On Key Reinstallation Attacks over 4G LTE Control-Plane: Feasibility and Negative Impact

On Key Reinstallation Attacks over 4G LTE Control-Plane: Feasibility and Negative Impact
复制标题

4G LTE 控制平面上的关键重装攻击:可行性和负面影响

DOI:
10.1145/3485832.3485833
复制
发表时间:
2021
期刊:
Annual Computer Security Applications Conference (ACSAC
影响因子:
--
通讯作者:
Anwar, Fatima Muhammad
Anwar, Fatima Muhammad
中科院分区:
--
文献类型:
--
作者:
Raza, Muhammad Taqi;Guo, Yunqi;Lu, Songwu;Anwar, Fatima Muhammad

文献摘要

参考文献

被引文献

相似文献

研究了4G LTE网络中密钥重装攻击的可行性。众所周知,LTE使用会话密钥用于其控制平面信令分组的机密性和完整性保护。然而,如果密钥未被更新并且计数器被重置,则可能出现密钥重新安装攻击。在本文中,我们表明,在当前的LTE安全设置的几个设计选择容易受到关键的重新安装攻击。具体地,在控制平面上,在设备和网络之间建立安全性的LTE安全性关联建立过程被断开。密钥通过一个过程安装,而其相关参数(如上行链路和下行链路计数器)通过另一个不同的过程重置。因此,对手可以利用不相交的安全设置过程,并发起密钥流重用攻击。因此,当他欺骗受害者使用相同的密钥对和计数器值来加密多个消息时,他就破坏了消息加密。这种控制平面攻击劫持了位置更新过程,从而使设备无法从互联网访问。此外,它还可以从LTE网络注销受害者。我们已经与美国两家主要运营商确认了我们的发现,并发现此类攻击可以通过软件定义的无线电设备发起,成本约为299美元。我们还提出了防范此类威胁的补救措施。
This paper studies the feasibility of key reinstallation attacks in the 4G LTE network. It is well known that LTE uses session keys for confidentiality and integrity protection of its control-plane signaling packets. However, if the keys are not updated and counters are reset, key reinstallation attacks may arise. In this paper, we show that several design choices in the current LTE security setup are vulnerable to key reinstallation attacks. Specifically, on the control plane, the LTE security association setup procedures, which establish security between the device and the network, are disconnected. The keys are installed through one procedure, whereas their associated parameters (such as uplink and downlink counters) are reset through another different procedure. The adversary can thus exploit the disjoint security setup procedures, and launch the key stream reuse attacks. He consequently breaks message encryption, when he tricks the victim to use the same pair of keys and counter value to encrypt multiple messages. This control-plane attack hijacks the location update procedure, thus rendering the device to be unreachable from the Internet. Moreover, it may also deregister the victim from the LTE network. We have confirmed our findings with two major US operators, and found that such attacks can be launched with software-defined radio devices that cost about $299. We further propose remedies to defend against such threats.
语音通话如何影响运营 LTE 网络中的数据
DOI: 10.1145/2500423.2500429
发表时间: 2013
期刊: Proceedings of the 19th annual international conference on Mobile computing & networking
影响因子: --
作者:
Guan;Chunyi Peng;Hongqi Wang;Chi;Songwu Lu
通讯作者: Songwu Lu
检测移动网络中有问题的控制平面协议交互
DOI: 10.1109/tnet.2015.2404336
发表时间: 2016
期刊: IEEE/ACM Transactions on Networking
影响因子: --
作者:
Guan;Yuanjie Li;Chunyi Peng;Chi;Songwu Lu
通讯作者: Songwu Lu
LTE 中上行控制信道干扰的检测和缓解
DOI: 10.1109/milcom.2014.199
发表时间: 2014
期刊: 2014 IEEE Military Communications Conference
影响因子: --
作者:
Marc Lichtman;Thaddeus Czauski;Sean Ha;Paul David;Jeffrey H. Reed
通讯作者: Jeffrey H. Reed
暴露协议层间和无线电间交互的 LTE 安全弱点
DOI: 10.1007/978-3-319-78813-5_16
发表时间: 2017
期刊: 2012 IEEE Symposium on Security and Privacy
影响因子: --
作者:
M. T. Raza;F. Anwar;Songwu Lu
通讯作者: Songwu Lu
Call Me Maybe:使用 ReVoLTE 窃听加密 LTE 通话
DOI: --
发表时间: 2020
期刊: USENIX Security Symposium
影响因子: --
作者:
David Rupprecht;K. Kohls;Thorsten Holz;Christina Pöpper
通讯作者: Christina Pöpper