GUTI Reallocation Demystified: Cellular Location Tracking with Changing Temporary Identifier
Byeongdo Hong, Sangwook Bae, Yongdae Kim
摘要
To keep subscribers' identity confidential, a cellular network operator must use a temporary identifier instead of a permanent one according to the 3GPP standard. Temporary identifiers include Temporary Mobile Subscriber Identity (TMSI) and Globally Unique Temporary Identifier (GUTI) for GSM/3G and Long-Term Evolution (LTE) networks, respectively. Unfortunately, recent studies have shown that carriers fail to protect subscribers in both GSM/3G and LTE mainly because these identifiers have static and persistent values. These identifiers can be used to track subscribers' locations. These studies have suggested that temporary identifiers must be reallocated frequently to solve this privacy problem. The only mechanism to update the temporary identifier in current LTE implementations is called GUTI reallocation. We investigate whether the current implementation of the GUTI reallocation mechanism can provide enough security to protect subscribers' privacy. To do this, we collect data by performing GUTI reallocation more than 30,000 times with 28 carriers across 11 countries using 78 SIM cards. Then, we investigate whether (1) these reallocated GUTIs in each carrier show noticeable patterns and (2) if they do, these patterns are consistent among different SIM cards within each carrier. Among 28 carriers, 19 carriers have easily predictable and consistent patterns in their GUTI reallocation mechanisms. Among the remaining 9 carriers, we revisit 4 carriers to investigate them in greater detail. For all these 4 carriers, we could find interesting yet predictable patterns after invoking GUTI reallocation multiple times within a short time period. By using this predictability, we show that an adversary can track subscribers' location as in previous studies. Finally, we present a lightweight and unpredictable GUTI reallocation mechanism as a solution.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper26
- Breaking LTE on Layer TwoDavid Rupprecht, Katharina Kohls, Thorsten Holz, Christina PöpperS&P 2019 · 被引用 219 次
- 5GReasoner: A Property-Directed Security and Privacy Analysis Framework for 5G Cellular Network ProtocolSyed Rafiul Hussain, Mitziu Echeverria, Imtiaz Karim, Omar Chowdhury 等CCS 2019 · 被引用 188 次
- Privacy Attacks to the 4G and 5G Cellular Paging Protocols Using Side Channel InformationSyed Rafiul Hussain, Mitziu Echeverria, Omar Chowdhury, Ninghui Li 等NDSS 2019 · 被引用 160 次
- A Billion Open Interfaces for Eve and Mallory: MitM, DoS, and Tracking Attacks on iOS and macOS Through Apple Wireless Direct LinkMilan Stute, Sashank Narain, Alex Mariotto, Alexander Heinrich 等USENIX Security 2019 · 被引用 59 次
- Pretty Good Phone PrivacyPaul Schmitt, Barath RaghavanUSENIX Security 2021 · 被引用 24 次
它引用的顶会 Paper2
- Practical Attacks Against Privacy and Availability in 4G/LTE Mobile Communication SystemsAltaf Shaik, Jean-Pierre Seifert, Ravishankar Borgaonkar, N. Asokan 等NDSS 2016 · 被引用 342 次
- FBS-Radar: Uncovering Fake Base Stations at Scale in the WildZhenhua Li, Weiwei Wang, Christo Wilson, Jian Chen 等NDSS 2017 · 被引用 92 次
相关 Paper
- Passive Multi-Target GUTI Identification via Visual-RF Correlation in LTE NetworksByeongdo Hong, Gunwoo YoonNDSS 2026 · 被引用 1 次
- CrossLink: Breaking Location Privacy by Linking Device Identifiers Across ProtocolsAneet Kumar Dutta, Mihirraj Dixit, Kevin Gni, Wouter Lueks 等CCS 2026
- LTrack: Stealthy Tracking of Mobile Phones in LTEMartin Kotuliak, Simon Erni, Patrick Leu, Marc Röschlin 等USENIX Security 2022
- AAKA: An Anti-Tracking Cellular Authentication Scheme Leveraging Anonymous CredentialsHexuan Yu, Changlai Du, Yang Xiao, Angelos D. Keromytis 等NDSS 2024
- LTEInspector: A Systematic Approach for Adversarial Testing of 4G LTESyed Rafiul Hussain, Omar Chowdhury, Shagufta Mehnaz, Elisa BertinoNDSS 2018 · 被引用 225 次
