{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,22]],"date-time":"2026-07-22T16:40:20Z","timestamp":1784738420905,"version":"3.55.0"},"reference-count":54,"publisher":"Privacy Enhancing Technologies Symposium Advisory Board","issue":"3","license":[{"start":{"date-parts":[[2019,7,1]],"date-time":"2019-07-01T00:00:00Z","timestamp":1561939200000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc-nd\/3.0"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2019,7,1]]},"abstract":"<jats:title>Abstract<\/jats:title>\n               <jats:p>Mobile communications are used by more than two-thirds of the world population who expect security and privacy guarantees. The <jats:italic>3rd Generation Partnership Project<\/jats:italic> (3GPP) responsible for the worldwide standardization of mobile communication has designed and mandated the use of the <jats:italic>AKA protocol<\/jats:italic> to protect the subscribers\u2019 mobile services. Even though privacy was a requirement, numerous subscriber location attacks have been demonstrated against AKA, some of which have been fixed or mitigated in the enhanced AKA protocol designed for 5G.<\/jats:p>\n               <jats:p>In this paper, we reveal a new privacy attack against all variants of the AKA protocol, including 5G AKA, that breaches subscriber privacy more severely than known location privacy attacks do. Our attack exploits a new logical vulnerability we uncovered that would require dedicated fixes. We demonstrate the practical feasibility of our attack using low cost and widely available setups. Finally we conduct a security analysis of the vulnerability and discuss countermeasures to remedy our attack.<\/jats:p>","DOI":"10.2478\/popets-2019-0039","type":"journal-article","created":{"date-parts":[[2019,7,20]],"date-time":"2019-07-20T09:31:05Z","timestamp":1563615065000},"page":"108-127","source":"Crossref","is-referenced-by-count":101,"title":["New Privacy Threat on 3G, 4G, and Upcoming 5G AKA Protocols"],"prefix":"10.56553","volume":"2019","author":[{"given":"Ravishankar","family":"Borgaonkar","sequence":"first","affiliation":[{"name":"SINTEF Digital , Norway ."}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lucca","family":"Hirschi","sequence":"additional","affiliation":[{"name":"Inria & LORIA , France ."}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shinjo","family":"Park","sequence":"additional","affiliation":[{"name":"Technische Universit\u00e4t Berlin , Germany ."}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Altaf","family":"Shaik","sequence":"additional","affiliation":[{"name":"Technische Universit\u00e4t , Berlin , Germany ."}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"35752","published-online":{"date-parts":[[2019,7,12]]},"reference":[{"key":"2022061417251689723_j_popets-2019-0039_ref_001_w2aab3b7b7b1b6b1ab1ab1Aa","unstructured":"[1] Tamarin tool code."},{"key":"2022061417251689723_j_popets-2019-0039_ref_002_w2aab3b7b7b1b6b1ab1ab2Aa","unstructured":"[2] 3GPP. 3G Security; Formal Analysis of the 3G Authentication Protocol. TS 33.902, (3GPP)."},{"key":"2022061417251689723_j_popets-2019-0039_ref_003_w2aab3b7b7b1b6b1ab1ab3Aa","unstructured":"[3] 3GPP. 3G security; Security architecture. TS 33.102, (3GPP)."},{"key":"2022061417251689723_j_popets-2019-0039_ref_004_w2aab3b7b7b1b6b1ab1ab4Aa","unstructured":"[4] 3GPP. 3G Security; Specification of the MILENAGE algorithm set: An example algorithm set for the 3GPP authentication and key generation functions f1, f1*, f2, f3, f4, f5 and f5*; Document 2: Algorithm specification. Technical Specification (TS) 35.206, (3GPP)."},{"key":"2022061417251689723_j_popets-2019-0039_ref_005_w2aab3b7b7b1b6b1ab1ab5Aa","unstructured":"[5] 3GPP. 3GPP System Architecture Evolution (SAE); Security architecture. TR 33.401, (3GPP)."},{"key":"2022061417251689723_j_popets-2019-0039_ref_006_w2aab3b7b7b1b6b1ab1ab6Aa","unstructured":"[6] 3GPP. AT command set for User Equipment (UE). TS 27.007, (3GPP)."},{"key":"2022061417251689723_j_popets-2019-0039_ref_007_w2aab3b7b7b1b6b1ab1ab7Aa","unstructured":"[7] 3GPP. SA3 - Security."},{"key":"2022061417251689723_j_popets-2019-0039_ref_008_w2aab3b7b7b1b6b1ab1ab8Aa","unstructured":"[8] 3GPP. Security architecture and procedures for 5G System. TS 33.501, (3GPP)."},{"key":"2022061417251689723_j_popets-2019-0039_ref_009_w2aab3b7b7b1b6b1ab1ab9Aa","unstructured":"[9] 3GPP. Service requirements for the Evolved Packet System (EPS). TS 122.278, (3GPP)."},{"key":"2022061417251689723_j_popets-2019-0039_ref_010_w2aab3b7b7b1b6b1ab1ac10Aa","unstructured":"[10] 3GPP. Specification of the TUAK algorithm set: A second example algorithm set for the 3GPP authentication and key generation functions f1, f1*, f2, f3, f4, f5 and f5*; Document 1: Algorithm specification. Technical Specification (TS) 35.231, (3GPP)."},{"key":"2022061417251689723_j_popets-2019-0039_ref_011_w2aab3b7b7b1b6b1ab1ac11Aa","unstructured":"[11] 3GPP. Study on subscriber privacy impact in 3GPP. TR 33.849, (3GPP)."},{"key":"2022061417251689723_j_popets-2019-0039_ref_012_w2aab3b7b7b1b6b1ab1ac12Aa","unstructured":"[12] 3GPP. Study on the security aspects of the next generation system. TR 33.899, (3GPP)."},{"key":"2022061417251689723_j_popets-2019-0039_ref_013_w2aab3b7b7b1b6b1ab1ac13Aa","unstructured":"[13] Advanced Card Systems Holdings Limited. ACR38 Smart Card Reader."},{"key":"2022061417251689723_j_popets-2019-0039_ref_014_w2aab3b7b7b1b6b1ab1ac14Aa","unstructured":"[14] Anand R. Prasad, Alf Zugenmaier, Adrian Escott and Mirko Cano Soveri. 3GPP 5G Security."},{"key":"2022061417251689723_j_popets-2019-0039_ref_015_w2aab3b7b7b1b6b1ab1ac15Aa","doi-asserted-by":"crossref","unstructured":"[15] Myrto Arapinis, Tom Chothia, Eike Ritter, and Mark Ryan. Analysing unlinkability and anonymity using the applied pi calculus. In 2010 23rd IEEE Computer Security Foundations Symposium, pages 107\u2013121. IEEE, 2010.10.1109\/CSF.2010.15","DOI":"10.1109\/CSF.2010.15"},{"key":"2022061417251689723_j_popets-2019-0039_ref_016_w2aab3b7b7b1b6b1ab1ac16Aa","doi-asserted-by":"crossref","unstructured":"[16] Myrto Arapinis, Loretta Mancini, Eike Ritter, Mark Ryan, Nico Golde, Kevin Redon, and Ravishankar Borgaonkar. New privacy issues in mobile telephony: fix and verification. In Proceedings of the 2012 ACM conference on Computer and communications security, pages 205\u2013216. ACM, 2012.10.1145\/2382196.2382221","DOI":"10.1145\/2382196.2382221"},{"key":"2022061417251689723_j_popets-2019-0039_ref_017_w2aab3b7b7b1b6b1ab1ac17Aa","unstructured":"[17] Jari Arkko. Extensible Authentication Protocol Method for 3rd Generation Authentication and Key Agreement (EAPAKA). RFC 4187."},{"key":"2022061417251689723_j_popets-2019-0039_ref_018_w2aab3b7b7b1b6b1ab1ac18Aa","doi-asserted-by":"crossref","unstructured":"[18] D. Basin, C. Cremers, K. Miyazaki, S. Radomirovic, and D. Watanabe. Improving the Security of Cryptographic Protocol Standards. IEEE Security Privacy, 13(3):24\u201331, May 2015.10.1109\/MSP.2013.162","DOI":"10.1109\/MSP.2013.162"},{"key":"2022061417251689723_j_popets-2019-0039_ref_019_w2aab3b7b7b1b6b1ab1ac19Aa","doi-asserted-by":"crossref","unstructured":"[19] David Basin, Jannik Dreier, Lucca Hirschi, Sa\u0161a Radomirovic, Ralf Sasse, and Vincent Stettler. A Formal Analysis of 5G Authentication. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, pages 1383\u20131396. ACM, 2018.10.1145\/3243734.3243846","DOI":"10.1145\/3243734.3243846"},{"key":"2022061417251689723_j_popets-2019-0039_ref_020_w2aab3b7b7b1b6b1ab1ac20Aa","doi-asserted-by":"crossref","unstructured":"[20] A. N. Bikos and N. Sklavos. LTE\/SAE Security Issues on 4G Wireless Networks. IEEE Security Privacy, 11(2):55\u201362, March 2013.10.1109\/MSP.2012.136","DOI":"10.1109\/MSP.2012.136"},{"key":"2022061417251689723_j_popets-2019-0039_ref_021_w2aab3b7b7b1b6b1ab1ac21Aa","unstructured":"[21] B. Blanchet. An Efficient Cryptographic Protocol Verifier Based on Prolog Rules. In Proceedings of CSFW\u201901, pages 82\u201396. IEEE Comp. Soc. Press, 2001."},{"key":"2022061417251689723_j_popets-2019-0039_ref_022_w2aab3b7b7b1b6b1ab1ac22Aa","doi-asserted-by":"crossref","unstructured":"[22] Vincent Cheval and Bruno Blanchet. Proving more observational equivalences with ProVerif. In Principles of Security and Trust, pages 226\u2013246. Springer, 2013.10.1007\/978-3-642-36830-1_12","DOI":"10.1007\/978-3-642-36830-1_12"},{"key":"2022061417251689723_j_popets-2019-0039_ref_023_w2aab3b7b7b1b6b1ab1ac23Aa","unstructured":"[23] Stephanie Clifford and Quentin Hardy. Attention Shoppers: Store is Tracking Your Cell. New York Times, 14, 2013."},{"key":"2022061417251689723_j_popets-2019-0039_ref_024_w2aab3b7b7b1b6b1ab1ac24Aa","doi-asserted-by":"crossref","unstructured":"[24] S. Delaune and L. Hirschi. A survey of symbolic methods for establishing equivalence-based properties in cryptographic protocols. ArXiv e-prints, October 2016.10.1016\/j.jlamp.2016.10.005","DOI":"10.1016\/j.jlamp.2016.10.005"},{"key":"2022061417251689723_j_popets-2019-0039_ref_025_w2aab3b7b7b1b6b1ab1ac25Aa","doi-asserted-by":"crossref","unstructured":"[25] Jannik Dreier, Lucca Hirschi, Sasa Radomirovic, and Ralf Sasse. Automated Unbounded Verification of Stateful Cryptographic Protocols with Exclusive OR. In 31st IEEE Computer Security Foundations Symposium (CSF\u20192018), 2018.10.1109\/CSF.2018.00033","DOI":"10.1109\/CSF.2018.00033"},{"key":"2022061417251689723_j_popets-2019-0039_ref_026_w2aab3b7b7b1b6b1ab1ac26Aa","unstructured":"[26] Tobias Engel. Locating Mobile Phones using Signalling System 7. https:\/\/berlin.ccc.de\/~tobias\/25c3-locating-mobile-phones.pdf."},{"key":"2022061417251689723_j_popets-2019-0039_ref_027_w2aab3b7b7b1b6b1ab1ac27Aa","unstructured":"[27] Ettus Research. USRP B210."},{"key":"2022061417251689723_j_popets-2019-0039_ref_028_w2aab3b7b7b1b6b1ab1ac28Aa","doi-asserted-by":"crossref","unstructured":"[28] Dan Forsberg, Gnther Horn, Wolf-Dietrich Moeller, and Valtteri Niemi. LTE Security. Wiley Publishing, 2nd edition, 2012.10.1002\/9781118380642","DOI":"10.1002\/9781118380642"},{"key":"2022061417251689723_j_popets-2019-0039_ref_029_w2aab3b7b7b1b6b1ab1ac29Aa","unstructured":"[29] Gamry Instrumens. Faraday Cage: What Is It? How Does It Work?"},{"key":"2022061417251689723_j_popets-2019-0039_ref_030_w2aab3b7b7b1b6b1ab1ac30Aa","unstructured":"[30] Ismael Gomez-Miguelez, Andres Garcia-Saavedra, Paul D. Sutton, Pablo Serrano, Cristina Cano, and Douglas J. Leith. srsLTE: An Open-Source Platform for LTE Evolution and Experimentation. CoRR, abs\/1602.04629, 2016."},{"key":"2022061417251689723_j_popets-2019-0039_ref_031_w2aab3b7b7b1b6b1ab1ac31Aa","unstructured":"[31] GSMA. Definitive data and analysis for the mobile industry. https:\/\/www.gsmaintelligence.com\/."},{"key":"2022061417251689723_j_popets-2019-0039_ref_032_w2aab3b7b7b1b6b1ab1ac32Aa","doi-asserted-by":"crossref","unstructured":"[32] Changhee Hahn, Hyunsoo Kwon, Daeyoung Kim, Kyungtae Kang, and Junbeom Hur. A Privacy Threat in 4th Generation Mobile Telephony and Its Countermeasure. The 9th International Conference on Wireless Algorithms, Systems, and Applications, pages 624\u2013635, 2014.10.1007\/978-3-319-07782-6_56","DOI":"10.1007\/978-3-319-07782-6_56"},{"key":"2022061417251689723_j_popets-2019-0039_ref_033_w2aab3b7b7b1b6b1ab1ac33Aa","unstructured":"[33] Lucca Hirschi, David Baelde, and St\u00e9phanie Delaune. A method for verifying privacy-type properties: the unbounded case. In Michael Locasto, Vitaly Shmatikov, and Ulfar Erlingsson, editors, Proceedings of the 37th IEEE Symposium on Security and Privacy (S&P\u201916)."},{"key":"2022061417251689723_j_popets-2019-0039_ref_034_w2aab3b7b7b1b6b1ab1ac34Aa","doi-asserted-by":"crossref","unstructured":"[34] M. Khan, A. Ahmed, and A. R. Cheema. Vulnerabilities of UMTS Access Domain Security Architecture. In Software Engineering, Artificial Intelligence, Networking, and Parallel\/Distributed Computing, 2008. SNPD \u201908. Ninth ACIS International Conference on, pages 350\u2013355, Aug 2008.10.1109\/SNPD.2008.78","DOI":"10.1109\/SNPD.2008.78"},{"key":"2022061417251689723_j_popets-2019-0039_ref_035_w2aab3b7b7b1b6b1ab1ac35Aa","doi-asserted-by":"crossref","unstructured":"[35] Mohammed Shafiul Alam Khan and Chris J Mitchell. Another look at privacy threats in 3G mobile telephony. In Australasian Conference on Information Security and Privacy, pages 386\u2013396. Springer, 2014.10.1007\/978-3-319-08344-5_25","DOI":"10.1007\/978-3-319-08344-5_25"},{"key":"2022061417251689723_j_popets-2019-0039_ref_036_w2aab3b7b7b1b6b1ab1ac36Aa","doi-asserted-by":"crossref","unstructured":"[36] F. Y. Leu, I. You, Y. L. Huang, K. Yim, and C. R. Dai. Improving security level of LTE authentication and key agreement procedure. In 2012 IEEE Globecom Workshops, pages 1032\u20131036, Dec 2012.10.1109\/GLOCOMW.2012.6477719","DOI":"10.1109\/GLOCOMW.2012.6477719"},{"key":"2022061417251689723_j_popets-2019-0039_ref_037_w2aab3b7b7b1b6b1ab1ac37Aa","doi-asserted-by":"crossref","unstructured":"[37] X. Li and Y. Wang. Security Enhanced Authentication and Key Agreement Protocol for LTE\/SAE Network. In Wireless Communications, Networking and Mobile Computing (WiCOM), 2011 7th International Conference on, pages 1\u20134, Sept 2011.10.1109\/wicom.2011.6040169","DOI":"10.1109\/wicom.2011.6040169"},{"key":"2022061417251689723_j_popets-2019-0039_ref_038_w2aab3b7b7b1b6b1ab1ac38Aa","doi-asserted-by":"crossref","unstructured":"[38] S. Meier, B. Schmidt, C. Cremers, and D. Basin. The Tamarin Prover for the Symbolic Analysis of Security Protocols. In Proc. 25th International Conference on Computer Aided Verification (CAV\u201913), volume 8044 of LNCS, pages 696\u2013701. Springer, 2013.10.1007\/978-3-642-39799-8_48","DOI":"10.1007\/978-3-642-39799-8_48"},{"key":"2022061417251689723_j_popets-2019-0039_ref_039_w2aab3b7b7b1b6b1ab1ac39Aa","doi-asserted-by":"crossref","unstructured":"[39] ABM Musa and Jakob Eriksson. Tracking unmodified smart-phones using Wi-Fi monitors. In Proceedings of the 10th ACM conference on embedded network sensor systems, pages 281\u2013294. ACM, 2012.10.1145\/2426656.2426685","DOI":"10.1145\/2426656.2426685"},{"key":"2022061417251689723_j_popets-2019-0039_ref_040_w2aab3b7b7b1b6b1ab1ac40Aa","doi-asserted-by":"crossref","unstructured":"[40] Piers O\u2019Hanlon, Ravishankar Borgaonkar, and Lucca Hirschi. Mobile subscriber WiFi privacy. In Proceedings of Mobile Security Technologies (MoST\u201917), held as part of the IEEE Computer Society Security and Privacy Workshops (SPW\u201917), 2017. To appear.10.1109\/SPW.2017.14","DOI":"10.1109\/SPW.2017.14"},{"key":"2022061417251689723_j_popets-2019-0039_ref_041_w2aab3b7b7b1b6b1ab1ac41Aa","unstructured":"[41] Open5GCore. Open5GCore \u2013 The Next Mobile Core Network Testbed Platform."},{"key":"2022061417251689723_j_popets-2019-0039_ref_042_w2aab3b7b7b1b6b1ab1ac42Aa","unstructured":"[42] OpenAirInterface. History."},{"key":"2022061417251689723_j_popets-2019-0039_ref_043_w2aab3b7b7b1b6b1ab1ac43Aa","unstructured":"[43] Osmocom Project. pySIM: A python tool to program magic SIMs. http:\/\/cgit.osmocom.org\/pysim\/."},{"key":"2022061417251689723_j_popets-2019-0039_ref_044_w2aab3b7b7b1b6b1ab1ac44Aa","unstructured":"[44] PC\/SC Workgroup. PC\/SC Workgroup Specifications."},{"key":"2022061417251689723_j_popets-2019-0039_ref_045_w2aab3b7b7b1b6b1ab1ac45Aa","unstructured":"[45] Peter Howard. AKA usage in 3GPP."},{"key":"2022061417251689723_j_popets-2019-0039_ref_046_w2aab3b7b7b1b6b1ab1ac46Aa","unstructured":"[46] SecT- TU Berlin. SCAT: Signaling Collection and Analysis Tool."},{"key":"2022061417251689723_j_popets-2019-0039_ref_047_w2aab3b7b7b1b6b1ab1ac47Aa","doi-asserted-by":"crossref","unstructured":"[47] Altaf Shaik, Jean-Pierre Seifert, Ravishankar Borgaonkar, N. Asokan, and Valtteri Niemi. Practical Attacks Against Privacy and Availability in 4G\/LTE Mobile Communication Systems. In 23nd Annual Network and Distributed System Security Symposium, NDSS 2016, San Diego, California, USA, February 21-24, 2016.10.14722\/ndss.2016.23236","DOI":"10.14722\/ndss.2016.23236"},{"key":"2022061417251689723_j_popets-2019-0039_ref_048_w2aab3b7b7b1b6b1ab1ac48Aa","unstructured":"[48] Sysmocom. sysmoUSIM-SJS1."},{"key":"2022061417251689723_j_popets-2019-0039_ref_049_w2aab3b7b7b1b6b1ab1ac49Aa","unstructured":"[49] Telegraphy. TeliaSonera launches world\u2019s first commercial LTE networks in Sweden and Norway."},{"key":"2022061417251689723_j_popets-2019-0039_ref_050_w2aab3b7b7b1b6b1ab1ac50Aa","unstructured":"[50] Swapnil Udar and Ravishankar Borgaonkar. Understanding IMSI Privacy. https:\/\/www.isti.tu-berlin.de\/fileadmin\/fg214\/ravi\/Darshak-bh14.pdf."},{"key":"2022061417251689723_j_popets-2019-0039_ref_051_w2aab3b7b7b1b6b1ab1ac51Aa","doi-asserted-by":"crossref","unstructured":"[51] Fabian van den Broek, Roel Verdult, and Joeri de Ruiter. Defeating IMSI Catchers. Proceedings of the 2015 ACM Conference on Computer and Communications Security -CCS \u201915, 2015.10.1145\/2810103.2813615","DOI":"10.1145\/2810103.2813615"},{"key":"2022061417251689723_j_popets-2019-0039_ref_052_w2aab3b7b7b1b6b1ab1ac52Aa","unstructured":"[52] Venturebeat. DEMO: Range Networks rings in cell-phone service for USD 2 a month."},{"key":"2022061417251689723_j_popets-2019-0039_ref_053_w2aab3b7b7b1b6b1ab1ac53Aa","unstructured":"[53] Ben Wojtowicz. OpenLTE. https:\/\/sourceforge.net\/projects\/openlte\/."},{"key":"2022061417251689723_j_popets-2019-0039_ref_054_w2aab3b7b7b1b6b1ab1ac54Aa","doi-asserted-by":"crossref","unstructured":"[54] Muxiang Zhang and Yuguang Fang. Security analysis and enhancements of 3GPP authentication and key agreement protocol. IEEE Transactions on Wireless Communications, 4(2):734\u2013742, March 2005.10.1109\/TWC.2004.842941","DOI":"10.1109\/TWC.2004.842941"}],"container-title":["Proceedings on Privacy Enhancing Technologies"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/content.sciendo.com\/view\/journals\/popets\/2019\/3\/article-p108.xml","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.sciendo.com\/pdf\/10.2478\/popets-2019-0039","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,7,20]],"date-time":"2022-07-20T16:30:29Z","timestamp":1658334629000},"score":1,"resource":{"primary":{"URL":"https:\/\/petsymposium.org\/popets\/2019\/popets-2019-0039.php"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,7,1]]},"references-count":54,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2019,7,12]]},"published-print":{"date-parts":[[2019,7,1]]}},"alternative-id":["10.2478\/popets-2019-0039"],"URL":"https:\/\/doi.org\/10.2478\/popets-2019-0039","relation":{},"ISSN":["2299-0984"],"issn-type":[{"value":"2299-0984","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,7,1]]}}}