Toward Self-Sovereign Management of Subscriber Identities in 5G/6G Core Networks
Abstract
1. Introduction
2. Background
2.1. Standard 5G Authentication and Data Exposure
2.2. Insider Threats and Architectural Vulnerabilities
2.3. MNO Threat Modeling
3. Related Works
3.1. Current 5G Subscriber Identity Protection Proposals
3.2. Self-Sovereign Identity Proposals for 6G
4. The Need for Subscriber Identity Privacy in 5G/6G Core Networks
| Algorithm 1 Derivation of and Network Context Setup |
| Input: : Anchor key received from AUSF (via Nausf_UEAuthentication) |
| Input: : Subscription Permanent Identifier |
| Input: : Anti-Bidding Down Between Architectures parameter |
| Output: : Initialized AMF Security Context with NAS keys |
|
| Algorithm 2 5G-GUTI Allocation and Context Storage at AMF |
| Input: (UE context containing SUPI, PLMN, AMF ID) |
| Input: (Registration Type: Initial, Mobility, or Periodic) |
| Input: (Provided by UE in Registration Request) |
| Output: Updated UE Context and potentially a new 5G-GUTI sent to UE |
|
5. Analysis of 5G VNF API Parameter Prevalence and Risks
6. Conclusions
Author Contributions
Funding
Data Availability Statement
Acknowledgments
Conflicts of Interest
References
- Fang, H.; Wang, X.; Xiao, Z.; Hanzo, L. Autonomous collaborative authentication with privacy preservation in 6G: From homogeneity to heterogeneity. IEEE Netw. 2022, 36, 28–36. [Google Scholar] [CrossRef]
- Mao, B.; Liu, J.; Wu, Y.; Kato, N. Security and privacy on 6G network edge: A survey. IEEE Commun. Surv. Tutor. 2023, 25, 1095–1127. [Google Scholar] [CrossRef]
- US Cybersecurity and Infrastructure Security Agency. Joint Statement by FBI and CISA on PRC Activity Targeting Telecommunications. 2024. Available online: https://www.cisa.gov/news-events/news/joint-statement-fbi-and-cisa-prc-activity-targeting-telecommunications (accessed on 22 November 2025).
- Federal Bureau of Investigation; Cybersecurity and Infrastructure Security Agency. Joint Statement from FBI and CISA on the People‘s Republic of China Targeting of Commercial Telecommunications Infrastructure. 2024; Press Release (Joint Statement). Available online: https://www.cisa.gov/news-events/news/joint-statement-fbi-and-cisa-peoples-republic-china-prc-targeting-commercial-telecommunications (accessed on 1 December 2025).
- 3GPP. Security Architecture and Procedures for 5G System. Technical Specification (TS) 33.501, 3rd Generation Partnership Project (3GPP). 2018. Available online: https://portal.3gpp.org/desktopmodules/Specifications/SpecificationDetails.aspx?specificationId=3169 (accessed on 19 November 2025).
- Ferrag, M.A.; Maglaras, L.; Argyriou, A.; Kosmanos, D.; Janicke, H. Security for 4G and 5G cellular networks: A survey of existing authentication and privacy-preserving schemes. J. Netw. Comput. Appl. 2018, 101, 55–82. [Google Scholar] [CrossRef]
- Homoliak, I.; Toffalini, F.; Guarnizo, J.; Elovici, Y.; Ochoa, M. Insight into insiders and it: A survey of insider threat taxonomies, analysis, modeling, and countermeasures. ACM Comput. Surv. (CSUR) 2019, 52, 1–40. [Google Scholar] [CrossRef]
- Cao, J.; Ma, M.; Li, H.; Ma, R.; Sun, Y.; Yu, P.; Xiong, L. A survey on security aspects for 3GPP 5G networks. IEEE Commun. Surv. Tutor. 2019, 22, 170–195. [Google Scholar] [CrossRef]
- Cybersecurity and Infrastructure Security Agency. Potential Threat Vectors to 5G Infrastructure. 2021. Available online: https://www.cisa.gov/sites/default/files/publications/potential-threat-vectors-5G-infrastructure_508_v2_0%20%281%29.pdf (accessed on 22 November 2025).
- Yu, H.; Du, C.; Xiao, Y.; Keromytis, A.; Wang, C.; Gazda, R.; Hou, Y.T.; Lou, W. Aaka: An anti-tracking cellular authentication scheme leveraging anonymous credentials. In Proceedings of the Network and Distributed System Security (NDSS) Symposium 2024, San Diego, CA, USA, 26 February–1 March 2024; Internet Society: Reston, VA, USA, 2024. [Google Scholar]
- Federal Communications Commission. FCC Fines AT&T, Sprint, T-Mobile, and Verizon Nearly $200 Million for Illegally Sharing Access to Customers’ Location Data. Available online: https://www.fcc.gov/document/fcc-fines-largest-wireless-carriers-sharing-location-data (accessed on 8 December 2025).
- Hoffman-Andrews, J. Verizon Injecting Perma-Cookies to Track Mobile Customers, Bypassing Privacy Controls—eff.org. Available online: https://www.eff.org/deeplinks/2014/11/verizon-x-uidh (accessed on 8 December 2025).
- Wiquist, W. FCC Settles Verizon “Supercookie” Probe. Available online: https://www.fcc.gov/document/fcc-settles-verizon-supercookie-probe (accessed on 8 December 2025).
- Parkin, J. Identity and Security in 5G Authentication. Master’s Thesis, University of Waterloo, Waterloo, ON, Canada, 2024. [Google Scholar]
- Chlosta, M.; Rupprecht, D.; Pöpper, C.; Holz, T. 5G SUCI-Catchers: Still catching them all? In Proceedings of the 14th ACM Conference on Security and Privacy in Wireless and Mobile Networks, Abu Dhabi, United Arab Emirates, 28 June–2 July 2021; pp. 359–364. [Google Scholar]
- 3rd Generation Partnership Project (3GPP). Study on Authentication Enhancements in the 5G System (5GS). Technical Report TR 33.846, 3GPP. 2021. Available online: https://portal.3gpp.org/desktopmodules/Specifications/SpecificationDetails.aspx?specificationId=3573 (accessed on 15 November 2025).
- Arapinis, M.; Mancini, L.; Ritter, E.; Ryan, M.; Golde, N.; Redon, K.; Borgaonkar, R. New privacy issues in mobile telephony: Fix and verification. In Proceedings of the 2012 ACM conference on Computer and Communications Security, Raleigh North, CA, USA, 16–18 October 2012; pp. 205–216. [Google Scholar]
- 3rd Generation Partnership Project (3GPP). Study on 5G Security Enhancement Against False Base Stations (FBS). Technical Report TR 33.809, 3GPP. 2022. Available online: https://portal.3gpp.org/desktopmodules/Specifications/SpecificationDetails.aspx?specificationId=3539 (accessed on 30 November 2025).
- Zhao, Y.; Liu, X.; Xie, M.; Yang, X.; Ning, J.; Qin, B.; Zhang, H.; Yu, Y. Anonymous Authentication and Key Agreement, Revisited. Cryptology ePrint Archive. 2025. Available online: https://eprint.iacr.org/2025/1986 (accessed on 8 December 2025).
- Eleftherakis, S.; Otim, T.; Santaromita, G.; Zayas, A.D.; Giustiniano, D.; Kourtellis, N. Demystifying Privacy in 5G Stand Alone Networks. In Proceedings of the 30th Annual International Conference on Mobile Computing and Networking, New York, NY, USA, 18– 22 November 2024; ACM MobiCom’24. pp. 1330–1345. [Google Scholar] [CrossRef]
- Garzon, S.R.; Yildiz, H.; Küpper, A. Decentralized identifiers and self-sovereign identity in 6g. IEEE Netw. 2022, 36, 142–148. [Google Scholar] [CrossRef]
- Garzon, S.R.; Yildiz, H.; Küpper, A. Towards decentralized identity management in multi-stakeholder 6G networks. In Proceedings of the 2022 1st International Conference on 6G Networking (6GNet), Paris, France, 6–8 July 2022; IEEE: Piscataway, NJ, USA, 2022; pp. 1–8. [Google Scholar]
- Zhang, G.; Hu, Q.; Zhang, Y.; Jiang, T. A blockchain-based user-centric identity management toward 6G networks. Digit. Commun. Netw. 2025, 12, 1–10. [Google Scholar] [CrossRef]
- Li, H.Y.; Xiao, S.H.; Cao, B.; Peng, M.; Li, L.; Liu, X. Primer for Trustworthy 6G: Unified Self-Sovereign Identifier System. ZTE Technol. J. 2025, 31, 22–30. [Google Scholar] [CrossRef]
- Strobel, D. IMSI catcher. Chair for Communication Security, Ruhr-Universität Bochum. 2007, Volume 14. Available online: https://www.intercettazioni.info/PDF/Imsi_Catcher.pdf (accessed on 19 November 2025).
- Scalise, P.; Hempel, M.; Sharif, H. A Survey of 5G Core Network User Identity Protections, Concerns, and Proposed Enhancements for Future 6G Technologies. Future Internet 2025, 17, 142. [Google Scholar] [CrossRef]
- 3GPP. System Architecture for the 5G System (5GS). Technical Specification (TS) 23.501, 3rd Generation Partnership Project (3GPP). 2017. Available online: https://portal.3gpp.org/desktopmodules/Specifications/SpecificationDetails.aspx?specificationId=3144 (accessed on 20 November 2025).
- Sharma, S. Reallocation of Temporary Identities: Applying 5G Cybersecurity and Privacy Capabilities (Draft). 2024. Available online: https://csrc.nist.gov/pubs/cswp/36/c/reallocation-of-temporary-identities-applying-5g-c/ipd (accessed on 11 December 2025).
- de Gregorio, J. GitHub—Jdegre/5GC_APIs: RESTful APIs of Main Network Functions in the 3GPP 5G Core Network. 2024. Available online: https://github.com/jdegre/5GC_APIs (accessed on 6 December 2025).
- 3GPP. 5G System; Technical Realization of Service Based Architecture; Stage 3. Technical Specification (TS) 29.500, 3rd Generation Partnership Project (3GPP). 2018. Available online: https://portal.3gpp.org/desktopmodules/Specifications/SpecificationDetails.aspx?specificationId=3338 (accessed on 14 November 2025).
- 3GPP. 5G System; Unified Data Management Services; Stage 3. Technical Specification (TS) 29.503, 3rd Generation Partnership Project (3GPP). 2018. Available online: https://portal.3gpp.org/desktopmodules/Specifications/SpecificationDetails.aspx?specificationId=3342 (accessed on 30 November 2025).
- 3GPP. 5G System; Session Management Services; Stage 3. Technical Specification (TS) 29.502, 3rd Generation Partnership Project (3GPP). 2018. Available online: https://portal.3gpp.org/desktopmodules/Specifications/SpecificationDetails.aspx?specificationId=3340 (accessed on 30 November 2025).
- 3GPP. 5G System; Session Management Policy Control Service; Stage 3. Technical Specification (TS) 29.512, 3rd Generation Partnership Project (3GPP). 2018. Available online: https://portal.3gpp.org/desktopmodules/Specifications/SpecificationDetails.aspx?specificationId=3352 (accessed on 5 December 2025).
- 3GPP. Telecommunication Management; Charging Management; 5G System, Charging Service; Stage 3. Technical Specification (TS) 32.291, 3rd Generation Partnership Project (3GPP). 2018. Available online: https://portal.3gpp.org/desktopmodules/Specifications/SpecificationDetails.aspx?specificationId=3398 (accessed on 5 December 2025).
- 3GPP. Numbering, Addressing and Identification. Technical Specification (TS) 23.003, 3rd Generation Partnership Project (3GPP). 2019. Available online: https://portal.3gpp.org/desktopmodules/Specifications/SpecificationDetails.aspx?specificationId=729 (accessed on 20 January 2026).
- Barabási, A.L.; Bonabeau, E. Scale-free networks. Sci. Am. 2003, 288, 60–69. [Google Scholar] [CrossRef] [PubMed]
- Newman, M.E. Power laws, Pareto distributions and Zipf’s law. Contemp. Phys. 2005, 46, 323–351. [Google Scholar] [CrossRef]
- Pósfai, M.; Barabási, A.L. Network Science; Cambridge University Press: Cambridge, UK, 2016; Volume 3. [Google Scholar]
- Clauset, A.; Shalizi, C.R.; Newman, M.E. Power-law distributions in empirical data. SIAM Rev. 2009, 51, 661–703. [Google Scholar] [CrossRef]







| Threat Model | Adversary Behavior & Privacy Implications |
|---|---|
| The Trusted Model | Assumes the Home Network (HN) is a benevolent custodian. Security focuses solely on attacks outside of the cellular infrastructure ecosystem. This model is considered obsolete due to the complexity of modern supply chains and the software-based nature of current 5G networks, which opens the door to third-party vendor or insider attacks [9]. |
| Honest-but-Curious (HbC) | The MNO faithfully executes network protocols (no service disruption or packet dropping) but analyzes all accessible traffic to profile users. Privacy schemes like AAKA [10] generally target this adversary, who leverages user trust to passively mine behavioral data for advertising purposes [11]. |
| Malicious-but-Cautious | An active adversary that may deviate from protocol (e.g., selling real-time location data, injecting headers) but only when the risk of detection is low. This model reflects an MNO balancing aggressive monetization against the risk of regulatory penalties or reputational damage [12,13]. |
| Coerced Model | An MNO compelled by legal jurisdiction or Lawful Interception (LI) mandates to break user privacy, or an MNO that has been attacked and these interfaces seized by adversaries. This renders user identity privacy assumptions void, regardless of the MNO’s internal integrity [3]. |
| Paper | Ref. | Research Findings | Proposed Approach |
|---|---|---|---|
| Parkin (2024) | [14] | Existing SUCI-catching defenses are inadequate. Each addresses only one attack variant or requires disruptive changes | RAN-focused. hSUPI (hashed SUPI) for forward-unlinkable SUCI. “Bring Your Own Identity” scheme with external identity provider. |
| Yu et al. (2024) | [10] | Cellular networks lack mechanisms to prevent subscriber behavior linkage across sessions | AAKA protocol enabling anonymous authentication without revealing true identity. Assumes HbC operator. Focused on authentication flow. |
| Zhao et al. (2025) | [19] | Revisits cellular subscriber tracking and data linkage attacks | Extends AAKA analysis. Does not fully decouple privacy protections from MNO domain. |
| Eleftherakis et al. (2024) | [20] | Two new vulnerabilities: GUTI Reallocation Command attack and Security Capabilities Bidding-Down attack in SA/NSA 5G | N/A (experimental analysis of air-interface vulnerabilities. Insider threats not considered.) |
| Garzón Bolívar et al. (2022) | [21,22] | PLMN-centric identity management limits cross-domain interoperability. HN retains identity mapping as credential issuer | Decentralized Identifiers (DID) and Self-Sovereign Identity (SSI) for 6G. Reduces tracking in roaming and edge scenarios. |
| Zhang et al. (2025) | [23] | MNOs can track user behaviors and metadata through centralized identity management | Blockchain with zero-knowledge proofs to separate digital identity from MNOs. Assumes HbC infrastructure. Insider threats not considered. |
| Li et al. (2025) | [24] | Subscriber identity should not be owned by any single organization | Unified Self-Sovereign Identifier (U-SSI) shared across operators. Onboarding and PII mapping not addressed |
| This work | SUPI-related identifiers are central to SBI Core NF APIs (5.11% of occurrences). Insider/state-level threats exploit persistent identifiers within the CN | Scoped across all 5G CN activities and identity exposure problem. Characterizes SBI identifier propagation. Advocates Zero-Trust CN architecture and subscriber-controlled identity management |
| Derived Key | Input KEY to KDF | FC | Signature | ||||
|---|---|---|---|---|---|---|---|
| 0x6A | SNN (serving network name) | len(SNN) | SQN ⊕ AK | len(SQN ⊕ AK) | |||
| 0x6C | SNN | len(SNN) | – | – | |||
| 0x6D | SUPI | len(SUPI) | ABBA | len(ABBA) | |||
| 0x69 | type=0x01 (NAS-enc) | len(0x01) | NAS alg id (1 octet) | 0x0001 | |||
| 0x69 | type=0x02 (NAS-int) | 0x0001 | NAS alg id (1 octet) | 0x0001 | |||
| (initial) | 0x6E | UL NAS COUNT (4 octets) | 0x0004 | Access type: 0x01 (3GPP) / 0x02 (non-3GPP) | 0x0001 | ||
| NH (Next Hop) | 0x6F | SYNC-input (new or previous NH) | 0x0020 | – | – | ||
| or NH | 0x70 | Target PCI | 0x0002 | Target ARFCN-DL | len(ARFCN-DL) | ||
| or | 0x69 | type=0x03 (RRC-enc) | 0x0001 | AS alg id (1 octet) | 0x0001 | ||
| or | 0x69 | type=0x04 (RRC-int) | 0x0001 | AS alg id (1 octet) | 0x0001 | ||
| or | 0x69 | type=0x05 (UP-enc) | 0x0001 | AS alg id (1 octet) | 0x0001 | ||
| or | 0x69 | type=0x06 (UP-int) | 0x0001 | AS alg id (1 octet) | 0x0001 |
| Interaction & Standard | Resource URI | Identity Inclusion (Schema) |
|---|---|---|
| Authentication (AUSF → UDM) TS 29.503 [31] | …/nudm-ueau/v1/{supi}/security-information/generate-auth-data | URI Path Parameter |
| Registration (AMF → UDM) TS 29.503 [31] | …/nudm-uecm/v1/{supi}/registrations/amf-3gpp-access | URI Path Parameter |
| Session Creation (AMF → SMF) TS 29.502 [32] | …/nsmf-pdusession/v1/sm-contexts | JSON Body: { “supi”: “imsi-001…”, … } |
| Policy Control (SMF → PCF) TS 29.512 [33] | …/npcf-smpolicycontrol/v1/sm-policies | JSON Body: { “supi”: “imsi-001…”, … } |
| Charging & Billing (SMF → CHF) TS 32.291 [34] | …/nchf-convergedcharging/v3/chargingdata | JSON Body: { “subscriberIdentifier”: “imsi-001…”, … } |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Scalise, P.; Hempel, M.; Sharif, H. Toward Self-Sovereign Management of Subscriber Identities in 5G/6G Core Networks. Telecom 2026, 7, 23. https://doi.org/10.3390/telecom7010023
Scalise P, Hempel M, Sharif H. Toward Self-Sovereign Management of Subscriber Identities in 5G/6G Core Networks. Telecom. 2026; 7(1):23. https://doi.org/10.3390/telecom7010023
Chicago/Turabian StyleScalise, Paul, Michael Hempel, and Hamid Sharif. 2026. "Toward Self-Sovereign Management of Subscriber Identities in 5G/6G Core Networks" Telecom 7, no. 1: 23. https://doi.org/10.3390/telecom7010023
APA StyleScalise, P., Hempel, M., & Sharif, H. (2026). Toward Self-Sovereign Management of Subscriber Identities in 5G/6G Core Networks. Telecom, 7(1), 23. https://doi.org/10.3390/telecom7010023

