Component-Based Formal Analysis of 5G-AKA: Channel Assumptions and Session Confusion
Cas Cremers, Martin Dehnel-Wild
摘要
The 5G mobile telephony standards are nearing completion; upon adoption these will be used by billions across the globe. Ensuring the security of 5G communication is of the utmost importance, building trust in a critical component of everyday life and national infrastructure. We perform fine-grained formal analysis of 5G's main authentication and key agreement protocol (AKA), and provide the first models to explicitly consider all parties defined by the protocol specification. Our analysis reveals that the security of 5G-AKA critically relies on unstated assumptions on the inner workings of the underlying channels. In practice this means that following the 5G-AKA specification, a provider can easily and 'correctly' implement the standard insecurely, leaving the protocol vulnerable to a security-critical race condition. We provide the first models and analysis considering component and channel compromise in 5G, whose results further demonstrate the fragility and subtle trust assumptions of the 5G-AKA protocol. We propose formally verified fixes to the encountered issues, and have worked with 3GPP to ensure these fixes are adopted.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper29
- 5GReasoner: A Property-Directed Security and Privacy Analysis Framework for 5G Cellular Network ProtocolSyed Rafiul Hussain, Mitziu Echeverria, Imtiaz Karim, Omar Chowdhury 等CCS 2019 · 被引用 188 次
- Privacy-Preserving and Standard-Compatible AKA Protocol for 5GYuchen Wang, Zhenfeng Zhang, Yongquan XieUSENIX Security 2021 · 被引用 58 次
- Seems Legit: Automated Analysis of Subtle Attacks on Protocols that Use SignaturesDennis Jackson, Cas Cremers, Katriel Cohn-Gordon, Ralf SasseCCS 2019 · 被引用 53 次
- MPInspector: A Systematic and Automatic Approach for Evaluating the Security of IoT Messaging ProtocolsQinying Wang, Shouling Ji, Yuan Tian, Xuhong Zhang 等USENIX Security 2021 · 被引用 45 次
- Noncompliance as Deviant Behavior: An Automated Black-box Noncompliance Checker for 4G LTE Cellular DevicesSyed Rafiul Hussain, Imtiaz Karim, Abdullah Al Ishtiaq, Omar Chowdhury 等CCS 2021 · 被引用 41 次
它引用的顶会 Paper2
相关 Paper
- A Formal Analysis of 5G AuthenticationDavid A. Basin, Jannik Dreier, Lucca Hirschi, Sasa Radomirovic 等CCS 2018 · 被引用 428 次
- 5G-RNAKA : A Random Number-based Authentication and Key Agreement Protocol for 5G SystemsHui Li, Haotian Li, Chi Ma, Jingjing Guan 等CCS 2025
- AKMA+: Security and Privacy-Enhanced and Standard-Compatible AKMA for 5G CommunicationYang Yang, Guomin Yang, Yingjiu Li, Minming Huang 等USENIX Security 2025
- From Control to Chaos: A Comprehensive Formal Analysis of 5G's Access ControlMujtahid Akon, Md. Toufikuzzaman, Syed Rafiul HussainS&P 2025
- PGUS: Pretty Good User Security for Thick MVNOs with a Novel Sanitizable Blind SignatureYang Yang, Quan Shi, Prosanta Gope, Behzad Abdolmaleki 等S&P 2025
