HomeRapidalertWhat are the security settings of GSM mobile networks?

What are the security settings of GSM mobile networks?


GSMExtensive and long-term research by the Systems Security Laboratory of the University of Piraeus on GSM mobile telephony networks has shown that the security settings of the networks operating in Greece do not follow best practices, as defined by the operating specifications, resulting in subscribers being vulnerable to attacks to monitor their movements and communications.

For the needs of this research in GSM mobile networks, widely available hardware and software were used, with the cost of the equipment ranging below 100 euros. Specifically, the open source platform, Arduino, was used, together with the add-on GSM shield, thus achieving the creation of a mobile phone with enhanced functionality.

GSMFigure 1: The experimental GSM phone developed

The required know-how as well as the experimental setup were developed by postgraduate students of the "Digital Systems Security" direction of the Department of Digital Systems of the University of Piraeus. The experiments took place in the Athens area and for the three Greek mobile telephony companies. The study was carried out by postgraduate students: F. Lalagiannis, Gr. Valtas and N. Kapetanakis, under the guidance of Mr. Christos Xenakis, Assistant Professor of the University of Piraeus and Mr. Christopher Dantoyan, researcher and lecturer at the same institution.

The purpose of the experiments was to record and analyze key parameters contained in the smart SIM of the phones that took part in the experiments, such as encryption keys and temporary identities, in order to evaluate the level of security provided by telecommunications organizations in their networks.

Initially, the frequency with which encryption keys (Kc) to protect voice data during its transfer over the wireless channel was studied. Encryption keys need to be renewed as often as possible, even after each call, otherwise users are vulnerable to call interception and identity theft.

It was observed that (see Table 1) provider A renews the encryption keys every 16 phone calls, B every 6 calls, while C, on average, every 10 calls, since there does not seem to be any specific pattern followed in his case.

Table 1.Encryption key renewal frequency for each provider.

ProviderKc refresh rate
A16 voice calls
B6 voice calls
C10 voice calls (on average)

 

The existence of a pattern in the renewal of keys (providers A and B), facilitates the actions of malicious actors in launching attacks, because they know in advance the behavior of the network. Also, the current situation results in users who make or receive 2-3 calls per day, maintaining the same encryption key for days or even weeks, which exposes them to risk.

Next, we investigated how the temporary user identities (Temporary Mobile Subscriber Identity – TMSI), which are assigned by the network to each subscriber in order to maintain their anonymity, change. The temporary TMSI identities, ideally, should change at regular intervals. Otherwise, users can be easily identified by third parties, who are able to monitor their movements.

In the first phase, the periodicity with which the TMSI identities change for static users, who stay for a long time in the same coverage area (Location Area – LA). It was therefore observed that (see Table 2) providers A and B do not change the temporary TMSI identities of their users for as long as they remain in the same coverage area. On the contrary, provider C renews the temporary TMSI identities approximately every 240 minutes.

Table 2.Temporary TMSIs for users who remain in the same coverage area

Provider A TMSIProvider B TMSIProvider C TMSI
701590D9A8B32A7A23B9C7A8
701590D9A8B32A7A23BA25D0
701590D9A8B32A7A23BA82D0
701590D9A8B32A7A23BAE940
701590D9A8B32A7A23BB46B0
701590D9A8B32A7A23BBADE8
701590D9A8B32A7A23BC0A98
701590D9A8B32A7A23BC7448
701590D9A8B32A7A23BCD8B0
701590D9A8B32A7A23BD4298
701590D9A8B32A7A23BDB418
701590D9A8B32A7A23BE15D8
701590D9A8B32A7A23BE74B0
701590D9A8B32A7A23BED9C8

 

Next, the researchers wanted to see what happens to the temporary identities (TMSI) of users when they move and change coverage area (LA). The results of the study show that (see Table 3) providers A and C change the values ​​of the temporary identities (TMSI) for users who move from one area to another, following the recommended practice. In contrast, telecommunications provider B does not renew the identities, putting its subscribers at risk, who can be easily traced.

Table 3: Temporary TMSIs for users changing coverage area

ABC
LACTMSILACLACLACTMSI
004A4921B2CF390858B315A2002512A83908
001618242A1229CC58B315A2002014A9E4B8
00254823F122274458B315A2002115AF0E08

 

Finally, it is worth noting that telecommunications providers treat their subscribers with high network usage in exactly the same way as those with low network usage. It is very important to point out that in every activity they do with the network, users are identified by their temporary identity, which is exposed to multiple threats. Therefore, it is recommended to replace it based on its use and the degree of exposure.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS