Source-linked AI summary
Security for 4G and 5G Cellular Networks: A Survey of Existing Authentication and Privacy-preserving Schemes
Mohamed Amine Ferrag, Leandros Maglaras, Antonios Argyriou, Dimitrios Kosmanos, Helge Janicke
TL;DR
4G and 5G cellular networks require authentication and privacy protection amid threats spanning privacy, integrity, availability, and authentication. The paper surveys existing schemes and related surveys, classifies threats, countermeasures, analyses, and scheme types, and compares the state of the art. It concludes with six open research directions for authentication and privacy preservation in emerging 5G settings.
Problem
Existing surveys did not thoroughly cover authentication and privacy-preservation issues for 4G and 5G networks, despite vulnerabilities associated with 5G’s openness and IP-based architecture.
Method
The paper conducts an extensive literature survey and classifies threats, countermeasures, security-analysis techniques, and authentication and privacy-preserving schemes.
Results
The survey identifies four threat categories, three countermeasure categories, twelve security-analysis techniques, and seven scheme types for 4G and 5G cellular networks.
Takeaways & Limitations
The paper proposes six open research directions covering Fog-based RANs, small-cell smart grids, SDN/NFV, intrusion-detection datasets, UAV systems, and vehicular crowdsensing.
Abstract
from arXiv · showhide
This paper presents a comprehensive survey of existing authentication and privacy-preserving schemes for 4G and 5G cellular networks. We start by providing an overview of existing surveys that deal with 4G and 5G communications, applications, standardization, and security. Then, we give a classification of threat models in 4G and 5G cellular networks in four categories, including, attacks against privacy, attacks against integrity, attacks against availability, and attacks against authentication. We also provide a classification of countermeasures into three types of categories, including, cryptography methods, humans factors, and intrusion detection methods. The countermeasures and informal and formal security analysis techniques used by the authentication and privacy preserving schemes are summarized in form of tables. Based on the categorization of the authentication and privacy models, we classify these schemes in seven types, including, handover authentication with privacy, mutual authentication with privacy, RFID authentication with privacy, deniable authentication with privacy, authentication with mutual anonymity, authentication and key agreement with privacy, and three-factor authentication with privacy. In addition, we provide a taxonomy and comparison of authentication and privacy-preserving schemes for 4G and 5G cellular networks in form of tables. Based on the current survey, several recommendations for further research are discussed at the end of this paper.
I. INTRODUCTION
5G expands cellular-network capacity, speed, and connectivity while introducing vulnerabilities across access control, confidentiality, availability, and privacy. This paper surveys authentication and privacy-preserving schemes, classifies threats and countermeasures, and identifies future research directions.
- 5G context: 5G offers bit rates above 10 gigabits per second, greater capacity, and very low latency for billions of connected IoT objects.The paper links these capabilities to a fully mobile and connected society with new network services.
- 5G context: Blending wireless technologies and providers through an IP-based core enables switching between technologies and providers to maintain QoS.The network’s openness and fast vertical handover also expose devices to access-control, communication-security, confidentiality, availability, and privacy vulnerabilities.
- Paper scope: The survey classifies cellular-network threats into attacks against privacy, integrity, availability, and authentication.It also discusses existing surveys covering communications, applications, standardization, and security.
- Paper scope: Countermeasures are organized into cryptography methods, human factors, and intrusion-detection methods, alongside informal and formal security-analysis techniques.These classifications structure the paper’s review of authentication and privacy-preserving schemes.
- Paper scope: Authentication and privacy-preserving schemes are classified into seven types, including handover, mutual, RFID, deniable, anonymous, key-agreement, and three-factor approaches.The paper also proposes six future directions spanning Fog-based RANs, smart grids, SDN/NFV, intrusion-detection datasets, UAVs, and vehicular crowdsensing.
II. EXISTING SURVEYS FOR 4G AND 5G CELLULAR NETWORKS
The paper reviews existing surveys of 4G and 5G communications, applications, standardization, and security, identifying limited coverage of authentication and privacy preservation. It positions this survey as a focused, thorough analysis of those issues.
- Existing survey landscape: Around fifty survey articles on 4G and 5G communications, applications, standardization, and security were categorized.The articles were retrieved from SCOPUS and Web of Science and published from 2007 to 2017.
- Existing survey landscape: Only seven previous surveys addressed security and privacy issues for 3G, 4G, and 5G cellular networks.
- Identified gap: Previous work did not comprehensively cover authentication and privacy-preserving issues in 4G and 5G networks.Authentication and privacy preservation was covered only partially by Cao et al., while other surveys did not cover this major aspect.
- This survey’s contribution: This survey analyzes authentication and privacy-preserving protocols for 4G/5G networks and identifies open issues and future directions.The authors intend the study to guide researchers toward important authentication and privacy-preservation topics.
III. THREAT MODELS AND COUNTERMEASURES
The survey organizes 4G and 5G threats by attack behavior and presents a structured view of existing survey coverage and security countermeasures. Its threat classification uses four categories spanning privacy, integrity, availability, and authentication.
- Threat models: Thirty-five attacks analyzed in 4G and 5G cellular networks are classified according to attack behavior.The classification uses four categories: attacks against privacy, integrity, availability, and authentication.
- Threat models: The four threat categories are attacks against privacy, attacks against integrity, attacks against availability, and attacks against authentication.
- Survey organization: The paper compares related surveys and categorizes research areas addressed by surveys of 4G and 5G cellular networks.
2) Attacks against integrity:
For integrity and related security protection, the surveyed schemes use cryptographic mechanisms, human-factor countermeasures, and security-analysis techniques. Hash functions are emphasized for data integrity, while cryptographic schemes include public-key, symmetric-key, and unkeyed methods.
- Attacks against integrity: Integrity attacks include spam, message blocking, cloning, message modification, message insertion, and tampering attacks.The paper notes that spam attacks may also be classified as availability attacks.
- Cryptography methods: Authentication and privacy-preserving schemes mostly use hash functions to assure the integrity of transmitted data.The paper identifies MAC, HMAC, and AMAC as popular hash-based methods.
- Countermeasures: Countermeasures for 4G and 5G authentication and privacy preservation also include human factors and intrusion detection methods.
- Cryptography methods: Cryptographic methods are classified into public-key cryptography, symmetric-key cryptography, and unkeyed cryptography.
- Cryptography methods: Public-key schemes use mechanisms including PKI, the Paillier cryptosystem, blind signatures, Rabin’s cryptosystem, and group signatures.PKI is used to identify genuine access points or base stations; Paillier encryption uses key generation, encryption, and decryption.
- Cryptography methods: Symmetric encryption is used by four schemes to provide user anonymity, including AES-based and entirely symmetric-key authentication approaches.
2) Humans factors:
Human-factor countermeasures use knowledge, possession, and biometric identity as authentication factors, each with distinct practical considerations.
- Humans factors: Human-factor countermeasures use three factors: what you know, what you have, and who you are.Examples include passwords or PINs, tokens or smart cards, and fingerprints or iris scans.
- Humans factors: Knowledge-based methods may be divulged or forgotten, while possession-based methods use items such as tokens, smart cards, passcodes, or RFID.
3) Intrusion detection methods:
Intrusion detection systems provide a second defense stage after preventive countermeasures, while surveyed security analyses use tool-assisted and tool-free techniques to evaluate schemes. The reviewed methods span statistical, probabilistic, neural, fuzzy, packet-inspection, and formal verification approaches.
- Intrusion detection methods: Intrusion detection systems must rapidly identify misbehavior after an attacker bypasses existing countermeasures and controls a legitimate network entity.The section describes IDS as the second stage of defense.
- Intrusion detection methods: Hidden Markov Models detect bandwidth-spoofing intrusions at 5G small-cell access points, while neural and neuro-fuzzy methods target network anomalies.The reviewed approaches include Random Neural Networks and Adaptive Neuro-Fuzzy Inference Systems.
- Intrusion detection methods: Random packet inspection dynamically adjusts inspection rates to balance deep-packet detection of malicious signatures with inspection efficiency.The scheme is discussed for LTE networks.
- Intrusion detection methods: TermID addresses wireless-sensor-network intrusions while targeting low network footprint and user privacy under dynamic conditions and limited bandwidth.Its evaluation uses the Aegean wireless intrusion dataset version 2.
- Intrusion detection methods: IDS effectiveness depends on intruder intelligence, and intrusion-response systems require false-alarm handling because they cannot manage IDS-generated false alarms.The survey identifies false-alarm handling as an important future IDS/IRS component.
- Security analysis techniques: Security analysis is divided into techniques without implementation tools and techniques with implementation tools, covering formal and informal evaluation of cryptographic schemes.Tool-free methods include eight listed techniques, while tool-assisted methods include AVISPA, MIT Kerberos, OpenUAT, and ProVerif.
A. Handover authentication with privacy
Handover authentication schemes for LTE and heterogeneous 4G/5G networks are classified by cryptographic basis and evaluated for security, privacy, and efficiency. The surveyed schemes provide capabilities such as anonymity, forward secrecy, unlinkability, and reduced overhead, but some privacy or secrecy properties remain unaddressed.
- Cryptographic classification: LTE handover authentication schemes are classified as symmetric-key, public-key, or hybrid schemes across eNodeB and HeNB mobility scenarios.The survey notes that the 3GPP-suggested handover cannot achieve backward security in some transitions.
- Privacy-preserving handover: Scheme supports perfect forward secrecy, master key forward secrecy, and user anonymity across LTE mobility scenarios while reducing computational, communication, and storage costs.The survey presents these as strong security guarantees and efficiency properties.
- Remaining limitations: The surveyed schemes leave identifiable gaps: schemes and omit identity and location privacy, while Nframe omits perfect forward and backward secrecy.The survey also notes that scheme does not consider k-anonymity for location privacy.
- Privacy-preserving handover: Scheme uses a pseudonym-based three-way handshake to provide fast handover, mutual authentication, key agreement, and privacy preservation.It is reported as more efficient in computation and communication overhead than Fu et al.’s earlier scheme.
- Privacy-preserving handover: NAHAP provides group-based anonymity and key derivation for LTE-A mobility scenarios with lower signaling, communication, and computational costs than the LTE-A handover mechanism.UGHA is described as another uniform group-based handover authentication protocol from the same authors.
- Privacy-preserving handover: Scheme targets unlinkability and traceability in 4G/5G heterogeneous communications and is reported to reduce signaling and computation overhead against Cao’s scheme and SE-AKA.The passage characterizes it as a privacy-preserving group authentication protocol.
B. Mutual authentication with privacy
Mutual-authentication schemes for 4G/5G must protect location and identity privacy alongside integrity and authenticity. The survey highlights approaches for location privacy, identity management, IoT-enabled LTE, and privacy-preserving applications.
- Mutual authentication with privacy requires location privacy, identity privacy, data integrity, and authenticity.
- Several surveyed protocols protect identity privacy but omit location privacy, while BIO3G also cannot resist denial-of-service attacks.
- Lu et al. proposed mutual authentication with provable link-layer location privacy and reported efficiency in packet delay and total packet time cost.
- AIM provides mutual authentication, privacy, and tracking avoidance for 4G networks through an identity-management mechanism.
- The mIPS location-aware mobile intrusion prevention system preserves personal privacy profiles but still requires evaluation for 5G communications.
- A privacy-preserving LTE-A scheme for smart-meter communications combines key agreement with mutual authentication, confidentiality, integrity, authenticity, and key evolution.
C. RFID authentication with privacy
RFID privacy-preserving authentication schemes target mutual authentication, anonymity, untraceability, integrity, availability, and resistance to desynchronization. The surveyed approaches emphasize lightweight operations and suitability for low-cost or IoT deployments.
- RFID systems use tags, readers, and back-end databases to identify objects without physical contact.
- SASI provides strong authentication and integrity protection using only simple bit-wise operations on RFID tags.
- An ECC-based RFID protocol achieves mutual authentication, anonymity, untraceability, and availability, with lower computation complexity than LMAP.
- An index-pseudonym protocol provides tag privacy, forward security, location privacy, integrity, tag anonymity, and resistance to desynchronization.
- A modified EAP-AKA mechanism improves performance by 50 percent over an earlier multipass authentication scheme.
- LRMAPC supports 5G IoT authentication through lightweight mutual authentication with reader caching and forward security.
- EAP is a wireless-network authentication framework defined through RFC 3748, RFC 2284, and RFC 5247.
E. Authentication with mutual anonymity
Authentication with mutual anonymity addresses user privacy and service-access traceability across cellular and related wireless systems. The surveyed mechanisms include anonymous authentication, privacy architectures, secure data sharing, and auxiliary-channel protocols.
- Anonymity protects cellular users’ privacy, and the PT protocol supports anonymous authentication and trust management in peer-to-peer systems.
- PrivaKERB addresses user anonymity and service-access untraceability through two privacy levels based on pseudonyms.
- PrivaKERB’s second privacy level adds service-access untraceability to user anonymity.
- SeDS combines digital signatures and symmetric encryption to support confidentiality, integrity, non-repudiation, and availability in 4G LTE-Advanced D2D communication.
- UACAP uses Diffie-Hellman key exchange with precommitment followed by out-of-band key verification.
G. Three-factor authentication with privacy
Three-factor authentication with privacy is organized around smart cards, passwords, and biometrics. The survey also compares authentication models, security-analysis techniques, and privacy models represented across the reviewed schemes.
- Three-factor privacy-preserving schemes are classified into smart-card-based, password-based, and biometric-based protocols.
- Biometric systems are classified as traditional, wearable, or hybrid systems.
- Privacy-preserving fingerprint authentication is designed so the client does not learn anything about the database.
- Password-based protocols aim to protect identity and provide strong mutual authentication in 4G and 5G networks.
- oPass uses one-time passwords to address password stealing and password reuse attacks simultaneously.
- An improved smart-card password scheme provides mutual authentication and forward secrecy while reducing server-side computation cost relative to three compared schemes.
- The survey identifies four main authentication models and compares AVISPA, ProVerif, game theory, and GNY logic for security analysis.
- The reviewed privacy models include identity privacy, RFID privacy, untraceability, anonymity, and location privacy.
A. Privacy preservation for Fog paradigm-based 5G radio access network
The paper identifies privacy and intrusion-detection challenges across fog-based 5G architectures and related virtualized networks. It highlights privacy-preservation gaps and the need for intrusion-detection datasets suited to 5G scenarios.
- A. Privacy preservation for Fog paradigm-based 5G radio access network: F-RAN architectures introduce privacy threats including man-in-the-middle and replay attacks.The cited discussion concerns loosely coupled and tightly coupled approaches for integrating computing functionality into 5G cellular networks.
- A. Privacy preservation for Fog paradigm-based 5G radio access network: 5G small-cell smart-grid planning can reduce energy-production cost by 30%, but the cited calculation excludes possible network security concerns.
- A. Privacy preservation for Fog paradigm-based 5G radio access network: SDN/NFV-based mobile packet-core surveys had not studied privacy preservation, leaving it as a proposed research direction.
- A. Privacy preservation for Fog paradigm-based 5G radio access network: 5G intrusion-detection research commonly relies on DARPA 1998–2000 or KDD 1999 datasets, whose suitability for 5G scenarios is questioned.The paper calls for new datasets to build network intrusion detectors under 5G environments.
E. Privacy preserving schemes for UAV systems in 5G heterogeneous communication environment
The paper situates UAV security and privacy within broader 5G authentication research, organizing existing countermeasures, analysis techniques, and scheme types. It also identifies UAV systems as one of six open directions for future work.
- E. Privacy preserving schemes for UAV systems in 5G heterogeneous communication environment: UAV deployment in 5G heterogeneous communication environments faces security and privacy challenges alongside drones’ limited wireless and computing capabilities.The paper describes UAV applications as becoming more complicated because of these limitations.
- E. Privacy preserving schemes for UAV systems in 5G heterogeneous communication environment: Surveyed countermeasures span public-key, symmetric-key, and unkeyed cryptography; knowledge, possession, and biometric factors; and signature-based, anomaly-based, and hybrid intrusion detection.
- E. Privacy preserving schemes for UAV systems in 5G heterogeneous communication environment: The survey identifies twelve informal and formal security-analysis techniques and classifies them by whether they use an implementation tool.Named tools include AVISPA, Open-source MIT Kerberos, OpenUAT, and ProVerif.
- E. Privacy preserving schemes for UAV systems in 5G heterogeneous communication environment: Authentication and privacy-preserving schemes are classified into seven types, including handover, mutual, RFID, deniable, mutual-anonymity, key-agreement, and three-factor schemes.
- E. Privacy preserving schemes for UAV systems in 5G heterogeneous communication environment: UAV systems in 5G environments are one of six proposed open research directions for authentication and privacy-preserving schemes.The other directions address fog-based RAN, smart grids, SDN/NFV architectures, intrusion-detection datasets, and vehicular crowdsensing.