What This Bill Does
This bill directs the Assistant Secretary of Commerce for Communications and Information to write a report about cybersecurity weaknesses in mobile phone service networks. The report will examine how vulnerable these networks are to cyberattacks and surveillance by hostile actors. The Assistant Secretary must submit this report to Congress within one year of the bill becoming law.
Who It Affects
Mobile service providers (including small and rural providers), mobile phone manufacturers, makers of mobile operating systems and apps, academic researchers, the Federal Communications Commission, the Department of Homeland Security, the Department of State, the intelligence community (a term defined in the National Security Act of 1947), and Congress.
Key Provisions
- The Assistant Secretary must examine how mobile service providers have addressed cybersecurity weaknesses found by researchers and federal agencies. (Sec. 2(b)(1))
- The report must discuss whether customers consider cybersecurity when buying mobile service and whether tools exist to help customers understand cybersecurity risks. (Sec. 2(b)(2))
- The report must estimate how widely encryption (scrambling information so others cannot read it) and authentication techniques (methods to verify identity) are used in mobile phones, services and software. (Sec. 2(b)(4))
- The report must discuss obstacles preventing providers from using stronger encryption and authentication methods and removing outdated ones with known weaknesses. (Sec. 2(b)(5))
- The report must estimate how widely cell site simulators (devices that trick phones into connecting to fake networks) and similar surveillance technologies are available and used by hostile actors in the United States. (Sec. 2(b)(7))
- The Assistant Secretary must exclude 5G technology from the report and only examine weaknesses that have been exploited in real situations or realistically could be exploited. (Sec. 2(d)(2), (3))
What Changes
If this bill becomes law, Congress will receive a detailed report examining how secure mobile phone networks are against cyberattacks and surveillance. The report will include classified (secret) information provided separately to Congress and will have sensitive technical details removed from the public version.
Important Definitions
- "Adversary" means any unauthorized hacker entering a mobile network, or any foreign government or foreign person conducting serious, long-term actions against United States national security or the safety of Americans. (Sec. 2(f)(1))
- "Mobile service" means commercial mobile service (regular cell phone service) or commercial mobile data service provided to United States customers. (Sec. 2(f)(6))
- "Mobile communications equipment or service" means any equipment or service needed to provide mobile service. (Sec. 2(f)(5))
- "United States person" means a U.S. citizen, a permanent resident alien, an organization created under U.S. law, or any person physically located in the United States. (Sec. 2(f)(8))
Effective Date
Not specified in bill text. The report is due one year after the date the bill becomes law.
IIB
118TH CONGRESS
1ST SESSION H. R. 1123
IN THE SENATE OF THE UNITED STATES
MARCH 8, 2023
Received; read twice and referred to the Committee on Commerce, Science,
and Transportation
AN ACT
To direct the Assistant Secretary of Commerce for Commu-
nications and Information to submit to Congress a report
examining the cybersecurity of mobile service networks,
and for other purposes.
Be it enacted by the Senate and House of Representa-
1
tives of the United States of America in Congress assembled,
2
VerDate Sep 11 2014
00:45 Mar 09, 2023
Jkt 039200
PO 00000
Frm 00001
Fmt 6652
Sfmt 6201
E:\BILLS\H1123.RFS
H1123
pbinns on DSKJLVW7X2PROD with $$_JOB
2
HR 1123 RFS
SECTION 1. SHORT TITLE.
1
This Act may be cited as the ‘‘Understanding Cyber-
2
security of Mobile Networks Act’’.
3
SEC. 2. REPORT ON CYBERSECURITY OF MOBILE SERVICE
4
NETWORKS.
5
(a) IN GENERAL.—Not later than 1 year after the
6
date of the enactment of this Act, the Assistant Secretary,
7
in consultation with the Department of Homeland Secu-
8
rity, shall submit to the Committee on Energy and Com-
9
merce of the House of Representatives and the Committee
10
on Commerce, Science, and Transportation of the Senate
11
a report examining the cybersecurity of mobile service net-
12
works and the vulnerability of such networks and mobile
13
devices to cyberattacks and surveillance conducted by ad-
14
versaries.
15
(b) MATTERS TO BE INCLUDED.—The report re-
16
quired by subsection (a) shall include the following:
17
(1) An assessment of the degree to which pro-
18
viders of mobile service have addressed, are address-
19
ing,
or
have
not
addressed
cybersecurity
20
vulnerabilities (including vulnerabilities the exploi-
21
tation of which could lead to surveillance conducted
22
by adversaries) identified by academic and inde-
23
pendent researchers, multistakeholder standards and
24
technical organizations, industry experts, and Fed-
25
eral agencies, including in relevant reports of—
26
VerDate Sep 11 2014
00:45 Mar 09, 2023
Jkt 039200
PO 00000
Frm 00002
Fmt 6652
Sfmt 6201
E:\BILLS\H1123.RFS
H1123
pbinns on DSKJLVW7X2PROD with $$_JOB
3
HR 1123 RFS
(A) the National Telecommunications and
1
Information Administration;
2
(B) the National Institute of Standards
3
and Technology; and
4
(C) the Department of Homeland Security,
5
including—
6
(i) the Cybersecurity and Infrastruc-
7
ture Security Agency; and
8
(ii) the Science and Technology Direc-
9
torate.
10
(2) A discussion of—
11
(A) the degree to which customers (includ-
12
ing consumers, companies, and government
13
agencies) consider cybersecurity as a factor
14
when considering the purchase of mobile service
15
and mobile devices; and
16
(B) the commercial availability of tools,
17
frameworks, best practices, and other resources
18
for enabling such customers to evaluate cyber-
19
security risk and price tradeoffs.
20
(3) A discussion of the degree to which pro-
21
viders of mobile service have implemented cybersecu-
22
rity best practices and risk assessment frameworks.
23
(4) An estimate and discussion of the preva-
24
lence and efficacy of encryption and authentication
25
VerDate Sep 11 2014
00:45 Mar 09, 2023
Jkt 039200
PO 00000
Frm 00003
Fmt 6652
Sfmt 6201
E:\BILLS\H1123.RFS
H1123
pbinns on DSKJLVW7X2PROD with $$_JOB
4
HR 1123 RFS
algorithms and techniques used in each of the fol-
1
lowing:
2
(A) Mobile service.
3
(B) Mobile communications equipment or
4
services.
5
(C) Commonly used mobile phones and
6
other mobile devices.
7
(D) Commonly used mobile operating sys-
8
tems and communications software and applica-
9
tions.
10
(5) A discussion of the barriers for providers of
11
mobile service to adopt more efficacious encryption
12
and authentication algorithms and techniques and to
13
prohibit the use of older encryption and authentica-
14
tion algorithms and techniques with established
15
vulnerabilities in mobile service, mobile communica-
16
tions equipment or services, and mobile phones and
17
other mobile devices.
18
(6) An estimate and discussion of the preva-
19
lence, usage, and availability of technologies that au-
20
thenticate legitimate mobile service and mobile com-
21
munications equipment or services to which mobile
22
phones and other mobile devices are connected.
23
(7) An estimate and discussion of the preva-
24
lence, costs, commercial availability, and usage by
25
VerDate Sep 11 2014
00:45 Mar 09, 2023
Jkt 039200
PO 00000
Frm 00004
Fmt 6652
Sfmt 6201
E:\BILLS\H1123.RFS
H1123
pbinns on DSKJLVW7X2PROD with $$_JOB
5
HR 1123 RFS
adversaries in the United States of cell site simula-
1
tors (often known as international mobile subscriber
2
identity catchers) and other mobile service surveil-
3
lance and interception technologies.
4
(c) CONSULTATION.—In preparing the report re-
5
quired by subsection (a), the Assistant Secretary shall, to
6
the degree practicable, consult with—
7
(1) the Federal Communications Commission;
8
(2) the National Institute of Standards and
9
Technology;
10
(3) the intelligence community;
11
(4) the Cybersecurity and Infrastructure Secu-
12
rity Agency of the Department of Homeland Secu-
13
rity;
14
(5) the Science and Technology Directorate of
15
the Department of Homeland Security;
16
(6) academic and independent researchers with
17
expertise in privacy, encryption, cybersecurity, and
18
network threats;
19
(7) participants in multistakeholder standards
20
and technical organizations (including the 3rd Gen-
21
eration Partnership Project and the Internet Engi-
22
neering Task Force);
23
(8) international stakeholders, in coordination
24
with the Department of State as appropriate;
25
VerDate Sep 11 2014
00:45 Mar 09, 2023
Jkt 039200
PO 00000
Frm 00005
Fmt 6652
Sfmt 6201
E:\BILLS\H1123.RFS
H1123
pbinns on DSKJLVW7X2PROD with $$_JOB
6
HR 1123 RFS
(9) providers of mobile service, including small
1
providers (or the representatives of such providers)
2
and rural providers (or the representatives of such
3
providers);
4
(10) manufacturers, operators, and providers of
5
mobile communications equipment or services and
6
mobile phones and other mobile devices;
7
(11) developers of mobile operating systems and
8
communications software and applications; and
9
(12) other experts that the Assistant Secretary
10
considers appropriate.
11
(d) SCOPE OF REPORT.—The Assistant Secretary
12
shall—
13
(1) limit the report required by subsection (a)
14
to mobile service networks;
15
(2) exclude consideration of 5G protocols and
16
networks in the report required by subsection (a);
17
(3) limit the assessment required by subsection
18
(b)(1) to vulnerabilities that have been shown to
19
be—
20
(A) exploited in non-laboratory settings; or
21
(B) feasibly and practicably exploitable in
22
real-world conditions; and
23
(4) consider in the report required by sub-
24
section (a) vulnerabilities that have been effectively
25
VerDate Sep 11 2014
00:45 Mar 09, 2023
Jkt 039200
PO 00000
Frm 00006
Fmt 6652
Sfmt 6201
E:\BILLS\H1123.RFS
H1123
pbinns on DSKJLVW7X2PROD with $$_JOB
7
HR 1123 RFS
mitigated by manufacturers of mobile phones and
1
other mobile devices.
2
(e) FORM OF REPORT.—
3
(1) CLASSIFIED INFORMATION.—The report re-
4
quired by subsection (a) shall be produced in unclas-
5
sified form but may contain a classified annex.
6
(2) POTENTIALLY EXPLOITABLE UNCLASSIFIED
7
INFORMATION.—The Assistant Secretary shall re-
8
dact potentially exploitable unclassified information
9
from the report required by subsection (a) but shall
10
provide an unredacted form of the report to the
11
committees described in such subsection.
12
(f) DEFINITIONS.—In this section:
13
(1) ADVERSARY.—The term ‘‘adversary’’ in-
14
cludes—
15
(A) any unauthorized hacker or other in-
16
truder into a mobile service network; and
17
(B) any foreign government or foreign
18
nongovernment person engaged in a long-term
19
pattern or serious instances of conduct signifi-
20
cantly adverse to the national security of the
21
United States or security and safety of United
22
States persons.
23
VerDate Sep 11 2014
00:45 Mar 09, 2023
Jkt 039200
PO 00000
Frm 00007
Fmt 6652
Sfmt 6201
E:\BILLS\H1123.RFS
H1123
pbinns on DSKJLVW7X2PROD with $$_JOB
8
HR 1123 RFS
(2) ASSISTANT SECRETARY.—The term ‘‘Assist-
1
ant Secretary’’ means the Assistant Secretary of
2
Commerce for Communications and Information.
3
(3) ENTITY.—The term ‘‘entity’’ means a part-
4
nership, association, trust, joint venture, corpora-
5
tion, group, subgroup, or other organization.
6
(4) INTELLIGENCE
COMMUNITY.—The term
7
‘‘intelligence community’’ has the meaning given
8
that term in section 3 of the National Security Act
9
of 1947 (50 U.S.C. 3003).
10
(5) MOBILE COMMUNICATIONS EQUIPMENT OR
11
SERVICE.—The term ‘‘mobile communications equip-
12
ment or service’’ means any equipment or service
13
that is essential to the provision of mobile service.
14
(6) MOBILE SERVICE.—The term ‘‘mobile serv-
15
ice’’ means, to the extent provided to United States
16
customers, either or both of the following services:
17
(A) Commercial mobile service (as defined
18
in section 332(d) of the Communications Act of
19
1934 (47 U.S.C. 332(d))).
20
(B) Commercial mobile data service (as de-
21
fined in section 6001 of the Middle Class Tax
22
Relief and Job Creation Act of 2012 (47 U.S.C.
23
1401)).
24
VerDate Sep 11 2014
00:45 Mar 09, 2023
Jkt 039200
PO 00000
Frm 00008
Fmt 6652
Sfmt 6201
E:\BILLS\H1123.RFS
H1123
pbinns on DSKJLVW7X2PROD with $$_JOB
9
HR 1123 RFS
(7) PERSON.—The term ‘‘person’’ means an in-
1
dividual or entity.
2
(8)
UNITED
STATES
PERSON.—The
term
3
‘‘United States person’’ means—
4
(A) an individual who is a United States
5
citizen or an alien lawfully admitted for perma-
6
nent residence to the United States;
7
(B) an entity organized under the laws of
8
the United States or any jurisdiction within the
9
United States, including a foreign branch of
10
such an entity; or
11
(C) any person in the United States.
12
Passed the House of Representatives March 7,
2023.
Attest:
CHERYL L. JOHNSON,
Clerk.
VerDate Sep 11 2014
00:45 Mar 09, 2023
Jkt 039200
PO 00000
Frm 00009
Fmt 6652
Sfmt 6201
E:\BILLS\H1123.RFS
H1123
pbinns on DSKJLVW7X2PROD with $$_JOB