1. Formal verification of authentication and service authorization protocols in 5G-enabled device-to-device communications using ProVerif
- Author
-
Jonathan Loo, Mahdi Aiash, and Ed Kamya Kiyemba Edris
- Subjects
Security analysis ,formal methods ,TK7800-8360 ,Computer Networks and Communications ,Computer science ,Access control ,D2D ,02 engineering and technology ,Cyber-security ,Encryption ,ProVerif ,0202 electrical engineering, electronic engineering, information engineering ,Electrical and Electronic Engineering ,Integrated Encryption Scheme ,Authentication ,business.industry ,security protocol ,020206 networking & telecommunications ,Service provider ,Cryptographic protocol ,Hardware and Architecture ,Control and Systems Engineering ,Signal Processing ,Cellular network ,authentication ,authorization ,020201 artificial intelligence & image processing ,Electronics ,business ,5G ,Computer network - Abstract
Device-to-Device (D2D) communications will be used as an underlay technology in the Fifth Generation mobile network (5G), which will make network services of multiple Service Providers (SP) available anywhere. The end users will be allowed to access and share services using their User Equipments (UEs), and thus they will require seamless and secured connectivity. At the same time, Mobile Network Operators (MNOs) will use the UE to offload traffic and push contents closer to users relying on D2D communications network. This raises security concerns at different levels of the system architecture and highlights the need for robust authentication and authorization mechanisms to provide secure services access and sharing between D2D users. Therefore, this paper proposes a D2D level security solution that comprises two security protocols, namely, the D2D Service security (DDSec) and the D2D Attributes and Capability security (DDACap) protocols, to provide security for access, caching and sharing data in network-assisted and non-network-assisted D2D communications scenarios. The proposed solution applies Identity-based Encryption (IBE), Elliptic Curve Integrated Encryption Scheme (ECIES) and access control mechanisms for authentication and authorization procedures. We formally verified the proposed protocols using ProVerif and applied pi calculus. We also conducted a security analysis of the proposed protocols.
- Published
- 2021