3 ms·
First of all, congratulations, when you get Bruce Schneier to endorse your work, you have probably done something interesting. But still the article is not ver
by NotSwift 5y ago
First of all, congratulations, when you get Bruce Schneier to endorse your work, you have probably done something interesting.
But still the article is not very clear on technical details. Of course on initial contacts your phone has to provide information about your service provider (they will somehow have to pay for your communications) and it has also has to have some form of identification about your phone (so that the service provider can decide if they want to pay for it). If I understand it correctly, normally this identification is the IMSI, which is normally constant for your phone. From the article it is not clear if you are proposing to generate multiple IMSI's for a phone or using other types of information in the protocols.
Do you have some links to a more technical explanation of PGPP?
- neolog 5y agohttps://www.usenix.org/system/files/sec21-schmitt.pdf https://www.usenix.org/system/files/sec21-schmitt.pdf
- barathr 5y agoThanks! So the paper that the other commenter linked is a good deep dive. The basic answer to your question is that we have multiple variants but the simplest is that phones using PGPP would have the same IMSI; once you do that, you hide who's who but create a new problem of how to make sure users are valid paying subscribers. We solve that new problem by developing a new oblivious authentication protocol that can verify someone is a valid user (i.e. someone who has authentication tokens that are not linked to them but are issued by the network).