Long Term Evolution and its security infrastructure

Slides:



Advertisements
Similar presentations
© 3GPP 2010 SEM GPP Standards 3GPP Standards A General Introduction.
Advertisements

Valtteri Niemi, SA3 Chairman
LTE-A Carrier Aggregation
UMA (Unlicensed Mobile Access) El Ayoubi Ahmed Hjiaj Karim.
LTE Security. Agenda Intro … Intro … The LTE System Radio Side (LTE – Long Term Evolution/Evolved UTRAN - EUTRAN) – Improvements in spectral efficiency,
© 3GPP 2009 Mobile World Congress, Barcelona, 19 th February Next Generation Core Networks Summit 2011 Standardisation and Developments within SAE.
World Class Standards ANFOV - Milano, 14 November 2007 – Paolo DE LUTIIS ANFOV - Milano, 14 November 2007 Autore:Paolo DE LUTIIS Telecom Italia Security.
UNIVERSAL MOBILE TELECOMMUNICATION SYSTEM(UMTS). EVOLUATION OF MOBILE COMMUNICATION 1 st Generation : Analog Cellular 2 nd Generation : Multiple Digital.
Aida BotonjićTieto1 LTE Aida Botonjić. Aida BotonjićTieto2 Why LTE? Applications: Interactive gaming DVD quality video Data download/upload Targets: High.
6 The IP Multimedia Subsystem Selected Topics in Information Security – Bazara Barry.
All IP Network Architecture 2001 년 12 월 5 일 통신공학연구실 석사 4 차 유성균
UMTS Mohamed Mokdad Ecole d’Ingénieurs de Bienne.
Overview.  UMTS (Universal Mobile Telecommunication System) the third generation mobile communication systems.
System Architecture for Billing of Multi- Player Games in a Wireless Environment using GSM/UMTS and WLAN Services Femi Adeyemo 11/21/02.
Information Security of Embedded Systems : Communication, wireless remote access Prof. Dr. Holger Schlingloff Institut für Informatik und Fraunhofer.
CSci5221: 3G/4G Cellular Network Architecture Overview 1 Cellular Voice/Data Architectures: A Primer Basics of Cellular Networks Survey of 2G/3G Cellular.
OneM2M Draft proposal for slide set. This is not intended to be a oneM2M presentation. It is a collection of source material slides which can be used.
1 # Mobile Broadband Outlook for the Americas, Rio de Janeiro, 26 April GPP Technology Standards Roadmap Stephen Hayes Chair 3GPP-SA
Confidential and proprietary material for authorized Verizon Wireless personnel only. Use, disclosure or distribution of this material is not permitted.
“Securing IP Multimedia Subsystem (IMS) infrastructures …,” M. Tsagkaropoulos UNIVERSITY OF PATRAS Department of Electrical & Computer Engineering Wireless.
Common Devices Used In Computer Networks
SIGNALING. To establish a telephone call, a series of signaling messages must be exchanged. There are two basic types of signal exchanges: (1) between.
Understanding 3GPP Bearers LTE / HSPA / EPC ‘knowledge nuggets’ Neil Wiffen - More free downloads at Public.
Wang Junxi. Agenda IntroductionTransmission Rate ImprovementStandardsUMTS OrganizationsUMTS Network ArchitectureBenefitConclusion.
Radio network controller
Design of Multi-RAT Virtualization Architectures in LTE-Advanced Wireless Network Location: 國立暨南國際大學電機系 Source: ICIC Express Letters, vol. 8, no. 5, May.
Completing the Convergence Puzzle: A Survey and A Roadmap IEEE Wireless Communications ‧ June 2009 DJAMAL-EDDINE MEDDOUR, USMAN JAVAID, AND NICOLAS BIHANNIC,
T Multimedia Seminar Carlos Herrero55828H Osmo Tolvanen46958L.
© NOKIADEFAULT.PPT / / AO page: 1 USIM requirements and structure NOKIA Mobile Phones TSGT3#3(99)082.
2003/12/291 Security Aspects of 3G-WLAN Interworking 組別: 2 組員: 陳俊文 , 李奇勇 , 黃弘光 , 林柏均
Chapter 4 Application Level Security in Cellular Networks.
LTE Architecture KANNAN M JTO(3G).
1 SAE architecture harmonization R RAN2/3, SA2 Drafting Group.
1 © 2006 Nokia pullola_ ppt / Extending Base Station Active Radio Link Set for Improved Uplink Scheduling Esa-Pekka Pullola Supervisor:
NETWORKING COMPONENTS Buddy Steele Assignment 3, Part 1 CECS-5460: Summer 2014.
Santhosh Rajathayalan ( ) Senthil Kumar Sevugan ( )
Doc.: IEEE /345r0 Submission May 2002 Albert Young, Ralink TechnologySlide 1 Enabling Seamless Hand-Off Across Wireless Networks Albert Young.
3GPP2 LTE Workshop SEOUL, Korea, 27 th– 28 th June GPP LTE Status Status Source Source 3GPP TSG RAN Chairman 3GPP TSG RAN Chairman ETSI TC MSG Chairman.
September 28, 2006 Page 1 3GPP2 MMD Status for IMS Workshop Jack Nasielski
Long Term Evolution (LTE) and System Architecture Evolution (SAE)
Update on 3GPP RAN3 Multi-RAT joint coordination
Update on ETSI Security work Charles Brookson OCG Security Chairman DOCUMENT #:GSC13-PLEN-57 FOR:Information SOURCE:Charles Brookson AGENDA ITEM:6.3
November 2001 Lars Falk, TeliaSlide 1 doc.: IEEE /617r1 Submission Status of 3G Interworking Lars Falk, Telia.
Introduction to 3GPP Specification & new Trends in Radio Networks
Objective This presentation covers the Generation of Telecom Network Evolution. Basically the presentation aims on the evolution from 1G to 4G and some.
Huawei Technologies 1 Technology changes. Communication lasts. AIE Requirements and Competitions.
Introduction to 3GPP2 cdma2000 Technology Workshop Ms. Jane Brownley Chair, 3GPP2 Steering Committee
SEMINAR RADIO NETWORK CONTROLLER FOR 3G MOBILE AND WIRELESS NETWORK DEVICES BY ARDRA . S7 IT SHMEC KADAKKAL ROLL.
1 On 3GPP2 Femto Security Anand Palanigounder Qualcomm Inc. Notice: Contributors grant a free, irrevocable license to 3GPP2 and its Organization.
Features of Long Term Evolution (LTE)
Author: Tobias Kaufmann, Bundesnetzagentur / Federal Network Agency Standardisation of Public Safety in 3GPP.
MBMS in GSM Evolution Systems – A Research Paper Magesh Annamalai – FAU Feeds – Grad Student Sr.Systems Engineer - Location Technology Group T - Mobile.
By Chaitanya Sarma & E.Prashant
3GPP TSG RAN WG2 meeting #92 Nanjing, China 23-27, May 2016 R
LONG TERM EVOLUTION DANISH HASRAT (091042) DEEPAK SINGH (091043) GAURAV THAWANI (091052) NILESH SINGH (091079)
1 Wireless Networks Lecture 17 GPRS: General Packet Radio Service (Part I) Dr. Ghalib A. Shah.
助理教授:吳俊興 助教:楊文健 國立高雄大學 資訊工程學系
LTE Long Term Evolution
.
Update on 3GPP RAN3 Multi-RAT joint coordination
3GPP interworking in R3 Group Name: ARC
教育部補助「行動寬頻尖端技術跨校教學聯盟第二期計畫 -- 行動寬頻網路與應用 -- 小細胞基站聯盟中心」 EPC核心網路系統設計 課程單元 05:Data Services in EPS 計畫主持人:許蒼嶺 (國立中山大學 電機工程學系) 授課教師:萬欽德 (國立高雄第一科技大學 電腦與通訊工程系)
LTE Long Term Evolution
Views for The LTE-Advanced Requirements
Long Term Evolution (LTE)
An Overview on LTE.
.
Erik Guttman, Chairman of 3GPP TSG SA Samsung Electronics
教育部補助「行動寬頻尖端技術跨校教學聯盟第二期計畫 -- 行動寬頻網路與應用 -- 小細胞基站聯盟中心」 模組名稱: 「LTE-Small Cell 核心網路架構及服務」 單元-A4:核心網路 (EPC) 與 Internet Cloud 的介接與存取 計畫主持人:許蒼嶺 (國立中山大學 電機工程學系)
LM 7. Cellular Network Security
Presentation transcript:

Long Term Evolution and its security infrastructure Fataneh Safavieh Mobile security Seminar,Bit,07.02.2011

Outline Introduction: some history &background What is LTE? LTE-SAE Security: some highlights Home(e)Node B Security

Introduction: some history & background

Mobile Evolution Improvements in mobile communication technology during the last two decades The Mobile Broadband is as important as Internt http://www.nsma.org/conf2008/Presentation/2-1045-Miyahara-LTE_Overview_NMSA%2021March08_final.pdf

User Expectations Highly desire of broadband acces everywhere 1. Home, Office 2. Train, Aeroplane, Canteen, during the Breake Ubiquity (anywhere, anytime) Higher voice quality Higher speed Lower prices Multitude of services http://www.nsma.org/conf2008/Presentation/2-1045-Miyahara-LTE_Overview_NMSA%2021March08_final.pdf

LTE The UMTS Long Term Evolution - Sesia, Toufik, Baker 3GPP The 3rd generation partnership project A global partnership of six SDOs: Europe ETSI USA ATIS China CCSA Japan ARIB & TTC Korea TTA LTE The UMTS Long Term Evolution - Sesia, Toufik, Baker

What is LTE?

What is LTE? The latest standard in the mobile network technology tree A project of 3GPP & mainly built on 3GPP cellular systems´ family May be referred as E-UTRA & E-UTRAN Has advanced new radio interface Circuit switched networksall-IP networks Broadband connectivity on the move 100Mbps(DL), 50Mbps(UL), ~10 ms Latency

UMTS and LTE architecture Extract from ”Towards Global Mobile Broadband” A White Paper from the UMTS Forum

LTE key features High Spectral Efficiency more customers, less costs Co-existence with other standards Flexible radio planning (cell size of 5km30/100km) Reduced Latency less RTT, multi-player gaming, audio/video conferencing Reduced costs for operators (OPEX & CAPEX) Increased data rates via enhanced air interface (OFDMA,SC-FDMA,MIMO) All-IP environment SAE or EPC key advantages of SAE

LTE-SAE Security: some highlights

Security in the LTE-SAE Network Security features in the network (from TS 33.401- Fig.4-1)

Security features in the LTE-SAE Network Five security feature groups defined in TS 33.401 (I): Network access security provides users with secure access to services protects against attacks on the access interface (II): Network domain security enables nodes to exchange signaling- & user- data securely protects against attacks on the wire line network (III): User domain security Provides secure access to mobile stations (IV): Application domain security enables applications in the user & provider domains to exchnage messages securely (V): Visibility and configurability of security allows the users to learn whether a security feature is in operation

Authentication & key agreement HSS generates authentication data and provides it to MME Challenge-response authentication and key agreement procedure between MME and UE 4th ETSI Security Workshop - Sophia-Antipolis , 13-14 January 2009

Confidentiality & integrity of signaling RRC signaling between UE and E-UTRAN NAS signaling between UE and MME S1 interface signaling protection is not UE-specific optional to use 4th ETSI Security Workshop - Sophia- Antipolis,13-14 January 2009

User plane confidentiality S1-U protection is not UE-specific (Enhanced) network domain security mechanisms (based on IPsec) Optional to use Integrity is not protected for various reasons, e.g.: performance limited protection for application layer 4th ETSI Security Workshop - Sophia- Antipolis, 13-14 January 2009

Cryptographic network separation Key hierarchy (TS 33.401 - Figure 6.2-1)

Cryptographic network separation Authentication vectors are specific to the serving network AV’s usable in UTRAN/GERAN cannot be used in EPS AV’s usable for UTRAN/GERAN access cannot be used for EUTRAN access Solution by a “separation bit” Rel-99 USIM is still sufficient for EPS access ME has to check the “separation bit” (when accessing E-UTRAN) 4th ETSI Security Workshop - Sophia-Antipolis , 13-14 January 2009

Key Handling in Handovers Model for the handover key chaining (TS 33.401 [1] Figure 7.2.8.1-1)

Home (e) Node B Security

System architecture of H(e)NB UE HNB SeGW insecure link Operator’s core network E-UTRAN air interface between UE and HeNB HeNB accesses operator’s core network via a Security Gateway The backhaul between HeNB and SeGW may be insecure Operator’s core network performs mutual authentication with HeNB via SeGW Security tunnel between HeNB and SeGW to protect information transmitted in backhaul link Figure from draft TR 33.820

Common threats to H(e)NB Physical tampering with H(e)NB Fraudulent software update / configuration changes Denial of service attacks against core network Eavesdropping of the other user’s UTRAN or E-UTRAN user data User cloning the H(e)NB authentication Token From TR 33.820

Security requirements to H(e)NB Unprotected data should never leave a secure domain inside H(e)NB Software updates and configuration changes for the H(e)NB shall be cryptographically signed (by operator or H(e)NB supplier) and verified configuration changes shall be authorized by H(e)NB operator or supplier Unauthenticated traffic shall be filtered out on the links between the core network and the H(e)NB New users should be required to explicitly confirm their acceptance before being joined to an H(e)NB H(e)NB authentication credentials shall be stored inside a secure domain i.e. from which outsider cannot retrieve or clone the credentials From TR 33.820

References and Resources

References and Resources A Long Term Evolution Downlink inspired channel simulator using the SUI 3Channel Model, Thesis of Sanjay Kumar Sarkar, August 2009 LTE The UMTS Long Term Evolution- Sesia, Toufik, Baker (WILEY Publication) 2009 http://www.nsma.org/conf2008/Presentation/2-1045-MiyaharaLTE_Overview_NMSA%2021March08_final.pdf Towards Global Mobile Broadband” A White Paper from the UMTS Forum, February 2008 TS 33.401

References and Resources 4th ETSI Security Workshop- Sophia-Antipolis , 13-14 January 2009 TR 33.820 A Survey of Security Threats on 4G Networks, Yongsuk Park and Taejoon Park Security in the LTE-SAE Network, www.agilent.com/find/lte www.3gpp.org www.radio-electronics.com http://sites.google.com/site/lteencyclopedia

Thank You For Your Attention!