DocumentCode :
2434633
Title :
Security Analysis and Amendment of 3G Core Network Based on MTPsec
Author :
Yang, Yucun ; He, Weiwei ; Feng, Suili
Author_Institution :
Sch. of Electron. & Inf. Eng., South China Univ. of Technol., Guangzhou
Volume :
1
fYear :
2008
fDate :
19-20 Dec. 2008
Firstpage :
519
Lastpage :
523
Abstract :
Mobile core network uses signaling system no. 7 (SS7) as its signaling system. SS7 takes charge of call setup, roaming, teardown messages, database queries and so on, and becomes the important goals of the attackers or the stealers as there is a large number of userpsilas information, such as identity, location, and service, contained in signaling messages. The use of MTPsec at MTP3 layer in SS7 protocol stack is a good solution to provide secure protection for signaling messages in 3G core network. MTPsec consists of key exchange (KE) protocol and authentication header (AH) protocol. However, some leaks in KE protocol make the core network face serious threats. In this paper, we firstly discuss the mechanism of MTPsec, analyze the security of KE protocol, and then point out that the flaw in KE may cause ldquoman-in-middle attackrdquo. Secondly, we propose a possible modification to prevent the MTPsec protocol from the attacks. Finally, we use BAN logic to make formal analysis on the security of the original and the modified authentication protocols in KE, respectively. It is shown that the modified protocol can offer the secure authentications between the initiator and the responder.
Keywords :
3G mobile communication; signalling protocols; telecommunication security; 3G core network; BAN logic; MTP3 layer; MTPsec protocol; SS7 protocol stack; authentication header protocol; key exchange protocol; man-in-middle attack; security analysis; signaling message secure protection; signaling system 7; Access protocols; Authentication; Body sensor networks; Communication system signaling; Conferences; DH-HEMTs; Logic; Mobile communication; Protection; Radio access networks; BAN logic; Key exchange; MTPsec protocol; Man-in-middle attack;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computational Intelligence and Industrial Application, 2008. PACIIA '08. Pacific-Asia Workshop on
Conference_Location :
Wuhan
Print_ISBN :
978-0-7695-3490-9
Type :
conf
DOI :
10.1109/PACIIA.2008.112
Filename :
4756614
Link To Document :
بازگشت