Reference · Subscriber privacy
Subscriber privacy: how a mobile identity becomes exposed
A mobile network cannot route to a subscriber it cannot name. Everything difficult about subscriber privacy follows from that one requirement, and from the long period in which the naming was done in the open.
Published
Where the permanent identifier is readable
Figure 1. The difference is where the encryption happens, not how strong it is. An identifier that leaves the handset in the clear is readable by anything that can hold a radio session open, which is why the false base station in the upper sequence needs no key and no cooperation from the operator.
1Premise
Why a network has to name you before it can reach you
A handset that has just been switched on is, to the network, anonymous and unreachable. Before it can receive a call it has to be located, authenticated and given a temporary address, and each of those steps needs something durable to hang on: an identifier that means the same subscription tomorrow as it did today. That identifier is the international mobile subscriber identity, and its permanence is not an oversight. It is the property that makes billing, roaming and lawful access possible at all.
The difficulty is that the same permanence makes the identifier worth collecting. A number that never changes, is unique to one subscription and is transmitted by the handset that holds it is close to an ideal tracking token, and for three network generations it could be drawn out of a handset by anything convincing enough to look like a cell. The temporary identifiers that were supposed to prevent this worked most of the time and failed at exactly the moments an attacker could arrange: at first attach, and whenever the network claimed not to recognise the temporary one.
So subscriber privacy on a mobile network is not a question of hiding traffic. It is a question of whether the act of becoming reachable has to disclose a permanent name, and if it does, to whom.
2Pages
The subject, page by page
Nine pages, from what the identifier is through to what the fifth generation changed about it. The detection pages are the practical end; the concealment and paging pages are the mechanism the detection pages depend on.
- IMSI catcher detection: what works and what only looks like it does
What a handset can observe, which anomalies are worth acting on, and why detection is inference rather than measurement.
- What is an IMSI, and why the number outlasts the handset
The structure of the identity, where it lives, and the property that makes it worth intercepting: it belongs to the subscription, not the phone.
- IMSI vs IMEI: which number identifies the subscriber
One number follows the subscription, the other follows the hardware. Which is which decides what a swap actually achieves.
- How a fake base station works, and why it still works
The behaviour being abused is the handset doing exactly what it was designed to do. That is why the problem took a generation to close.
- SUCI and SUPI: what identity concealment in 5G actually does
The permanent identifier stops crossing the air interface in the clear. What that fixes, and the gaps it leaves by design.
- Paging: the quiet way a network reveals where you are
Interception is not the only exposure. A network that has to find a handset before it can ring it says something every time it looks.
- IMSI catcher detector apps: what a phone will not let them see
The apps are not badly built. They are asked to detect a radio attack from behind an interface that hides the radio.
- Lawful interception and IMSI catchers are not the same thing
One runs inside the network under a warrant and leaves a record. The other stands outside it and leaves none. They get discussed as one thing.
- What the project specified about subscriber identity privacy
Three published specifications, and the question of how much of the 2016 design survived into what was eventually standardised.
DRecords
What the project itself specified
Three of the archive’s specifications address subscriber identity directly. They were written while the first 5G security architecture was still in draft, which makes them a record of what the problem looked like before it was settled rather than a description of what was eventually standardised.
| Cluster | Specification | Concern | Pages |
|---|---|---|---|
| T3.2 | Privacy-enhanced identity protection | Concealment of subscriber identifiers | 13 |
| T3.2 | Device-based anonymization | Anonymization performed at the device | 10 |
| T3.2 | Privacy policy analysis | Machine analysis of a stated privacy policy | 25 |
The relationship between those four documents and the standard that followed is discussed on the specifications page. The short version is that the archive establishes what was proposed and by whom, and does not establish which proposals were adopted; the two questions get run together often enough that it is worth separating them explicitly.
QQuestions
Questions and answers
Is subscriber privacy the same thing as call encryption?
No, and conflating them is the reason the problem was tolerated for so long. Encryption protects what is said. Subscriber privacy concerns who is saying it and from where, which is carried in the signalling that sets a call up, before there is a call. A network can encrypt every byte of content and still announce, in the clear, that a particular subscription just arrived in a particular place.
Does 5G solve it?
It closes the specific hole that made the permanent identity readable over the air, which was the largest one and had been open since the second generation. It does not close every path by which a handset can be recognised or located, and one of the concealment options standardised alongside the others provides no concealment at all, so the outcome depends on what an operator chooses to deploy, not on what the specification permits.
Why does a research archive from 2017 carry pages written in 2026?
Because the identity problem outlived the project that studied it. The specifications collected here were written while the first 5G security architecture was still being drafted, and they describe a threat that is still present on the older network generations running alongside 5G today. The archive holds what was specified; these pages describe where that subject stands now, and say plainly which is which.