Towards secure 4G and 5G access network protocols

Altaf Shaik · DepositOnce · 2020

The security architecture of 2G and 3G mobile networks has been dramatically improved to accommodate 4G (Fourth Generation, a.k.a Long Term Evolution (LTE)) security requirements. As generations evolve, security improvements address previously known vulnerabilities, esp. in terms of user privacy. Thus, there have been substantial efforts to protect user plane traffic by using robust encryption algorithms over the LTE access network. Contrarily, the control plane remains vulnerable despite its security enhancements. Especially, the radio and subscriber management protocols have not evolved for the last two decades in mobile networks. By design, these protocols are allowed to operate without any security measures to minimize overheads in the system. Such design choices made by the standard body Third Generation Partnership Project (3GPP) are justified as a trade-off between conflicting requirements such as security and availability and performance. These justifications remain valid, considering that telecommunication systems have traditionally been proprietary, expensive, and efforts to mount attacks against them were challenging. Today, the proliferation of inexpensive radio hardware and open-source cellular software has changed the threat landscape in mobile networks. In this context, our research practically investigates the validness of LTE security trade-offs. For this, we develop a low-cost experimental testbed to mount different types of wireless attacks and evaluate their feasibility and impact on commercial LTE devices and networks. We discover several new vulnerabilities in the access network protocols that jeopardize the privacy and availability aspects of the system. We also identify bad security practices in end-user devices and the operator’s infrastructure that catalyze our attacks and further, amplify its consequences. Our findings indicate that the equilibrium points in the trade-offs have changed today compared to where they were when designing the LTE security architecture. Also, the security margins to protect against trade-off changes being too narrow demonstrates the lack of resilience in LTE networks. Unlike jamming or other types of Denial-of-Service (DoS) attacks, ours are stealthy and remain active on end-user devices for a prolonged period. To this extent, we responsibly communicated our research findings to the relevant standard bodies, operators, and baseband vendors. We emphasize that the justification for these trade-offs is no longer valid and violates LTE security requirements. Thus, we propose mitigations to restore privacy and availability aspects of the system, and fortunately, they are enforced into 4G and 5G specifications and also into worldwide operational devices and networks. We recommend that safety margins introduced into future specifications should incorporate greater agility and flexibility to maintain a stable trade-off equation.

Read the paper · More papers on PaperTik