5G Positioning: Security and Privacy Aspects 299
investment is required, except on the receiver side, DTV would be a promising backup
positioning system and thereby also a means to improve the security of a 5G system.
Cloud and AGNSS, as discussed earlier, are also possible backup systems.
13.9 Enhancing Trustworthiness
Several trustworthiness metrics can be used in order to check the trust level of an LISP,
LBSP or a mobile user, by any other of the localization players shown in Figure 13.1.
These are:
● Proximity metrics: only a certain geo‐spatial region could be allowed for a LISP, LBSP
or end‐user when receiving information from the other actors in Figure 13.1. For
example, a user device located in Helsinki, Finland could reject all database information or all service providers that are not tagged in the Helsinki region (or in a smaller
defined geographical region). Both distance proximity and temporal proximity metrics could be envisaged [57];
● Authentication metrics: the signals used for positioning could have authentication
keys embedded within them, so that unauthorized or fake signals are automatically
rejected. Similarly, the LBSP can offer services only to authorized users, identified
through certain authentication procedures. More about authentication is discussed
in Section 13.8;
● Similarity metrics: if the LISP or LBSP have access to the location information of
many users, some similarity patterns between users located in close proximity to each
other can be checked and the outliers can be thus detected and removed. Also similarity patterns with past user geo‐location information, when such information is
available, can be used for an increased trustworthiness of the user location data from
the network side;
● Privacy metrics: such as the location uncertainty related to a particular user or the
linkability of location information to the user who generated it [123].
13.10 Cryptographic Techniques for Security
and Privacy of Positioning
Cryptographic solutions that are required for ensuring security and privacy of 5G
positioning depend on the application and adversary models. We discuss three main
scenarios:
1) The end‐user, the network (LISP and LBSP), and the devices in their possession are
trusted and only security against malicious outsiders is required;
2) The location information provided by the end‐user (or in certain cases LISP or
LIC) is not available or cannot be trusted (e.g. because the end‐user itself has the
incentive to provide a false location or it may be subject to malicious middle men
(e.g. mafia fraud)) and, thus, the location (or the distance from a verifying node)
must be verified; and
3) The network (LISP, LIC and LSBP) cannot be trusted and, thus, privacy of the end‐
user’s location must be ensured.
Précédent

- 341/483

Suivant