USENIX Security2021Top-tier venue
Privacy-Preserving and Standard-Compatible AKA Protocol for 5G
Yuchen Wang, Zhenfeng Zhang, Yongquan Xie
Abstract
The 3GPP consortium has published the Authentication and Key Agreement protocol for the 5th generation (5G) mobile communication system (i.e., 5G-AKA) by Technical Specification (TS) 33.501. It introduces public key encryption to conceal the so-called SUPIs so as to enhance mobile users' privacy. However, 5G-AKA is only privacy-preserving at the presence of passive attackers, and is still vulnerable to the linkability attacks from active attackers. An active attacker can track target mobile phones via performing these attacks, which puts the privacy of users at risk. In this paper, we propose a privacy-preserving solution for the AKA protocol of 5G system denoted by 5G-AKA . It is resistant to linkability attacks performed by active attackers, and is compatible with the SIM cards and currently deployed Serving Networks (SNs). In particular, we first conduct an analysis on the known linkability attacks in 5G-AKA, and find out a root cause of all attacks. Then, we design a countermeasure with the inherent key encapsulation mechanism of ECIES (i.e., ECIES-KEM), and use the shared key established by ECIES-KEM to encrypt the challenges sent by a Home Network (HN). With this measure, a target User Equipment (UE) who receives a message replayed from its previously attended sessions behaves as non-target UEs, which prevents the attacker from distinguishing the UE by linking it with its previous sessions. Moreover, 5G-AKA does not raise additional bandwidth cost, and only introduces limited additional time costs from 0.02% to 0.03%. Finally, we use a stateof-the-art formal verification tool, Tamarin prover, to prove that 5G-AKA achieves the desired security goals of privacy, authentication and secrecy.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 800b9478-ebd2-4a04-aa75-afe57fb3fc0dCited by top-tier papers7
- Finding Traceability Attacks in the Bluetooth Low Energy Specification and Its ImplementationsJianliang Wu, Patrick Traynor, Dongyan Xu, Dave (Jing) Tian et al.USENIX Security 2024 · 6 citations
- Strong Privacy-Preserving Universally Composable AKA Protocol with Seamless Handover Support for Mobile Virtual Network OperatorRabiah Alnashwan, Yang Yang, Yilu Dong, Prosanta Gope et al.CCS 2024 · 4 citations
- AKMA+: Security and Privacy-Enhanced and Standard-Compatible AKMA for 5G CommunicationYang Yang, Guomin Yang, Yingjiu Li, Minming Huang et al.USENIX Security 2025
- Thwarting Smartphone SMS Attacks at the Radio Interface LayerHaohuang Wen, Phillip A. Porras, Vinod Yegneswaran, Zhiqiang LinNDSS 2023
- 5G-Spector: An O-RAN Compliant Layer-3 Cellular Attack Detection ServiceHaohuang Wen, Phillip A. Porras, Vinod Yegneswaran, Ashish Gehani et al.NDSS 2024
Builds on8
- Post-quantum Key Exchange - A New HopeErdem Alkim, Léo Ducas, Thomas Pöppelmann, Peter SchwabeUSENIX Security 2016 · 972 citations
- Frodo: Take off the Ring! Practical, Quantum-Secure Key Exchange from LWEJoppe W. Bos, Craig Costello, Léo Ducas, Ilya Mironov et al.CCS 2016 · 431 citations
- A Formal Analysis of 5G AuthenticationDavid A. Basin, Jannik Dreier, Lucca Hirschi, Sasa Radomirovic et al.CCS 2018 · 428 citations
- Practical Attacks Against Privacy and Availability in 4G/LTE Mobile Communication SystemsAltaf Shaik, Jean-Pierre Seifert, Ravishankar Borgaonkar, N. Asokan et al.NDSS 2016 · 342 citations
- A Comprehensive Symbolic Analysis of TLS 1.3Cas Cremers, Marko Horvat, Jonathan Hoyland, Sam Scott et al.CCS 2017 · 247 citations
Related papers
- 5G-RNAKA : A Random Number-based Authentication and Key Agreement Protocol for 5G SystemsHui Li, Haotian Li, Chi Ma, Jingjing Guan et al.CCS 2025
- Component-Based Formal Analysis of 5G-AKA: Channel Assumptions and Session ConfusionCas Cremers, Martin Dehnel-WildNDSS 2019 · 131 citations
- E2E-AKMA: An End-to-End Secure and Privacy-Enhancing AKMA Protocol Against the Anchor Function CompromiseYueming Li, Long Chen, Qianwen Gao, Zhenfeng ZhangUSENIX Security 2026
- AAKA: An Anti-Tracking Cellular Authentication Scheme Leveraging Anonymous CredentialsHexuan Yu, Changlai Du, Yang Xiao, Angelos D. Keromytis et al.NDSS 2024
- PGUS: Pretty Good User Security for Thick MVNOs with a Novel Sanitizable Blind SignatureYang Yang, Quan Shi, Prosanta Gope, Behzad Abdolmaleki et al.S&P 2025
