+ All Categories
Home > Documents > Mobile Privacy in 2025 - Black Hat...3 •First demonstration in 1877 –Stockholm, Sweden...

Mobile Privacy in 2025 - Black Hat...3 •First demonstration in 1877 –Stockholm, Sweden...

Date post: 27-Apr-2020
Category:
Upload: others
View: 1 times
Download: 0 times
Share this document with a friend
21
Mobile Privacy in 2025 Dr. Ravishankar Borgaonkar Kaitiaki Labs LLP & University of Oxford 21 September 2017
Transcript
Page 1: Mobile Privacy in 2025 - Black Hat...3 •First demonstration in 1877 –Stockholm, Sweden •“Telephone is the instrument of Devil” ** •Innovations -wireline (1877) to wireless

MobilePrivacyin2025Dr. RavishankarBorgaonkar

KaitiakiLabsLLP&UniversityofOxford

21September2017

Page 2: Mobile Privacy in 2025 - Black Hat...3 •First demonstration in 1877 –Stockholm, Sweden •“Telephone is the instrument of Devil” ** •Innovations -wireline (1877) to wireless

2

• CellularNetworks

• 1Gto4G– architecture

• 1Gto4G- vulnerabilities

• 5Garchitecture

• 5Gvision2025

• Securitychallenges

Outline

Page 3: Mobile Privacy in 2025 - Black Hat...3 •First demonstration in 1877 –Stockholm, Sweden •“Telephone is the instrument of Devil” ** •Innovations -wireline (1877) to wireless

3

• Firstdemonstrationin1877– Stockholm,Sweden

• “TelephoneistheinstrumentofDevil”**

• Innovations- wireline(1877)towireless(2017)

• Foundation– seamlessconnectivityandlowlatency

• Features- qualityofservice&availability

MagicofCellularNetworks

** & Figure Source- Ericsson History

Page 4: Mobile Privacy in 2025 - Black Hat...3 •First demonstration in 1877 –Stockholm, Sweden •“Telephone is the instrument of Devil” ** •Innovations -wireline (1877) to wireless

4

• Noauthentication&encryption

• Heavydevices

• Noroaming– internationalcalls

1GNetworksto4G

figure- Ericsson History

• Authentication&encryption

• Smartdevices

• RoamingandhighspeedInternet

Page 5: Mobile Privacy in 2025 - Black Hat...3 •First demonstration in 1877 –Stockholm, Sweden •“Telephone is the instrument of Devil” ** •Innovations -wireline (1877) to wireless

DesignStakeholders

5

• Cellularnetworkproviders

• End-userequipmentvendors

• Standardorganizations

• Infrastructure&supportservices

• Over-The-Topservices

Page 6: Mobile Privacy in 2025 - Black Hat...3 •First demonstration in 1877 –Stockholm, Sweden •“Telephone is the instrument of Devil” ** •Innovations -wireline (1877) to wireless

SecureCellularCommunication

BaseStationMobile

CoreNetwork

2G/3G/4G

Authentication

Availability

Confidentiality

Integrity

Arewesecured?

6

Page 7: Mobile Privacy in 2025 - Black Hat...3 •First demonstration in 1877 –Stockholm, Sweden •“Telephone is the instrument of Devil” ** •Innovations -wireline (1877) to wireless

PrivacyAssets

7

• Deviceinformation

� IMEI,identitiesetc.

� Locationdata

� Sensitivedata(forexampleuserhealthinfo)

• Personalinformation

� IMEI,IMSI,phonenumberetc.

� SMSandcall/Internetdata

� Locationdata

Page 8: Mobile Privacy in 2025 - Black Hat...3 •First demonstration in 1877 –Stockholm, Sweden •“Telephone is the instrument of Devil” ** •Innovations -wireline (1877) to wireless

Attackers

• Fraudsters

• Cybercriminals

• Insiderthreats

• Cyberwarfareactors(arguable)

Page 9: Mobile Privacy in 2025 - Black Hat...3 •First demonstration in 1877 –Stockholm, Sweden •“Telephone is the instrument of Devil” ** •Innovations -wireline (1877) to wireless

ThreatsandAttackerModel

BaseStationMobile

CoreNetwork

9

Page 10: Mobile Privacy in 2025 - Black Hat...3 •First demonstration in 1877 –Stockholm, Sweden •“Telephone is the instrument of Devil” ** •Innovations -wireline (1877) to wireless

Vulnerabilities&Attacks

BaseStationMobilePracticalattacksoncorenetworkandend-users

• architectureissuesandrisksIMSICatchers

10

Attacksagainst3operatingsystems• Baseband,(U)SIM&Android

vulnerabilities

Page 11: Mobile Privacy in 2025 - Black Hat...3 •First demonstration in 1877 –Stockholm, Sweden •“Telephone is the instrument of Devil” ** •Innovations -wireline (1877) to wireless

Standards&Regulations

Page 12: Mobile Privacy in 2025 - Black Hat...3 •First demonstration in 1877 –Stockholm, Sweden •“Telephone is the instrument of Devil” ** •Innovations -wireline (1877) to wireless

CellularSecurityStandards• Standardizationbodies

� 3GPP(3rdGenerationPartnershipProject)� ETSI(EuropeanTelecommunicationsStandardsInstitute)� GSMA(GSMAssociation)� ITU(InternationalTelecommunicationUnion)

• Mandatorysecurityandprivacyrequirements

• Internationalandnationalregulations(useofencryption,dataretention)

Page 13: Mobile Privacy in 2025 - Black Hat...3 •First demonstration in 1877 –Stockholm, Sweden •“Telephone is the instrument of Devil” ** •Innovations -wireline (1877) to wireless

Standards&DeploymentIssues

• PadlocksymbolforHTTPS

• Haveyouseenduringmobilecalllately?

SecurityIndicatorsonMobile

Page 14: Mobile Privacy in 2025 - Black Hat...3 •First demonstration in 1877 –Stockholm, Sweden •“Telephone is the instrument of Devil” ** •Innovations -wireline (1877) to wireless

5GNetworks

14

• 5G- Nextgenerationcellularnetworks� Handlesmoredata� Connectsmoredevices� Lowlatency�Morereliability

• 1-10Gbps speed

• Drivenbynewuse-cases,forexample� Connecteddriverlesscars� Remotesurgery

Page 15: Mobile Privacy in 2025 - Black Hat...3 •First demonstration in 1877 –Stockholm, Sweden •“Telephone is the instrument of Devil” ** •Innovations -wireline (1877) to wireless

5GNetworksCharacteristics

15Figure Source- Vodafone

Page 16: Mobile Privacy in 2025 - Black Hat...3 •First demonstration in 1877 –Stockholm, Sweden •“Telephone is the instrument of Devil” ** •Innovations -wireline (1877) to wireless

Cloud-Native5GArchitecture

16

Movingtowardsnetworksoftwarization andprogrammability

� Radionetwork

� Networkclouds

� SDN(Software-DefinedNetworks)

� NFV(NetworkFunctionsVirtualization)

BaseStation

CloudRadioAccessNetwork

Page 17: Mobile Privacy in 2025 - Black Hat...3 •First demonstration in 1877 –Stockholm, Sweden •“Telephone is the instrument of Devil” ** •Innovations -wireline (1877) to wireless

Vision2025– 5G

17Figure Source- 5GPPP Project

Page 18: Mobile Privacy in 2025 - Black Hat...3 •First demonstration in 1877 –Stockholm, Sweden •“Telephone is the instrument of Devil” ** •Innovations -wireline (1877) to wireless

5GDevicesin2025?

18

• Non-removableUSIMcards- eSIM era

• Non-removablebattery

• ChangecellularoperatorwithoutgoingtoashopandUSIM

• Alwaysconnected(5Gspeed>WiFi speed)

• Smallcells– connectedtoclouds

Page 19: Mobile Privacy in 2025 - Black Hat...3 •First demonstration in 1877 –Stockholm, Sweden •“Telephone is the instrument of Devil” ** •Innovations -wireline (1877) to wireless

CurrentCellularNetworkIssues

• Privacyengineering

• OSandBasebandsoftwareupdate

• Targetedattacks

• Capabilitytodetectthreats

Page 20: Mobile Privacy in 2025 - Black Hat...3 •First demonstration in 1877 –Stockholm, Sweden •“Telephone is the instrument of Devil” ** •Innovations -wireline (1877) to wireless

5GPrivacyChallengesfor2025

20

• Radiointerfacesecurity� Essentialfordeliverydronesandself-drivingconnectedcars

• Mandatorysecuritymeasuresinthenetwork� Protectionofcellulardatainthirdpartyservices(cloud)� Quantumsafecryptographytechniques

• Regulatoryframework� Privacyawarenessandlaws� Effectivepoliciesandenforcements� Dataretention

• DoS attacks

• SecurityinSDNandNFV

Page 21: Mobile Privacy in 2025 - Black Hat...3 •First demonstration in 1877 –Stockholm, Sweden •“Telephone is the instrument of Devil” ** •Innovations -wireline (1877) to wireless

ThankYou.

Questions

21


Recommended