A Novel 5G Key Reinstallation Attack and Defensive Strategies
Wei Fan, Bingnan Shi, Cheng Peng · 2025
In recent years, fifth-generation (5G) technology, as the latest mobile communication technology, has gradually matured and entered the commercialization stage. However, with the increasing number of attacks against 5G networks, concerns about its security risks have been raised. This paper conducts a detailed study of 5G standalone (SA) networks and proposes a key reinstallation attack named NRetry based on two vulnerabilities identified in the Non-Access Stratum (NAS) layer. This attack leverages a man-in-the-middle (MitM) device to trigger keystream reuse, allowing encrypted messages to be decrypted. The attacker can even forge encrypted messages to deceive the core network into incorrectly handling the user equipment (UE) state. In light of the significant security risks posed by the NRetry attack, we propose corresponding remedies for the identified vulnerabilities. Additionally, we introduce a core network defense system named DDS, based on a state machine model, to detect and defend against such attacks. The system is divided into three modules, highly configurable, capable of extracting attack signatures, and setting corresponding detection thresholds. Upon detecting an attack and verifying the authenticity of the alert, the system quickly activates a defense module to reject suspicious messages and employs bidirectional positioning technology to identify and block the attacker's MitM device, thereby preventing further damage. We have validated the effectiveness of DDS in real-world scenarios and conducted horizontal comparisons to demonstrate the advantages of our approach.