Exposing Device Features on 4G and 5G Networks
Altaf af Shai aik
(Technische Universität Berlin, Germany)
Ravishankar Borgaonkar
(SINTEF Digital, Norway)
1 26.09.2019
Hardware.io 2019, Netherlands
4G and 5G Networks Altaf af Shai aik (Technische Universitt - - PowerPoint PPT Presentation
Exposing Device Features on KAITIAKI 4G and 5G Networks Altaf af Shai aik (Technische Universitt Berlin, Germany) Ravishankar Borgaonkar (SINTEF Digital, Norway) Hardware.io 2019, Netherlands 26.09.2019 1 5G? G? Human Communication
Altaf af Shai aik
(Technische Universität Berlin, Germany)
Ravishankar Borgaonkar
(SINTEF Digital, Norway)
1 26.09.2019
Hardware.io 2019, Netherlands
2 26.09.2019
3 26.09.2019
Source: https://www.informationsecuritybuzz.com/articles/security-challenges-next-generation-5g-mobile-networks/
New Services (Use Cases) LTE Security Requirements + Enhancements New Networking Technologies NFV/SDN
26.09.2019 4
Device identifiers/ Credentials/ Authentication+/ Encryption/ Integrity+/ Privacy+/ Resilience+
Edge Cloud
Network Slicing Security/ NFV/SDN Security/
Central Cloud
Mobile Edge Computing/
Cell
5 26.09.2019
6 26.09.2019
7 26.09.2019
Core network Capabilities1 (Security algorithms, voice calling support, V2V) Radio access Capabilities2 (frequency bands, Rx & Tx features, MIMO, CA, Category)
1. 3GPP TS 24.301, 23.401, 24.008 2. 3GPP TS 36.331
8 26.09.2019
9 26.09.2019
10 26.09.2019
11 26.09.2019
Get capabilities Registration Success Authentication and Security Send Capabilities Radio Access Capabilities Save all Capabilities Registration (Core Network Capabilities) OTA Security
12 26.09.2019
13 26.09.2019
UE Capabilities
14 26.09.2019
cars, IoT devices, trackers, laptops, routers….
devices and commercial networks
15 26.09.2019
17 26.09.2019
similar to IP Nmap
Baseband Vendor Name and Model Cellular Phone (Tablet) Android Samsung Huawei HTC LG NOKIA iOS Iphone, Ipad (with version) Others Car Railways Router USB dongle Hotspots Laptops Vending machines Wearables Cellular IoT NB-IoT Smart Meters Smart grid Sensors LTE-M Asset Trackers Agriculture Home automation
Chip Maker, Device Model, Operating System, Application of device, Baseband Software Version
18 26.09.2019
V2V for automated car Voice calling and codec support for phone GPS capability for tracker Data only support for routers, USB data sticks (SMS only)
19 26.09.2019
20 26.09.2019
21 26.09.2019
Devices
Capability Huawei Samsung Intel Mediatek Qualcomm CM Service Prompt 1 1 EIA0 1 1 1 1 Access class controlfor CSFB 1 1 1 Extended Measurement Capability 1
Implementation differences among Baseband vendors
22 26.09.2019
23 26.09.2019
24 26.09.2019
Capability Phone Others UE’s Usage setting Voice or Data Not present Voice domain preference CS Voice
Voice Not present UMTS AMR codec Present Not
Difference b/w phone and other devices
Capability Android iOS MS assisted GPS 1 Voice over PS-HS- UTRA-FDD-r9 1
Difference b/w iOS and Android
Capability Cellular IoT Cellular PSM Timer 1 T3412 ext period TAU timer 1
Difference b/w cellular and cellular IoT
26.09.2019
Phone Baseband Huawei Huawei Samsung Samsung Apple Intel or QCT
Phone and preferred Baseband
26
27 26.09.2019
29 26.09.2019
Security
detect
30 26.09.2019
Get capabilities Registration Success Send Capabilities
Radio Capabilities
Save all Capabilities OTA Security
Radio Capabilities
RELAY
31 26.09.2019
26.09.2019 32 32
affected (USA, Switzerland, France, Japan, Korea Netherlands, UK, Belgium, Iceland)
33 26.09.2019
34 26.09.2019
35 26.09.2019
Registration Success
Capabilities Capabilities
Registration
PSM_enable PSM_disabled
Authentication and Security
PSM_Not_enabled Battery_Drain
36 26.09.2019
vendors
37 26.09.2019
38 26.09.2019
Fixes in LTE release 14 for NB-IoT will be commercial soon UE Capabilities should be security protected : accessible only after mutual authentication
updated Capabilities should be replayed to UE after NAS security setup for verification – Hash of them
Thank you
altaf329@sect.tu-berlin.de Ravi.borgaonkar@sintef.no Director@kaitiaki.in
26.09.2019 39