AAKA: An Anti-Tracking Cellular Authentication Scheme Leveraging Anonymous Credentials
Hexuan Yu, Changlai Du, Yang Xiao, Angelos D. Keromytis, Chonggang Wang, Robert Gazda, Y. Thomas Hou, Wenjing Lou
Abstract
—Mobile tracking has long been a privacy problem, where the geographic data and timestamps gathered by mobile network operators (MNOs) are used to track the locations and movements of mobile subscribers. Additionally, selling the geolocation information of subscribers has become a lucrative business. Many mobile carriers have violated user privacy agreements by selling users’ location history to third parties without user consent, exacerbating privacy issues related to mobile tracking and profiling. This paper presents AAKA , an anonymous authentication and key agreement scheme designed to protect against mobile tracking by honest-but-curious MNOs . AAKA leverages anonymous credentials and introduces a novel mobile authentication protocol that allows legitimate subscribers to access the network anonymously, without revealing their unique (real) IDs. It ensures the integrity of user credentials, preventing forgery, and ensures that connections made by the same user at different times cannot be linked. While the MNO alone cannot identify or profile a user, AAKA enables identification of a user under legal intervention, such as when the MNOs collaborate with an authorized law enforcement agency. Our design is compatible with the latest cellular architecture and SIM standardized by 3GPP, meeting 3GPP’s fundamental security requirements for User Equipment (UE) authentication and key agreement processes. A comprehensive security analysis demonstrates the scheme’s effectiveness. The evaluation shows that the scheme is practical, with a credential presentation generation taking ∼ 52 ms on a constrained host device equipped with a standard cellular SIM.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ca4f6b77-3933-407c-a83f-c28001e19366Cited by top-tier papers6
- Strong Privacy-Preserving Universally Composable AKA Protocol with Seamless Handover Support for Mobile Virtual Network OperatorRabiah Alnashwan, Yang Yang, Yilu Dong, Prosanta Gope et al.CCS 2024 · 4 citations
- FC-GUARD: Enabling Anonymous yet Compliant Fiat-to-Cryptocurrency ExchangesShaoyu Li, Hexuan Yu, Md Mohaimin Al Barat, Yang Xiao et al.INFOCOM 2026 · 1 citation
- ANONYCALL: Enabling Native Private Calling in Mobile NetworksHexuan Yu, Chaoyu Zhang, Yang Xiao, Angelos D. Keromytis et al.NDSS 2026
- AKMA+: Security and Privacy-Enhanced and Standard-Compatible AKMA for 5G CommunicationYang Yang, Guomin Yang, Yingjiu Li, Minming Huang et al.USENIX Security 2025
- LPG: Raise Your Location Privacy Game in Direct-to-Cell LEO Satellite NetworksQuan Shi, Liying Wang, Prosanta Gope, Qi Liang et al.USENIX Security 2026
Builds on5
- A Formal Analysis of 5G AuthenticationDavid A. Basin, Jannik Dreier, Lucca Hirschi, Sasa Radomirovic et al.CCS 2018 · 428 citations
- GUTI Reallocation Demystified: Cellular Location Tracking with Changing Temporary IdentifierByeongdo Hong, Sangwook Bae, Yongdae KimNDSS 2018 · 90 citations
- Privacy-Preserving and Standard-Compatible AKA Protocol for 5GYuchen Wang, Zhenfeng Zhang, Yongquan XieUSENIX Security 2021 · 58 citations
- Pretty Good Phone PrivacyPaul Schmitt, Barath RaghavanUSENIX Security 2021 · 24 citations
- UCBlocker: Unwanted Call Blocking Using Anonymous AuthenticationChanglai Du, Hexuan Yu, Yang Xiao, Y. Thomas Hou et al.USENIX Security 2023
Related papers
- E2E-AKMA: An End-to-End Secure and Privacy-Enhancing AKMA Protocol Against the Anchor Function CompromiseYueming Li, Long Chen, Qianwen Gao, Zhenfeng ZhangUSENIX Security 2026
- 5G-RNAKA : A Random Number-based Authentication and Key Agreement Protocol for 5G SystemsHui Li, Haotian Li, Chi Ma, Jingjing Guan et al.CCS 2025
- With a Little Help from My Friends: Constructing Practical Anonymous CredentialsLucjan Hanzlik, Daniel SlamanigCCS 2021 · 52 citations
- Component-Based Formal Analysis of 5G-AKA: Channel Assumptions and Session ConfusionCas Cremers, Martin Dehnel-WildNDSS 2019 · 131 citations
- PGUS: Pretty Good User Security for Thick MVNOs with a Novel Sanitizable Blind SignatureYang Yang, Quan Shi, Prosanta Gope, Behzad Abdolmaleki et al.S&P 2025
