A man-in-the-middle attack on UMTS

A man-in-the-middle attack on UMTS
复制标题

DOI:
10.1145/1023646.1023662
复制
发表时间:
2004-10
期刊:
--
影响因子:
--
通讯作者:
Ulrike Meyer;S. Wetzel
Ulrike Meyer;S. Wetzel
中科院分区:
其他
文献类型:
--
作者:
Ulrike Meyer;S. Wetzel

文献摘要

被引文献

相似文献

在本文中,我们提出了一个中间人攻击的通用移动的电信标准(UMTS),新兴的3G移动的技术之一。这种攻击允许入侵者向UMTS用户冒充有效的GSM基站,而不管是否使用UMTS认证和密钥协商。由于UMTS标准要求在移动的站和网络之间进行相互认证,因此迄今为止,UMTS网络被认为是安全的,不会受到中间人攻击。UMTS标准中定义的网络认证依赖于认证令牌的有效性和随后的安全模式命令的完整性保护,我们表明,这两种机制都是必要的,以防止中间人攻击。因此,我们表明,攻击者可以安装一个模仿攻击,因为GSM基站不支持完整性保护。我们攻击的可能受害者是同时支持UTRAN和GSM空中接口的所有移动的站。特别地,对于在从2G(GSM)到3G(UMTS)技术的过渡阶段期间使用的大多数设备来说,情况就是这样。
In this paper we present a man-in-the-middle attack on the Universal Mobile Telecommunication Standard (UMTS), one of the newly emerging 3G mobile technologies. The attack allows an intruder to impersonate a valid GSM base station to a UMTS subscriber regardless of the fact that UMTS authentication and key agreement are used. As a result, an intruder can eavesdrop on all mobile-station-initiated traffic.Since the UMTS standard requires mutual authentication between the mobile station and the network, so far UMTS networks were considered to be secure against man-in-the-middle attacks. The network authentication defined in the UMTS standard depends on both the validity of the authentication token and the integrity protection of the subsequent security mode command.We show that both of these mechanisms are necessary in order to prevent a man-in-the middle attack. As a consequence we show that an attacker can mount an impersonation attack since GSM base stations do not support integrity protection. Possible victims to our attack are all mobile stations that support the UTRAN and the GSM air interface simultaneously. In particular, this is the case for most of the equipment used during the transition phase from 2G (GSM) to 3G (UMTS) technology.