5G Positioning: Security and Privacy Aspects 293
13.5.1.3 Security Threats Affecting LBSP
From the LBSP’s point of view, the main security threats come from:
1) Unauthorized use of the Location Based Service: for example, a user who did not pay
the service would try to use it by accessing fraudulently the LBSP;
2) Location leakage or theft: user location information can leak accidentally or due to
hacking of LBSP and such location leakage can adversely affect the user and its trust
in LBSP. For example, knowing when a family is on holidays (based on their location)
can create opportunities of house burglary if such information gets into malevolent
hands. Or stealing the location identity of another user can allow one to ride freely
on automatic toll highways, as the bill would be sent to another user;
3) Lack of transparency in privacy policies: an LBSP uses location information or content
to provide a service to the user. Often, such a service is a web‐based service, meaning
that it requires access to the Internet. Often the LBSP developers rely on mixed third
parties’ data sources. For example, a location‐based advertising application may use
data about various shop offers in a certain shopping center, combined with customers’ loyalty cards to that particular shop. Such a service could offer discounts to loyal
users or to users passing in a certain time interval around that shop. The third‐party
unit can also require the user location, for example for storing up statistics about a
particular user’s shopping habits and these requirements might be into conflict with
LBSP policy that claims that location data is only used anonymously. The LSBP should
make it clear to what extent and what kind of user location is collected by the third
parties (e.g. floor or building level versus meter accuracy position) and if such data
can be associated with individual user profiles, and this should be made visible in the
LBSP policies to the users. Also, a best approach would be when the user is given the
possibility to choose how his/her location data is used and there are mechanisms to
verify and reinforce the correct usage of the location data.
13.5.1.4 Security Threats Affecting the 5G User Device or LIC
From the users’ point of view, some of the threats encountered at LISP and LBSP are
also affecting the users, and some new threats appear. The main security threats on the
users’ side can be grouped into:
1) The presence of malicious nodes in the system: this affects both the LISP and the users
in the mobile‐centric positioning, as the location estimate relies on information collected from various nodes in the system;
2) Low trustworthiness level in LISP or LBSP or both: this affects user devices using both
device‐centric and network‐centric localization. This may happen when the user
relies, for example, on a cloud LISP or LBSP or on solutions involving crowd‐sourced
data. Trustworthiness is critical in some location‐based applications involving emergency help, road assistance or billing (e.g. road tolling). The trustworthiness levels
are often defined with respect to a certain target accuracy or availability. For example, if an LISP is trusted to provide a location accuracy of less than 5 m in 80% of
cases, we cannot say if the same LISP can be trusted to provide a location accuracy
of less than 0.5 m in 99% of cases;
3) The intentional and unintentional interferences: this affects both the LISP and the
users in the mobile‐centric positioning, as a low‐quality measurement or low‐quality
signaling would deteriorate the location estimation or in extreme cases prevent the
Précédent

- 335/483

Suivant