FMC (Fixed Mobile Convergence) Wh t Ab What About Security? t S - - PowerPoint PPT Presentation

fmc fixed mobile convergence wh t ab what about security
SMART_READER_LITE
LIVE PREVIEW

FMC (Fixed Mobile Convergence) Wh t Ab What About Security? t S - - PowerPoint PPT Presentation

FMC (Fixed Mobile Convergence) Wh t Ab What About Security? t S it ? Vancouver June 2008 Vancouver June 2008 Franck Veysset, Orange Labs Firstname.lastname at orange-ftgroup dot com research & development Agenda Introduction


slide-1
SLIDE 1

FMC (Fixed Mobile Convergence) Wh t Ab t S it ? What About Security?

Vancouver – June 2008 Vancouver June 2008

Franck Veysset, Orange Labs Firstname.lastname at orange-ftgroup dot com

research & development

slide-2
SLIDE 2

Agenda

Introduction - FMC? WIFI-SIP overview UMA overview Femtocell overview iWLAN Architecture Security?

"Technology overview ( not FTGroup network strategy )"

research & development France Telecom Group FIRST 2008 p 2

Technology overview ( not FTGroup network strategy )

slide-3
SLIDE 3

WiFi-SIP, UMA, FMC…

New needs – new offers

Simplify the current situation (PSTN GSM VoIP phones at home !!)

, ,

Simplify the current situation (PSTN, GSM, VoIP phones at home !!) Use of a single phone (wireless)

  • At home and on the road

Enhance quality / coverage at home

WiFi U A P t h i ll l

  • WiFi: Use your own A.P. at home – improve cellular coverage
  • Handover GSM/WIFI?

Higher data rate -> new services? Lowers communication costs (at least from the customer point of view)

  • Good for ARPU and market shares

One phone = increase reachability

Different technologies are available Different technologies are available

WiFi-SIP UMA (GAN) Femtocell / picocell

O

research & development France Telecom Group FIRST 2008 p 3

Others…

slide-4
SLIDE 4

FMC?

Fixed to Mobile Convergence First tests: Denmark, 1997 – PSTN/GSM Single number one messaging system

Single number, one messaging system No handover

First “real” offers in 2005 – UMA based

BT with “Fusion”, Bluetooth based at its beginning

In France, “emergence” of FMC?

After Triple play offers, quadruple play is becoming the standard…

  • Twin / beautifulphone (Dual phone GSM/WiFi SIP?) by n9uf Cegetel
  • Free phone (GSM/WiFi SIP)
  • Unik (GSM/UMA, Orange)

research & development France Telecom Group FIRST 2008 p 4

slide-5
SLIDE 5

FMC (2/2)

Real FMC possible with WiFi wide adoption

L WiFi hi

Low-power WiFi chips

Phone (and WiFi) needs to be always on

research & development France Telecom Group FIRST 2008 p 5

slide-6
SLIDE 6

Other “technologies” exist…

More or less in use Don’t provide handover

p

Bluetooth VoIP

Bluetooth dongle (Siemens) Bluetooth dongle (Siemens)

Dedicated WiFi phone

Netgear Skype WiFi Phone

g yp

  • Netgear SPH101

Other parternships between pure internet players and manufacturers

SIM reader on fixed phone (to import contact list!)

research & development France Telecom Group FIRST 2008 p 6

slide-7
SLIDE 7

Wi-Fi SIP (Session Initiation protocol) (Session Initiation protocol)

research & development France Telecom Group FIRST 2008 p 7

slide-8
SLIDE 8

SIP: Intro

Internet World

SIP is an IETF standard (2002)

SIP id i li

SIP provides signaling Voice transport relies on RTP

WiFi-SIP very similar to genuine VoIP-SIP

WiFi SIP very similar to genuine VoIP SIP

On the terminal

SIP and RTP stack: signaling and stream Add IP and WIFI stack This is a WiFi SIP-phone

SIP: just add another application on your Wi-Fi terminal Di j i d f GSM

Disjoined from GSM access No handover (except with GSM “private extensions”)

research & development France Telecom Group FIRST 2008 p 8

slide-9
SLIDE 9

Wi-Fi SIP Overview

Home gateway Gateway / MGC SIP serveur

SIP+RTP SIP+RTP SS7+voice

research & development France Telecom Group FIRST 2008 p 9

slide-10
SLIDE 10

SIP Security

Authentication

At best id and password (http digest)

Strong authentication is possible but not mandatory (read: not used )

Strong authentication is possible but not mandatory (read: not used…)

  • Need to be supported by terminals and servers

Confidentiality

Usually: Clear text (RTP )

Usually: Clear text… (RTP…) It is possible to use SRTP (and SIP TLS) but… Therefore relies on Wi-Fi security (critical path)

Strong lack of security functionalities Strong lack of security functionalities

Does low cost means lack of functionalities? Sip design & security (IETF way…)

Wi Fi it i th iti l

Wi-Fi security is then critical

WEP only?

research & development France Telecom Group FIRST 2008 p 10

slide-11
SLIDE 11

UMA (Unlicensed Mobile Access) (Unlicensed Mobile Access)

research & development France Telecom Group FIRST 2008 p 11

slide-12
SLIDE 12

UMA: Intro

From the telco world

UMA Consortium (Alcatel, BT, Cingular, Ericsson, Motorola, Nokia, Nortel,

RIM Siemens Sony Ericsson etc ) RIM, Siemens, Sony Ericsson, etc.)

UMA not a standard, but specifications pushed into 3GPP (GAN)

Provides an alternative access to 2G/3G services On the terminal

IPsec stack: to reach the UMA platform UMA stack: GSM packet encapsulation in IP (includes RTP…) And of course IP+WiFi stack SIM (USIM) for crypto (authentication, encryption…)

UMA lt ti t GSM t k

UMA: alternative access to GSM network

Full access (Voice, GPRS, SMS…)

research & development France Telecom Group FIRST 2008 p 12

slide-13
SLIDE 13

http://www.umatechnology.org/

research & development France Telecom Group FIRST 2008 p 13

slide-14
SLIDE 14

UMA Overview

research & development France Telecom Group FIRST 2008 p 14

slide-15
SLIDE 15

UMA Functional Architecture

research & development France Telecom Group FIRST 2008 p 15

slide-16
SLIDE 16

UMA Security

Authentication

Authentication relies on the SIM/USIM

  • IKEv2 and EAP-SIM / EAP-AKA (mutual) + X509 (server side)
  • Then genuine GSM authentication (A3/A8)

Encryption

Wi-Fi security for domestic link IPsec between terminal and UNC Warning: NULL encryption possible on IPsec link

research & development France Telecom Group FIRST 2008 p 16

slide-17
SLIDE 17

Femtocell

research & development France Telecom Group FIRST 2008 p 17

slide-18
SLIDE 18

Principles

Femtocells are low-power wireless access points that operate in

p p p licensed spectrum to connect standard mobile devices to a mobile

  • perator’s network using residential DSL or cable broadband

connections (cf femtoforum.org)

New way to connect to 2G/3G network

I t l

Increase telco. coverage IP connection to core network Any 2G/3G handset supported

research & development France Telecom Group FIRST 2008 p 18

slide-19
SLIDE 19

Femtocell Architecture (3G)

research & development France Telecom Group FIRST 2008 p 19

slide-20
SLIDE 20

Femtocell Security

No standardization yet (Work in progress)

Femtoforum 3GPP Femtoforum, 3GPP…

Authentication

User and/or network authentication rely on the SIM/USIM

  • Genuine GSM/UMTS world…

What about the *cell authentication? Usim?

Encryption

Idem, genuine GSM/UMTS functionalities

Questions: Iub+ / A/Gb interfaces?

BSC/RNC connected to the internet? IPsec on Iub+ link?

Security of customer’s RNC (thee *cell) is the key point

research & development France Telecom Group FIRST 2008 p 20

slide-21
SLIDE 21

iWLAN

research & development France Telecom Group FIRST 2008 p 21

slide-22
SLIDE 22

I-WLAN Architecture

research & development France Telecom Group FIRST 2008 p 22

slide-23
SLIDE 23

I-WLAN Security

Packet Data Gateway 3GPP AAA server HLR/AuC SA IKEv2 negotiation EAP cellular methods (EAP-AKA) Authentication vectors IPsec tunnel establishment

S it i il t UMA

Security similar to UMA PDG located in a different place than in 3GPP architecture

(PDG in the core network)

research & development France Telecom Group FIRST 2008 p 23

slide-24
SLIDE 24

I-Wlan Issues

For now, data only services

, y

IPsec gateway on internet

Attacks always possible Attacks always possible

Specific attacks on IKE v2, EAP-xxx… fuzzing for example When the user is connected, access only to Wi interface

Almost identical to genuine GPRS access

Core network should not be reachable

Core network should not be reachable

But the technology still looks quite immature

research & development France Telecom Group FIRST 2008 p 24

slide-25
SLIDE 25

Problems, security issues?

research & development France Telecom Group FIRST 2008 p 25

slide-26
SLIDE 26

Quick Analysis

Not exhaustive New technology… stay tuned for more information Implementation proprietary

GAN conformity still to be confirmed SIP: relies on provider implementation / architectural choices SIP: relies on provider implementation / architectural choices Cell: also relies on provider implementation and tech choices I-WLAN: lack of standardization

research & development France Telecom Group FIRST 2008 p 26

slide-27
SLIDE 27

WiFi AP…

First thing: needs for a Wi-Fi access point

Open, WEP, WPA? WiFi always on?

Thi i ht h t i t it

This might have strong impact on your security Corporate case: deploy or reuse existing Wi-Fi network

Mix voice and data on the same network? With uncontrolled internet access ?

research & development France Telecom Group FIRST 2008 p 27

slide-28
SLIDE 28

Authentication (SIP, EAP…) ( )

SIP authentication

May rely on clear text or HTTP digest MD5 is not particularly “on the rise”… Brute force attack is feasible on low entropy passwords

  • 40 Millions MD5 per second on a Bi-Xeon (mdcrack)
  • More than 100M on well choosen hard (PS3…)

EAP AKA EAP SIM th ti ti

EAP-AKA or EAP-SIM authentication

Looks quite healthy Tamper resistant hardware is definitively a plus

research & development France Telecom Group FIRST 2008 p 28

slide-29
SLIDE 29

General comments

Exposing Telco core network?

Fuzzer anyone? This might be the next big threat

Sensible devices are located at customer premises? Handling and locating emergency calls? Towards new frauds?

I t t t k

Impact on customer network

QoS on shared network… Power outage…

research & development France Telecom Group FIRST 2008 p 29

slide-30
SLIDE 30

Questions?

Thanks for your attention

research & development