Call Me Maybe: Eavesdropping Encrypted LTE Calls With ReVoLTE

Call Me Maybe: Eavesdropping Encrypted LTE Calls With ReVoLTE
复制标题

Call Me Maybe:使用 ReVoLTE 窃听加密 LTE 通话

DOI:
--
复制
发表时间:
2020
期刊:
USENIX Security Symposium
影响因子:
--
通讯作者:
Christina Pöpper
Christina Pöpper
中科院分区:
--
文献类型:
--
作者:
David Rupprecht;K. Kohls;Thorsten Holz;Christina Pöpper

文献摘要

被引文献

相似文献

VoLTE(Voice over LTE)是一种基于分组的电话服务,无缝集成到长期演进(LTE)标准中,并由大多数电信提供商在实践中部署。由于这种广泛的使用,对VoLTE的成功攻击可能会影响全球大量用户。在这项工作中,我们介绍了R E V O LTE,一种利用LTE实现方法来恢复加密VoLTE通话内容的攻击,从而使对手能够窃听电话。R E V O LTE在无线电层上利用可预测的密钥流重用,允许对手以最少的资源解密记录的通话。通过一系列的初步实验和实际实验,我们成功地证明了R E V O LTE的可行性,并分析了在商业网络中严重影响我们攻击的各种因素。为了减轻R E V O LTE攻击,我们提出并讨论了供应商和设备供应商可部署的短期和长期对策。
Voice over LTE (VoLTE) is a packet-based telephony service seamlessly integrated into the Long Term Evolution (LTE) standard and deployed by most telecommunication providers in practice. Due to this widespread use, successful attacks against VoLTE can affect a large number of users worldwide. In this work, we introduce R E V O LTE, an attack that exploits an LTE implementation flaw to recover the contents of an encrypted VoLTE call, hence enabling an adversary to eaves-drop on phone calls. R E V O LTE makes use of a predictable keystream reuse on the radio layer that allows an adversary to decrypt a recorded call with minimal resources. Through a series of preliminary as well as real-world experiments, we successfully demonstrate the feasibility of R E V O LTE and analyze various factors that critically influence our attack in commercial networks. For mitigating the R E V O LTE attack, we propose and discuss short-and long-term countermeasures deployable by providers and equipment vendors.