English

TESLA-for-5G: Broadcast Authentication for 5G Networks Using TESLA

Cryptography and Security 2026-06-25 v1

Abstract

5G base stations broadcast unauthenticated system information (SI) that every user equipment (UE) reads during cell selection. This enables attackers to broadcast forged SI from a fake base station (FBS), deceiving UEs into camping on it. Prior approaches require UEs to authenticate System Information Block 1 (SIB1) using digital signatures. This necessitates computation-heavy verification for every SIB1 reception, imposing a significant burden on resource-constrained UEs. We propose TESLA-for-5G (TF5), a broadcast authentication protocol for 5G SIB1 that combines TESLA with GG09 Schnorr-like identity-based signatures (IBS). In the steady state, TF5 enables UEs to authenticate each SIB1 message using a symmetric MAC and delayed key disclosure, eliminating the need for per-message digital signatures. Initial trust is bootstrapped during cell entry using a lightweight GG09 IBS over the TESLA parameters, avoiding certificate distribution overhead. We formally verify TF5 in Tamarin under a Dolev-Yao adversary and demonstrate its favorable computation, communication, and storage costs through both an implementation on the OpenAirInterface 5G stack and trace-driven analysis.

Cite

@article{arxiv.2606.26528,
  title  = {TESLA-for-5G: Broadcast Authentication for 5G Networks Using TESLA},
  author = {Subin Song and Michael K. Reiter and Taekyoung Kwon},
  journal= {arXiv preprint arXiv:2606.26528},
  year   = {2026}
}

Comments

20 pages, 8 tables, 2 algorithms, no figures

R2 v1 2026-07-22T20:09:56.191Z