeken, and Ylianttila
274
security mechanisms. Hence the IMSI catchers are also used to monitor and track the
locations of specific subscribers.
The traditional cellular systems are usually dependent on Universal Subscriber Identity
Module (USIM) cards, to manage user’s identities and keys. In the case of 5G systems,
devices and equipments such as smartphones, wearables and smart sensors would be
comparatively smaller in size and too economical to accommodate USIM. Therefore,
novel methods are required in this case to manage the device identities [7]. There is possibility of a framework that can comprise the device and service identities together.
During the manufacturing phase, the device identity can be allocated and is considered
as a unique global identity. On the other hand, the service provider offers the service
identities. Device identity is also referred to as the physical identity and may address
single or multiple service identities. It allows users to make their decision regarding
which particular device can be permitted to access the network and utilize the assigned
services [7].
The 5G ecosystem would need more flexible, general and open identity management
infrastructure, which should have the scope for various alternatives and be able to give
permission for that. One way of proceeding for companies is that, they might allow the
existing ID management mechanism to reuse it for 5G access. In 5G, there would be an
immense number of hand‐held devices that may include smartphones and tablets, as
well as wearables; therefore it is important to find ways on how to handle these devices
and at the same time maintain the subscribers’ identities. It is also crucial to think about
novel trust models for 5G networks. There are also some key concepts such as network
slicing and virtualization, which must be considered when proposing the secure identity management solutions for such scenarios [11].
12.5 Trust Models
Trust models change with respect to the time and improvements in technology.
Previously, for companies, the mobile devices of all users are considered to be more
trustworthy, because they were issued and managed by their own IT department. But
recently, every user in the company/enterprise wants their own personal gadgets, which
can eventually lead to a number of security threats to firewalls of the company [11].
Trust includes capabilities such as security, identity management and privacy. Even
with to date, there are no standard trust models available for current networks (2G‐4G).
The current (2G‐4G) trust model mainly comprises of the entities, such as user
(subscriber), service provider, network operator, Virtual Mobile Network Operator
(VMNO), and equipment manufacturer among others, as shown in Figure 12.2 [1].
Usually, the subscribers keep their trust over the service provider and assume that the
rules and regulations written in the service subscription contract/billing must be followed, and this trust is then further developed based on experience, reputation and
the legal framework. It is assumed that the end‐to‐end path between subscribers
and service providers are secured during any communication (may be voice), and users
trust that their critical data is secure with operators.
The service provider is responsible for providing the required services to subscribers through some kind of user device or equipment, such as a mobile phone or tablet.
The trust which service providers mostly seek from the subscribers is that they must
Précédent

- 316/483

Suivant