Lohan, Alén-Savikko, Chen, Järvinen, Leppäkoski, Kuusniemi, and Korpisaari
292
● Physical Attack/Firmware Replacement (PA): in a PA attack, also of the active type, an
attacker has physical access to the device and can replace firmware or steal credential
information such as static keys;
● Eavesdropping (ED): in an ED attack, which is a passive attack, the attacker passively
monitors the network communications for capturing communicating data and
authentication credentials.
Here, we add a few notes about how security aspects have evolved from the first generation (1G) of mobile phones to 5G, and these again apply to both communication and
navigation aspects. The first generation of mobile networks (1G) basically did not have
any mechanism of encryption 32 [58]. In early 2G systems, the mutual authentication
between mobile users and the network did not exist, which left the possibility for an
attacker to set up fake base stations and convince legitimate mobile devices to connect
to [98]. In order to minimize exposure of user identifiers (known as International
Mobile Subscriber Identifier or IMSI) in over‐the‐air signaling messages, 2G systems
introduced the use of temporary mobile subscriber identifiers. However, in the absence
of mutual authentication, fake base stations were used as “IMSI catchers” to harvest
IMSIs and to track movements of users [16].
The security has significantly been strengthened by 3GPP (Third Generation
Partnership Project) in 3G specifications, which introduced mutual authentication and
the use of stronger and well‐analyzed cryptographic algorithms [2]. LTE specifications
further improved signaling protocols by requiring authentication and encryption
(referred to as “ciphering” in 3GPP terminology) in more situations than was previously
required. Previously known attacks, such as the ability to track user movement, were
thought to be difficult in LTE [99], although recent work [106] proved that this problem
can be solved. However, radio jamming, which generates an attack through a jammer by
transmitting energy to disrupt reliable data communication, can still be a potential
attack to LTE or 5G [72].
13.5.1.2 Security Threats Affecting LISP
From the LISP’s point of view (Figure 13.1), there are several potential sources of vulnerabilities in the location solution, which could hinder the robustness of the location estimate:
1) The presence of malicious nodes in the system: the malicious nodes are those nodes
(fixed or mobile) sending fake or erroneous information to the LISP. Examples are
the spoofing and meaconing nodes when AGNSS is used, fake ANs in 5G network or
malicious mobile devices sending wrong or erroneous measurements to the 5G network. Spoofing here refers to the situation when a malicious node broadcasts a synthetic GNSS signal in order to try to trick the mobile AGNSS receiver into using the
false signals and obtaining an incorrect position or time. Meaconing here refers to
the situation when a malicious node re‐broadcasts real satellite signals after a brief
delay, in order to create errors in the AGNSS unit on the 5G receiver;
2) The intentional and unintentional interferences: examples here are the jamming (i.e.
broadcast of a narrowband interference signal) of the GNSS signal when AGNSS solutions are used for 5G positioning or narrowband and wideband interferences in 5G band,
which may affect the quality of the measurements and signaling needed for positioning;
3) Network‐centric database deterioration: this vulnerability applies to positioning
techniques relying on a training database, such as RSS‐based approaches.
Précédent

- 334/483

Suivant