Skip to main content
QUICK REVIEW

[论文解读] The current state of affairs in 5G security and the main remaining security challenges

Roger Piqueras Jover|arXiv (Cornell University)|Apr 17, 2019
Vehicular Ad Hoc Networks (VANETs)Engineering参考文献 18被引用 18
一句话总结

本文分析了5G协议安全的现状,识别出从LTE继承而来的关键漏洞以及5G认证和隐私机制中的新缺陷。它提出通过集成公钥基础设施(PKI)和数字证书来取代对预认证消息的信任,从而实现对基站信号的端到端验证,缓解如IMSI捕获器和欺骗攻击等威胁。

ABSTRACT

The first release of the 5G protocol specifications, 3rd Generation Partnership Project (3GPP) Release 15, were published in December 2017 and the first 5G protocol security specifications in March 2018. As one of the technology cornerstones for Vehicle-to-Vehicle (V2X), Vehicle-to-Everything (V2E) systems and other critical systems, 5G defines some strict communication goals, such as massive device connectivity, sub-10ms latency and ultra high bit-rate. Likewise, given the firm security requirements of certain critical applications expected to be deployed on this new cellular communications standard, 5G defines important security goals. As such, 5G networks are intended to address known protocol vulnerabilities present in both legacy GSM (Global System for Mobile Communications) networks as well as current LTE (Long Term Evolution) mobile systems. This manuscript presents a summary and analysis of the current state of affairs in 5G protocol security, discussing the main areas that should still be improved further before 5G systems go live. Although the 5G security standard documents were released just a year ago, there is a number of research papers detailing security vulnerabilities, which are summarized in this manuscript as well.

研究动机与目标

  • 解决源自传统LTE和2G架构的5G协议中持续存在的安全漏洞。
  • 识别并分析绕过当前5G安全机制的基于预认证消息的攻击。
  • 提出一种可扩展、密码学上坚固的解决方案,以取代对基站消息的隐式信任。
  • 倡导将公钥基础设施(PKI)和数字证书集成到5G核心架构中,以实现端到端认证。
  • 强调迫切需要对5G安全进行整体性、架构层面的重新设计,而不仅仅是点对点修补。

提出的方法

  • 分析5G Release 15规范,重点关注认证与密钥协议(AKA)以及SUPI/SUCI机制。
  • 在5G背景下评估现有LTE漏洞,特别是IMSI捕获器和预认证消息欺骗问题。
  • 提出一种基于数字证书的系统,其中基站使用运营商颁发的证书对广播消息进行签名。
  • 引入时间戳签名以防止重放攻击,增强消息的完整性和真实性。
  • 建议采用分层信任模型,包括全球根CA和区域CA,移动运营商作为终端实体证书颁发机构。
  • 主张用经过密码学验证、证书保护的通信模型取代“预认证消息”这一术语。

实验结果

研究问题

  • RQ15G协议中哪些主要安全漏洞源自LTE及更早的通信代际?
  • RQ2当前5G机制如SUPI和SUCI为何无法防止基于预认证消息的攻击?
  • RQ3为消除对基站信号的隐式信任,需要哪些架构层面的变更?
  • RQ4公钥基础设施(PKI)和数字证书能否有效保护5G广播消息并防止欺骗攻击?
  • RQ5可信证书颁发机构(CA)和信任根在大规模保护5G生态系统中应发挥何种作用?

主要发现

  • 尽管有所改进,5G当前的安全模型仍依赖对预认证消息的隐式信任,使其易受欺骗和IMSI/SUPI追踪攻击。
  • SUCI机制虽保护了SUPI的机密性,但无法防止所有预认证攻击,尤其是那些利用AKA执行前消息完整性的攻击。
  • 研究人员已识别出新5G AKA协议中的关键缺陷,表明仅靠密码学设计不足以保障安全,必须辅以架构加固。
  • 基于数字证书并结合时间戳签名的解决方案可有效防止广播消息上的重放和欺骗攻击。
  • 将PKI与分层信任模型(包括全球根CA和运营商级证书颁发)集成,可实现端到端认证,并消除对未经验证基站的信任。
  • 5G规范中缺乏标准化、全系统范围的PKI,留下关键安全缺口,必须在全面部署前予以解决。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。