NReplay: 5G Key Reinstallation Attack Based on NAS Layer Vulnerabilities
Wei Fan, Bingnan Shi, Cheng Peng · 2024
With the rapid development of 5G communication, it has been widely applied by users in multiple fields. However, this has led to concerns about security and privacy. This paper identifies two vulnerabilities within the 5G non-access stratum (NAS) layer, which could lead to key reinstallation attacks, posing significant risks to the privacy and communication security of user equipment (UE). In response to these vulnerabilities, we design a key reinstallation attack called NReplay. By coercing the counter reset in the UE's NAS layer, we are able to reconstruct the keystream and utilize it to forge encrypted mess-ages, ultimately resulting in the deregistration of the victim UE from the 5G network. We validate the feasibility of NReplay in 5G Standalone (SA) network through attack experiments con-ducted on three major mobile communication operators. Additionally, we propose corresponding defense measures to enhance the overall encryption security system of 5G air interface.