Security and Protocol Exploit Analysis of the 5G Specifications
Roger Piqueras Jover, Vuk Marojevic

TL;DR
This paper critically analyzes 5G security specifications, revealing potential vulnerabilities and unrealistic assumptions that could compromise user privacy, security, and network availability despite improvements over previous generations.
Contribution
It provides a comprehensive evaluation of 5G security protocols, identifying gaps and edge cases that may lead to vulnerabilities not fully addressed in the specifications.
Findings
Potential vulnerabilities due to null encryption and null authentication.
Edge cases that could compromise user privacy and network security.
Limitations in the scope of security functions and assumptions about key management.
Abstract
The Third Generation Partnership Project (3GPP) released its first 5G security specifications in March 2018. This paper reviews the 5G security architecture, requirements and main processes and evaluates them in the context of known and new protocol exploits. Although the security has been enhanced when compared to previous generations to tackle known protocol exploits, our analysis identifies some potentially unrealistic system assumptions that are critical for security as well as a number protocol edge cases that could render 5G systems vulnerable to adversarial attacks. For example, null encryption and null authentication are supported and can be used in valid system configurations, and certain key security functions are still left outside of the scope of the specifications. Moreover, the prevention of pre-authentcation message exploits appears to rely on the implicit assumption of…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Authentication Protocols Security · Wireless Communication Security Techniques · Internet Traffic Analysis and Secure E-voting
