A Systematic Security Analysis for Beyond 5G Non-Access Stratum Protocol from the Perspective of Network Coexistence

IF 6.9 3区 管理学 Q1 COMPUTER SCIENCE, INFORMATION SYSTEMS
Zhiwei Cui, Baojiang Cui, Jie Xu, Junsong Fu
{"title":"A Systematic Security Analysis for Beyond 5G Non-Access Stratum Protocol from the Perspective of Network Coexistence","authors":"Zhiwei Cui, Baojiang Cui, Jie Xu, Junsong Fu","doi":"10.1007/s10796-025-10586-2","DOIUrl":null,"url":null,"abstract":"<p>The Beyond 5G (B5G) network promotes the development of all sectors of society and greatly changes our lives. To provide subscribers with better security and privacy protection, the 3rd Generation Partnership Project (3GPP) has enhanced the Non-Access Stratum (NAS) protocol for B5G. It is crucial to analyze the security of NAS protocol and confirm whether it achieves security goals. However, previous work mainly considered the issues in B5G standard, while overlooking the fact that 4G and B5G networks coexist in actual mobile network operators. In this paper, we provide the first systematic security analysis model for B5G NAS protocol under the assumption of network coexistence. We identified 9 protocol vulnerabilities, including one never reported before. This new vulnerability could be exploited to track the target user. We have reported the novel vulnerability to the GSM Association (GSMA) and obtained a tracking number CVD-2022-0058.</p>","PeriodicalId":13610,"journal":{"name":"Information Systems Frontiers","volume":"35 1","pages":""},"PeriodicalIF":6.9000,"publicationDate":"2025-02-18","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Information Systems Frontiers","FirstCategoryId":"94","ListUrlMain":"https://doi.org/10.1007/s10796-025-10586-2","RegionNum":3,"RegionCategory":"管理学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
引用次数: 0

Abstract

The Beyond 5G (B5G) network promotes the development of all sectors of society and greatly changes our lives. To provide subscribers with better security and privacy protection, the 3rd Generation Partnership Project (3GPP) has enhanced the Non-Access Stratum (NAS) protocol for B5G. It is crucial to analyze the security of NAS protocol and confirm whether it achieves security goals. However, previous work mainly considered the issues in B5G standard, while overlooking the fact that 4G and B5G networks coexist in actual mobile network operators. In this paper, we provide the first systematic security analysis model for B5G NAS protocol under the assumption of network coexistence. We identified 9 protocol vulnerabilities, including one never reported before. This new vulnerability could be exploited to track the target user. We have reported the novel vulnerability to the GSM Association (GSMA) and obtained a tracking number CVD-2022-0058.

基于网络共存视角的超5G非接入层协议系统安全性分析
超5G (B5G)网络促进了社会各界的发展,极大地改变了我们的生活。为了给用户提供更好的安全和隐私保护,第三代合作伙伴计划(3GPP)对B5G的非接入层(NAS)协议进行了增强。分析NAS协议的安全性,确认其是否达到安全目标是至关重要的。然而,以往的工作主要考虑的是B5G标准的问题,忽略了4G和B5G网络在实际移动网络运营商中并存的事实。本文首次提出了基于网络共存假设的B5G NAS协议系统安全分析模型。我们确定了9个协议漏洞,包括一个以前从未报道过的漏洞。这个新漏洞可能被利用来跟踪目标用户。我们已经向GSM协会(GSMA)报告了这个新的漏洞,并获得了跟踪号CVD-2022-0058。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
Information Systems Frontiers
Information Systems Frontiers 工程技术-计算机:理论方法
CiteScore
13.30
自引率
18.60%
发文量
127
审稿时长
9 months
期刊介绍: The interdisciplinary interfaces of Information Systems (IS) are fast emerging as defining areas of research and development in IS. These developments are largely due to the transformation of Information Technology (IT) towards networked worlds and its effects on global communications and economies. While these developments are shaping the way information is used in all forms of human enterprise, they are also setting the tone and pace of information systems of the future. The major advances in IT such as client/server systems, the Internet and the desktop/multimedia computing revolution, for example, have led to numerous important vistas of research and development with considerable practical impact and academic significance. While the industry seeks to develop high performance IS/IT solutions to a variety of contemporary information support needs, academia looks to extend the reach of IS technology into new application domains. Information Systems Frontiers (ISF) aims to provide a common forum of dissemination of frontline industrial developments of substantial academic value and pioneering academic research of significant practical impact.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信