Lohan, Alén-Savikko, Chen, Järvinen, Leppäkoski, Kuusniemi, and Korpisaari
300
All these scenarios lead to different security and privacy goals and require different
cryptographic solutions. The four primary goals of cryptography are confidentiality,
integrity, authenticity and non‐repudiation [19]:
1) Confidentiality: (often referred to as secrecy) ensures that the information can be
accessed only by authorized entities. Typically, this means that data is encrypted
with a strong encryption algorithm (e.g. with AES [80]) that allows decryption only
by an entity who has the secret key;
2) Integrity: protects data from unauthorized manipulation and allows the authorized
entity to notice any manipulations. This can be achieved, for example, by computing a (cryptographic) check sum with a cryptographic hash function (e.g. with
SHA‐256 [79]);
3) Authenticity: provides proof that an entity is the one that it claims to be (e.g. with
cryptographic challenge‐response protocols) or that data originates from an entity it
is claimed to originate from (e.g. with digital signatures);
4) Non‐repudiation: prevents an entity from denying earlier commitments or actions.
For instance, it prevents a person from later denying signing of a document. Non‐
repudiation can be achieved, for example, with digital signatures (e.g. with (EC)
DSA [78]).
Traditional secret‐key cryptography uses the same key for encryption and decryption
and requires key exchange via secure channel prior to communication between the
entities. Public‐key cryptography [114] uses an asymmetric key pair where only the
decryption key needs to be secret, but the encryption key can be public. This allows
everyone to encrypt, but only an entity with the secret key can decrypt. The disadvantage of public‐key cryptography is that it is significantly more computationally complex
than secret‐key cryptography. The following discusses certain cryptographic techniques that have been proposed for solving security issues in the aforementioned three
scenarios or that may play a role in finding such solutions, although specific solutions
are still missing
13.10.1 Cryptographic Authentication in Positioning
A repeating problem in the aforementioned 5G positioning scenarios is how to
ensure authenticity and integrity of positioning signals and position information. If
an entity, who knows its location, wants to share its location or (e.g. some other
information which allows the recipient to derive its own location) in a reliable and
secure manner, then it must ensure that any malicious party cannot tamper with the
communication. The same problem is omnipresent in data communication and, in
principle, integrity and authenticity of positioning can be solved with similar cryptographic techniques used elsewhere in communication. If two entities can share a
secret‐key via a secure channel, then they can use this key with standard cryptographic techniques to ensure authenticity and integrity of their communication, for
example, with cryptographic message authentication codes (e.g. with HMAC [77]). If
a key cannot be shared before deployment, then public‐key cryptography can be
used for key agreement or for providing integrity and authenticity with digital signatures. These cryptographic techniques are typically enough to avoid the threat of
“unauthorized use of the location based service” (with standard user authentication)
Précédent

- 342/483

Suivant