Attacks Against Security Context in 5G Network


연구 분야: Infrastructure



학회: International Symposium on Mobile Internet Security


초록

The security context used in 5G authentication is generated during the Authentication and Key Agreement (AKA) procedure and stored in both the user equipment (UE) and the network sides for the subsequent fast registration procedure. Given its importance, it is imperative to formally analyze the security mechanism of the security context. The security context in the UE can be stored in the Universal Subscriber Identity Module (USIM) card or in the baseband chip. In this work, we present a comprehensive and formal verification of the fast registration procedure based on the security context under the two scenarios in ProVerif. Our analysis identifies two vulnerabilities, including one that has not been reported before. An attacker can exploit these vulnerabilities to register to the network with the victim’s identity and then launch other attacks. To ensure that these attacks are indeed realizable in practice, we have responsibly confirmed them through experimentation in three operators. Our analysis reveals that these vulnerabilities stem from design flaws of the standard and unsafe practices by operators. We finally propose several potential countermeasures to prevent these attacks. We have reported our findings to the GSMA and received a coordinated vulnerability disclosure (CVD) number CVD-2022-0057.


Author Profile
Li Su

China Mobile Research Institute Beijing China

China
Author Profile
Haitao Du

China Mobile Research Institute Beijing China

China
Author Profile
Zhiwei Cui

Beijing University of Posts and Telecommunications Beijing China

Andorra

📄 논문 정보

발행 연도 2023년
인용수 0
출판 국가 Andorra, China
사이트 Springer
좋아요 수 0

연관 논문 목록 (290건)