The sixth generation (6G) of mobile networks are being developed to overcome limitations in previous generations and meet emerging user demands. As a European project, the Smart Networks and Services Joint Undertaking (SNS JU) 6G Flagship project Hexa-X-II has a leading role for developing technologies and anchoring 6G end-to-end system. This paper summarizes the security, privacy and resilient (SPR) controls identified by Hexa-X-II project and their validation frameworks.
This paper presents a novel framework for enhancing the security, data rate, and sensing performance of integrated sensing and communications (ISAC) systems. We employ a random frequency and pulse repetition interval (PRI) agility (RFPA) method for the waveform design, where the necessary random sequences are governed by shared secrets. These secrets, which can be pre-shared or generated via channel reciprocity, obfuscate critical radar parameters like Doppler frequency and pulse start times, thereby significantly impeding the ability to perform reconnaissance from a passive adversary without the secret key. To further introduce enhanced data throughput, we also introduce a hybrid information embedding scheme that integrates amplitude shift keying (ASK), phase shift keying (PSK), index modulation (IM), and spatial modulation (SM), for which a low-complexity sparse-matched filter receiver is proposed for accurate decoding with practical complexity. Finally, the excellent range-velocity resolution and clutter suppression of the proposed waveform are analyzed via the ambiguity function (AF).
We introduce a comprehensive approach to enhance the security, privacy, and sensing capabilities of integrated sensing and communications (ISAC) systems by leveraging random frequency agility (RFA) and random pulse repetition interval (PRI) agility (RPA) techniques. The combination of these techniques, which we refer to collectively as random frequency and PRI agility (RFPA), with channel reciprocity-based key generation (CRKG) obfuscates both Doppler frequency and PRIs, significantly hindering the chances that passive adversaries can successfully estimate radar parameters. In addition, a hybrid information embedding method integrating amplitude shift keying (ASK), phase shift keying (PSK), index modulation (IM), and spatial modulation (SM) is incorporated to increase the achievable bit rate of the system significantly. Next, a sparse-matched filter receiver design is proposed to efficiently decode the embedded information with a low bit error rate (BER). Finally, a novel RFPA-based secret generation scheme using CRKG ensures secure code creation without a coordinating authority. The improved range and velocity estimation and reduced clutter effects achieved with the method are demonstrated via the evaluation of the ambiguity function (AF) of the proposed waveforms.
Everyday services of society increasingly rely on mobile applications, resulting in a conflicting situation between the possibility of participation on the one side and user privacy and digital freedom on the other. In order to protect users' rights to informational self-determination, regulatory approaches for the collection and processing of personal data have been developed, such as the EU's GDPR. However, inspecting the compliance of mobile apps with privacy regulations remains difficult. Thus, in order to enable end users and enforcement bodies to verify and enforce data protection compliance, we propose mopri, a conceptual framework designed for analyzing the behavior of mobile apps through a comprehensive, adaptable, and user-centered approach. Recognizing the gaps in existing frameworks, mopri serves as a foundation for integrating various analysis tools into a streamlined, modular pipeline that employs static and dynamic analysis methods. Building on this concept, a prototype has been developed which effectively extracts permissions and tracking libraries while employing robust methods for dynamic traffic recording and decryption. Additionally, it incorporates result enrichment and reporting features that enhance the clarity and usability of the analysis outcomes. The prototype showcases the feasibility of a holistic and modular approach to privacy analysis, emphasizing the importance of continuous adaptation to the evolving challenges presented by the mobile app ecosystem.
Device identifiers like the International Mobile Equipment Identity (IMEI) are crucial for ensuring device integrity and meeting regulations in 4G and 5G networks. However, sharing these identifiers with Mobile Network Operators (MNOs) brings significant privacy risks by enabling long-term tracking and linking of user activities across sessions. In this work, we propose a privacy-preserving identifier checking method in 5G. This paper introduces a protocol for verifying device identifiers without exposing them to the network while maintaining the same functions as the 3GPP-defined Equipment Identity Register (EIR) process. The proposed solution modifies the PEPSI protocol for a Private Set Membership (PSM) setting using the BFV homomorphic encryption scheme. This lets User Equipment (UE) prove that its identifier is not on an operator's blacklist or greylist while ensuring that the MNO only learns the outcome of the verification. The protocol allows controlled deanonymization through an authorized Law Enforcement (LE) hook, striking a balance between privacy and accountability. Implementation results show that the system can perform online verification within five seconds and requires about 15 to 16 MB of communication per session. This confirms its practical use under post-quantum security standards. The findings highlight the promise of homomorphic encryption for managing identifiers while preserving privacy in 5G, laying the groundwork for scalable and compliant verification systems in future 6G networks.
Joint Communication and Sensing (JCAS) enables User Equipment (UE) to offload computational tasks to nearby peer devices or edge servers over context-aware wireless links. While this improves latency and resource utilization, the dual usage of the wireless spectrum for communication and environmental sensing introduces novel privacy risks, particularly for tasks involving location-sensitive or contextual data. This paper introduces a novel offloading framework that leverages real-time environmental information sensed by JCAS base stations to dynamically estimate the privacy risk associated with each offloading link. Based on these context-aware risk estimates, UE selects among local, Device-to-Device (D2D), or edge execution modes to minimize a composite cost function balancing privacy leakage and delay. A lightweight greedy scheduler is applied to solve the offloading decision problem efficiently under deadline constraints. Simulation results demonstrate that our method significantly reduces effective privacy leakage with negligible latency overhead, consistently outperforming context-agnostic baseline strategies.
Trustworthiness and trust are fundamental factors in societies that enable us to interact and enjoy mingling in crowds without fear. As robotic devices start permeating our daily lives, they must behave as completely trustworthy objects so that people will accept them just as they would trust other people when interacting with them in their daily lives. As trust and trustworthiness have been researched in social sciences for many years, this opens the question: How can we learn from system models and findings from social sciences to translate such learnings into requirements for future technical solutions? This is of particular importance now, as 5G and 6G cellular communications open the door for the Tactile Internet --- connected robotics interacting with humans. We present a novel holistic approach on how to tackle trustworthiness systematically in the context of communications. We propose a first attempt to incorporate objective system properties and subjective beliefs to establish trustworthiness-based trust.
Channel Reciprocity-based Key Generation (CRKG) technique has gained significant attention among researchers in the field of Physical Layer Security (PLS). While existing methods in this area typically use raw channel information as input for secret key generation, we propose a novel approach that derives features from the raw material for key generation. Our comprehensive study explores a wide range of features derived from the reciprocal components of the Channel Impulse Response (CIR)s in both the time and frequency domains. Our findings demonstrate that the derived feature set exhibits better channel characteristics than the raw key material, even in the presence of eavesdroppers. We evaluate the efficiency of our proposed feature set using several performance metrics in a new feature-based key generation scheme to validate its efficiency. The results highlight the potential of this feature set for future key-generation applications.
The complexity of modern communication systems continues to escalate with the advent of 6G technologies and their diverse applications. A significant challenge in such systems is effectively analyzing and addressing privacy concerns without compromising functionality or overusing the resources. This paper introduces a novel and efficient risk-aware methodology for privacy modeling and enhancement, specifically designed to address the unique requirements of 6G in the context of railway crossing monitoring. Despite considering the application-specific infrastructure, the proposed methodology can apply to other non-6G-based use cases.
Integrated sensing and communication (ISAC) enables radio systems to simultaneously sense and communicate with their environment. This paper, developed within the Hexa-X-II project funded by the European Union, presents a comprehensive cross-layer vision for ISAC in 6G networks, integrating insights from physical-layer design, hardware architectures, AI-driven intelligence, and protocol-level innovations. We begin by revisiting the foundational principles of ISAC, highlighting synergies and trade-offs between sensing and communication across different integration levels. Enabling technologies (such as multiband operation, massive and distributed MIMO, non-terrestrial networks, reconfigurable intelligent surfaces, and machine learning) are analyzed in conjunction with hardware considerations including waveform design, synchronization, and full-duplex operation. To bridge implementation and system-level evaluation, we introduce a quantitative cross-layer framework linking design parameters to key performance and value indicators. By synthesizing perspectives from both academia and industry, this paper outlines how deeply integrated ISAC can transform 6G into a programmable and context-aware platform supporting applications from reliable wireless access to autonomous mobility and digital twinning.
The sixth generation (6G) of mobile networks is being developed to overcome limitations in previous generations and meet emerging user demands. As spearhead of the European research and development effort on 6G, the Smart Networks and Services Joint Undertaking (SNS JU) 6G Flagship project Hexa-X-II has a leading role for developing the technologies and anchoring 6G end-toend (E2E) system. This paper summarizes the security, privacy, and resilience (SPR) controls identified by the Hexa-X-II project and their validation activities. Moreover, we share the SPR view on the 6G E2E system with the SPR features which are necessary to ensure the trustworthiness of 6 G.
This work introduces Information Inference Diagrams (I2Ds), a modeling framework aiming to complement existing approaches for privacy and security analysis of distributed systems. It is intended to support established threat modeling processes. Our approach is designed to be compatible with Data Flow Diagrams (DFDs), which form the basis of many established techniques and tools. Unlike DFDs, I2Ds represent information propagation, going beyond mere data flows to enable more formal reasoning in threat modeling while remaining practical. They define inference and sharing (flow) relations on information items to model how information moves through a system. To this end, we provide formal definitions for information items, entities, and flows. By introducing classes as a type system, our formal rules are both generic and allow conformance to existing vocabularies. We demonstrate the applicability of I2Ds through examples, that showcase their versatility in system analysis.
Remote attestation (RA) is the foundation for trusted execution environments in the cloud and trusted device driver onboarding in operating systems. However, RA misses a rigorous mechanized definition of its security properties in one of the strongest models, i.e., the semantic model. Such a mechanization requires the concept of StateSeparating Proofs (SSP). However, SSP was only recently implemented as a foundational framework in the Rocq Prover. Based on this framework, this paper presents the first mechanized formalization of the fundamental security properties of RA. Our Rocq Prover development first defines digital signatures and formally verifies security against forgery in the strong existential attack model. Based on these results, we define RA and reduce the security of RA to the security of digital signatures. Our development provides evidence that the RA protocol is secure against forgery. Additionally, we extend our reasoning to the primitives of RA and reduce their security to the security of the primitives of the digital signatures.
This paper introduces a reconfigurable radio frequency (RF) front-end based management of accuracy and other sensing key performance indicators (KPIs) as means for privacy control in the context of integrated sensing and communications (ISAC). Being part of the sensing devices (especially user equipments), the reconfigurable front-end would enable the users to control dynamically the sensing KPIs of their devices. This would allow the enablement of sensing-based applications while maintaining privacy and ensuring that the sensing application only receives the minimal amount of necessary sensing data. In this work, the use of RF front-end reconfigurability is highlighted for different types of systems and an architecture to integrate the controls in privacy-preserving User Equipments (UEs) is proposed. The active KPI management with RF front-end controls can be a key factor for the deployment of joint/integrated communication and sensing systems without causing a privacy nightmare in future sixth generation (6G) networks.
Integrated Sensing and Communication (ISAC) technology extends network functionality beyond communication by incorporating radar-like sensing, making it a crucial emerging technology for 6G. In addition to base station, User Equipment (UE) can also perform sensing in their surroundings and sensing data processing, contributing to the ISAC operations. However, UE introduces security and privacy risks due to their involvement in sensing activities, while being potential targets of various attacks at the same time. This paper first examines the UE architecture for ISAC, focusing on the key components involved in sensing, processing, and other related activities. Based on the roles of the components, deployment-specific interactions in resource allocation, and processing within sensing sessions, we identify potential security and privacy threats. To mitigate these risks, we recommend mechanisms that uphold key security and privacy properties, such as confidentiality, integrity, availability, reliability, data shielding, and protection of Personally Identifiable Information (PII) within the ISAC-enabled UE architecture.
This paper introduces a novel methodology to enhance privacy in Cooperative Intelligent Transport Systems (C-ITS) by improving unlinkability in vehicle-to-everything (V2X) communication. Focusing on the Cooperative Awareness Basic Service, we employ a Hidden Markov Model (HMM) to model the unlinkability of Cooperative Awareness Messages (CAMs) exchanged between vehicles and roadside units (RSUs) under the surveillance of a Global Passive Adversary (GPA). Implementing a joint obfuscation approach maximizes unlinkability by transforming the CAMs’ original data within a distortion threshold, preserving data utility while confounding the GPA’s ability to reliably link messages to specific vehicles. The experimental evaluation confirms the superiority of our method when compared with multivariate independent noise models, including Gaussian and Laplace. Our approach also incorporates an authentication protocol, ensuring the secure and collaborative execution of the obfuscation algorithm by the vehicles involved.
The role of trust in communication systems is critical in an interconnected world. Remote Attestation (RA) introduces a new paradigm to establish this trust, enabling communication systems to defend against new classes of attackers. In the context of distributed group communications in which communication partners join the network at runtime, existing solutions for network attestation are inadequate. They rely either on a central entity to facilitate joining of devices and/or network attestation, or on hardware features that are not present on the most common cryptoprocessors.To address this gap, a new network RA scheme is proposed in this work. This scheme includes two protocols: one for attesting communication partners upon network entry and another one for regular network attestation. Instead of a third-party verifier, the members of the network themselves act as verifiers in the system. The proposed protocol suite is integrated into LCMsec, an existing peer-to-peer Publish/Subscribe protocol in which trust was previously coupled to the possession of private keying material. A proof-of-concept implementation is assessed to show that the network attestation latency scales well with large group sizes. It is demonstrated that the protocol introduces little startup latency beyond the baseline introduced by the underlying attestation mechanism.
Differential Privacy (DP) provides a rigorous framework for developing privacy-preserving applications. For discrete selection problems, the Exponential Mechanism (EM) offers a computationally tractable solution. However, the conventional EM fails to incorporate critical real-world constraints, such as non-uniform priors on the input domain or desired marginal distributions (evidence) over the output space. This limitation is significant, as the only alternative - direct optimization under such constraints - is often computationally prohibitive for largescale applications, impeding the practical deployment of DP. To address this challenge, we introduce a novel utility formulation for the EM that explicitly models datapoints' dissimilarity while integrating prior information. This formulation is parameterized, allowing us to generate an ensemble of candidate EMs. We propose an efficient bisection-based search heuristic to select a near-optimal mechanism from this ensemble. Empirical evaluation demonstrates that our method improves privacy (up to 5%) parameter epsilon over the conventional EM. Furthermore, its performance closely approximates the optimal DP solution under constraints on expected dissimilarity, input priors, and output evidence, offering a practical and scalable approach.
Joint Communication and Sensing (JCAS) technology is envisioned to become a part of many Cyber-Physical Systems (CPSs), further advancing essential capabilities provided to numerous applications in critical infrastructure. Due to the use of human-specific sensing data, JCAS systems are vulnerable to privacy threats, and there is no established method to assess the privacy of such systems efficiently. In this paper, we propose a new privacy assessment approach that quantitatively expresses the overall privacy of the JCAS-based system under consideration, for which privacy enhancements are then proposed. While we apply our approach to a railway JCAS-based CPS in this paper, it also applies to CPSs of other kinds.