Information security testing method and information security testing device

By implementing packet extraction unit and processing circuit in the information security testing equipment, obtaining the base station key and generating test packages, simulating the TEID and IP addresses of legitimate users, and testing the security mechanism of the central unit of the base station, solving the problems of low testing efficiency and insufficient security in the existing technology, and achieving efficient and accurate security testing.

JP2025070909AActive Publication Date: 2025-05-02INSTITUTE FOR INFORMATION INDUSTRY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2023191432
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-10-20
Filing Date
2023-11-09
Publication Date
2025-05-02
Estimated Expiration
2043-11-09

AI Technical Summary

Technical Problem

Existing information security testing methods cannot efficiently test the security mechanism of the base station central unit, especially in determining the security of tunnel endpoint identifiers (TEIDs) and IP addresses, and cannot effectively test the confidentiality and integrity protection functions of the central unit.

Method used

By implementing packet extraction unit and processing circuit in the information security test equipment, establish communication connections with user equipment, base stations and core networks, obtain base station keys and derive integrity keys and encryption keys, use these keys to generate test packets, simulate the TEID and IP addresses of legitimate users, and test whether the central unit has a security mechanism to check TEID and IP addresses.

Benefits of technology

It realizes efficient testing of the security mechanism of the central unit of the base station, can accurately determine whether the central unit has a mechanism to check TEID and IP addresses, and tests its confidentiality and integrity protection functions, improving testing efficiency and accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025070909000001_ABST
    Figure 2025070909000001_ABST
Patent Text Reader

Abstract

To disclose an information security testing method and an information security testing device.SOLUTION: The present invention discloses an information security testing method and an information security testing device that obtain at least an integrity key, at least one encryption key, a tunnel endpoint identifier, a first IP address of a user plane of a central unit, a second Internet Protocol address of a distribution unit, and a third Internet Protocol address of user equipment from signaling transmitted after the user equipment, a base station, and a core network establish a communication connection, and then generate a first test packet to be transmitted to the user plane of the central unit, and determine whether the central unit has a first security mechanism for inspecting the tunnel endpoint identifier, the third Internet Protocol address, or a first source Internet Protocol address.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates to an information security testing method and an information security testing device, and in particular to an information security testing method and an information security testing device for a central unit of a base station. [Background technology]

[0002] In the structure of an Open Radio Access Network (O-RAN), a base station may include a distribution unit and a central unit. In addition, an existing information security test method generates a random Tunnel End Identifier (TEID) and a random Internet Protocol (IP) address, and uses the random TEID and the random IP address to test whether the central unit of the base station has a security mechanism for checking the TEID and the IP address.

[0003] In this situation, the existing information security testing method has low testing efficiency, blindly tests attacks on the central unit of the base station, and cannot accurately determine whether the central unit has a security mechanism for inspecting the TEID or IP address, nor can it test the confidentiality and integrity protection function of the central unit. Summary of the Invention [Problem to be solved by the invention]

[0004] The technical problem to be solved by the present invention is to provide an information security testing method and an information security testing device to complement the deficiencies of existing technology, by obtaining a tunnel endpoint identifier and an IP address of a legitimate user, and using the obtained tunnel endpoint identifier and IP address to determine whether the central unit has a security mechanism for inspecting the tunnel endpoint identifier or IP address. [Means for solving the problem]

[0005] In order to solve the above technical problems, one embodiment of the present invention provides an information security testing method as follows. The information security testing method is executed by an information security testing device after a communication connection is established between a user equipment, a base station and a core network. The information security testing method includes: obtaining a base station key from a first signaling sent from the core network through a first interface to a base station including a distribution unit and a central unit including a control plane and a user plane, deriving at least one integrity key and at least one encryption key based on the base station key, and obtaining a General Packet Radio Service Tunneling Protocol (GPRS Tunneling Protocol) key from a second signaling sent from the control plane of the central unit through a second interface to the distribution unit. The method includes: acquiring a tunnel endpoint identifier (TEID) of a Global Time Protocol (GTP) and a first IP address of a user plane; acquiring a second IP address of the distribution unit from a third signaling sent from the distribution unit to a control plane of the central unit through a second interface; acquiring a third IP address of the user equipment from a fourth signaling sent from the control plane of the central unit to the distribution unit through the second interface; and performing a first security test process to determine whether the central unit has a first security mechanism for inspecting the tunnel endpoint identifier, the third IP address, or the first source IP address by generating a first test packet based on at least one integrity key, at least one encryption key, the tunnel endpoint identifier, the first IP address, the second IP address, and the third IP address and sending it to the user plane of the central unit through the third interface.

[0006] In order to solve the above technical problem, another technical solution adopted by the present invention is to provide an information security testing device. The information security testing device includes a packet extracting unit and a processing circuit. The packet extracting unit obtains a base station key from a first signaling sent from the core network through a first interface to a base station including a distribution unit and a central unit including a control plane and a user plane after a user equipment, a base station and a core network establish a communication connection, and derives at least one integrity key and at least one encryption key based on the base station key; and obtains a General Packet Radio Service Tunneling Protocol (GPRS Tunneling Protocol) from a second signaling sent from the control plane of the central unit through a second interface to the distribution unit. The control unit is configured to perform a first security test process to determine whether the central unit has a first security mechanism for checking the tunnel endpoint identifier, the third IP address, or the first source IP address by generating a first test packet based on the at least one integrity key, the at least one encryption key, the tunnel endpoint identifier, the first IP address, the second IP address, and the third IP address and sending the first test packet to the user plane of the central unit through the third interface.

[0007] In order to further understand the characteristics and technical contents of the present invention, please refer to the following detailed description and illustrations of the present invention. However, the illustrations provided are only for reference and explanation, and are not intended to limit the present invention. [Brief description of the drawings]

[0008] [Figure 1] 1 is a functional block diagram of an information security testing device according to an embodiment of the present invention; [Diagram 2] 1 is a flowchart of an information security testing method according to an embodiment of the present invention. [Diagram 3] FIG. 2 is a schematic diagram of a first test parameter acquisition process in which a packet extraction unit of the information security test device according to the embodiment of the present invention is set. [Figure 4] FIG. 2 is a schematic diagram illustrating a processing circuit of an information security testing device according to an embodiment of the present invention configured to execute a first security testing process. [Diagram 5] 4 is a flowchart of a first security testing process in the first embodiment of the present invention; [Figure 6] 11 is a flowchart of a first security testing process of the second embodiment of the present invention; [Figure 7] 13 is a flowchart of a first security testing process of the third embodiment of the present invention; [Figure 8] FIG. 11 is a schematic diagram illustrating a processing circuit of the information security testing device according to the embodiment of the present invention configured to execute a second security testing process. [Figure 9] 4 is a flowchart of a second security testing process in the first embodiment of the present invention. [Figure 10] 11 is a flowchart of a second security testing process in the second embodiment of the present invention; [Figure 11] 11 is a flowchart of an information security testing method according to a second embodiment of the present invention. [Figure 12] FIG. 11 is a schematic diagram of a second test parameter acquisition process in which a packet extraction unit of the information security test device according to the embodiment of the present invention is set. [Figure 13] FIG. 11 is a schematic diagram illustrating a processing circuit of the information security testing apparatus according to the embodiment of the present invention configured to execute a third security testing process. [Figure 14]11 is a flowchart of a third security testing process in the first embodiment of the present invention; [Figure 15] 11 is a flowchart of a third security testing process in the second embodiment of the present invention; [Figure 16] 13 is a flowchart of a third security testing process of the third embodiment of the present invention; DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0009] The following describes the embodiments disclosed by the present invention with specific examples. Those skilled in the art can understand the advantages and effects of the present invention from the disclosure of this specification. The present invention can be implemented or applied in other different embodiments. Each detail in this specification can be modified and changed equivalently based on various aspects or applications without departing from the spirit of the present invention. In addition, the drawings of the present invention are for simple and schematic illustration only and do not show actual dimensions. The following embodiments further describe technical matters related to the present invention, but the disclosed contents do not limit the present invention.

[0010] Please refer to Figures 1 and 2. Figure 1 is a functional block diagram of an information security testing device according to an embodiment of the present invention, and Figure 2 is a flow diagram of steps of an information security testing method according to an embodiment of the present invention. As shown in Figure 1, an information security testing device 10 of this embodiment can be coupled to a base station 14 and a core network 16, and includes a packet extraction unit 100 and a processing circuit 102.

[0011] The packet extractor 100 is a hardware device, such as a network access point (Test Access Points, TAPs), capable of capturing and analyzing a signal transmitted on an interface. However, the present invention does not limit the specific embodiment of the packet extractor 100. In addition, the processing circuit 102 is coupled to the packet extractor 100 and can be realized by cooperation of hardware (e.g., a central processor and a memory) and software and / or firmware, but the present invention does not limit the specific embodiment of the processing circuit 102.

[0012] In this embodiment, the base station 14 and the core network 16 can transmit signals through the first interface 21. And the base station 14 is a base station of the O-RAN architecture. Therefore, the base station 14 includes a distribution unit 140 and a central unit 142. And the central unit 142 includes a control plane 1420 and a user plane 1422. And the control plane 1420 of the distribution unit 140 and the central unit 142 can transmit signals through the second interface 22 (i.e., F1-C interface), and the user plane 1422 of the distribution unit 140 and the central unit 142 can transmit signals through the third interface 23 (i.e., F1-U interface). As shown in FIG. 2, the information security test method of this embodiment is performed after the information security test device 10 establishes a communication connection with the user equipment 12, the base station 14 and the core network 16, and includes the following steps:

[0013] Step S110: Obtain a base station key from a first signaling sent from a core network to a base station via a first interface, and derive at least one integrity key and at least one encryption key based on the base station key.

[0014] Step S120: Obtain the TEID of the GTP and the first IP address of the user plane from the second signaling sent from the control plane of the central unit through the second interface to the distribution unit.

[0015] Step S130: Obtain a second IP address of the distribution unit from a third signaling sent from the distribution unit to the control plane of the central unit through a second interface.

[0016] Step S140: Obtain a third IP address of the user equipment from a fourth signaling sent from the control plane of the central unit through the second interface to the distribution unit.

[0017] Step S150: Perform a first security testing process, which determines whether the central unit has a first security mechanism for inspecting the TEID, the third IP address, or the first source Internet Protocol address by generating a first test packet based on at least one integrity key, at least one encryption key, the TEID, the first IP address, the second IP address, and the third IP address, and sending it to the user plane of the central unit through the third interface.

[0018] For the convenience of the following description, the above steps S110 to S140 can be defined as a first test parameter acquisition process. The packet extraction unit 100 of the information security test device 10 is configured to execute the first test parameter acquisition process after the user equipment 12, the base station 14, and the core network 16 establish a communication connection. Please also refer to FIG. 3. FIG. 3 is a schematic diagram of a configuration in which the packet extraction unit of the information security test device of the embodiment of the present invention executes the first test parameter acquisition process. In addition, for signals transmitted on an interface, this embodiment displays them in order under the interface.

[0019] As shown in Fig. 3, in order to accommodate the base station 14 in the O-RAN architecture, the core network 16 includes an Access and Mobility Function (AMF) entity 160 and a User Plane Function (UPF) entity 162 (not depicted in Fig. 3). Thus, after a communication connection is established between the user equipment 12, the base station 14, and the core network 16, the packet extractor 100 extracts the base station key K from the first signaling M1 transmitted from the AMF entity 160 of the core network 16 to the control plane 1420 of the central unit 142 through the first interface 21, e.g., the N2 interface. gNB (This is not depicted in Figure 3 either.) Then, the base station key K gNB Based on this, the packet extractor 100 derives a first integrity key KR RCint , a second integrity key K UPint , the first encryption key K RRCenc , and a second encryption key K UPenc For example, the packet extraction unit 100 can derive the base station key K by using a key derivation function (KDF). gNB Based on the first integrity key K RRCint , a second integrity key K UPint , the first encryption key K RRCenc , and a second encryption key K UPenc can be derived.

[0020] In this embodiment, the first signaling M1 includes, for example, a base station key K gNB However, the present invention is not limited to this. gNB Based on the first integrity key K RRCint , a second integrity key K UPint , the first encryption key K RRCenc and a second encryption key K UPencThe technical means for deriving is already known to those skilled in the art, so details will not be described.

[0021] Next, the packet extraction unit 100 can obtain the TEID of GTP and the first IP address UP_IP of the user plane 1422 from the second signaling M2 transmitted from the control plane 1420 of the central unit 142 to the distribution unit 140 through the second interface 22 (i.e., the F1-C interface). Then, the packet extraction unit 100 can obtain the second IP address DU_IP of the distribution unit 140 from the third signaling M3 transmitted from the distribution unit 140 to the control plane 1420 of the central unit 142 through the second interface 22.

[0022] In this embodiment, the second signaling M2 is, for example, a UE Context Setup Request signaling whose contents include a TEID and a first IP address UP_IP. And the third signaling M3 is, for example, a UE Context Setup Response signaling whose contents include a second IP address DU_IP, but the present invention is not limited thereto. At this point, the user equipment 12, the base station 14, and the core network 16 have established a communication connection, so the TEID acquired by the packet extraction unit 100 is also referred to as the TEID of a legitimate user.

[0023] In addition, the packet extractor 100 can obtain the third IP address UE_IP of the user equipment 12 from the fourth signaling M4 sent from the control plane 1420 of the central unit 142 to the distribution unit 140 through the second interface 22. In addition, the first integrity key K obtained by the packet extractor 100 can be obtained from the fourth signaling M4. RRCint , a second integrity key K UPint , the first encryption key K RRCenc , the second encryption key K UPencIn response to the TEID, the first IP address UP_IP, the second IP address DU_IP, and the third IP address UE_IP, the processing circuit 102 is configured to perform a first security testing process.

[0024] In this embodiment, the fourth signaling M4 is a Session Establishment Accept signaling of a Protocol Data Unit (PDU) whose content includes the third IP address UE_IP, but the present invention is not limited thereto. Similarly, since the communication connection between the user equipment 12, the base station 14 and the core network 16 at this time has already been established, the third IP address UE_IP obtained by the packet extraction unit 100 is also called the legitimate user's IP address.

[0025] Therefore, compared with the existing technology, the information security testing method and information security testing device 10 of the present embodiment can obtain the TEID and IP address (i.e., the third IP address UE_IP) of the legitimate user. And, for the central unit 142, the second IP address DU_IP of the distribution unit 140 is also called the first source Internet Protocol address S1_IP (not shown). And the central unit 142 has a first security mechanism for checking the first source Internet Protocol address S1_IP.

[0026] Therefore, the processing circuit 102 can falsify the tunnel endpoint identifier (TEID), the third IP address UE_IP, or the second IP address DU_IP acquired by the packet extraction unit 100 to test whether the central unit 142 has a first security mechanism for inspecting the tunnel endpoint identifier (TEID), the third IP address UE_IP, or the first source Internet Protocol address S1_IP. For ease of explanation below, the tunnel endpoint identifier, the third IP address UE_IP, and the second IP address DU_IP acquired by the packet extraction unit 100 are defined as a plurality of first test parameters. Please also refer to FIG. 4. FIG. 4 is a schematic diagram showing a configuration when the processing circuit of the information security test device according to the embodiment of the present invention executes a first security test process.

[0027] As shown in FIG. 4, after tampering with one first test parameter, the processing circuit 102 generates a first integrity key K RRCint , a second integrity key K UPint , the first encryption key K RRCenc and a second encryption key K UPenc According to the first IP address UP_IP, the processing circuit 102 can generate a first test packet TP1 whose encryption and integrity are protected, and the content of the first test packet TP1 includes the first test parameter after tampering (hereinafter, referred to as the first target test parameter) and other untampered first test parameters. For example, the processing circuit 102 can use the encryption protection algorithm and the integrity protection algorithm to generate the first test packet TP1 whose encryption and integrity are protected based on the above key. Also, according to the first IP address UP_IP, the processing circuit 102 sends the first test packet TP1 to the user plane 1422 of the central unit 142 through the third interface 23 (i.e., the F1-U interface).

[0028] Next, the processing circuit 102 may determine whether the user plane 1422 of the central unit 142 has sent the first test packet TP1 through the fourth interface 24 (i.e., the N3 interface) to the UPF entity 162 of the core network 16. In response to determining that the user plane 1422 of the central unit 142 has not sent the first test packet TP1 through the fourth interface 24 to the UPF entity 162 of the core network 16, the processing circuit 102 may determine that the central unit 142 has a first security mechanism that checks a first target test parameter.

[0029] Specifically, the processing circuit 102 extracts and analyzes the signal transmitted on the fourth interface 24 through the packet extraction unit 100 to determine whether the user plane 1422 has sent the first test packet TP1 to the UPF entity 162 through the fourth interface 24. However, the present invention is not limited to a specific implementation manner in which the processing circuit 102 determines whether the user plane 1422 has sent the first test packet TP1 to the UPF entity 162 through the fourth interface 24.

[0030] Further, please refer to Fig. 5. Fig. 5 is a flowchart of the first security testing process of the first embodiment of the present invention. As shown in Fig. 5, if the processing circuit 102 chooses to tamper with the TEID (i.e., the TEID of a legitimate user) obtained from the packet extraction unit 100, the first security testing process of this embodiment includes the following steps:

[0031] Step S1511: The TEID is tampered with.

[0032] Step S1512: Generate a first test packet with encryption and integrity protection according to at least one integrity key and at least one encryption key, and the content of the first test packet includes a second IP address, a third IP address, and a tampered TEID.

[0033] Step S1513: Send a first test packet to the user plane of the central unit through the third interface based on the first IP address.

[0034] Step S1514: Determine whether the user plane of the central unit sends a first test packet to the UPF entity of the core network through the fourth interface. If so, the first security test process of this embodiment proceeds to step S1515. If not, the first security test process of this embodiment proceeds to step S1516.

[0035] Step S1515: Determine that the central unit does not have the first security mechanism for verifying the TEID.

[0036] Step S1516: Determine that the central unit has a first security mechanism for checking the TEID. The relevant details have been described above, so there is no need to repeat them here.

[0037] Meanwhile, please also refer to Fig. 6. Fig. 6 is a flow chart of the first security testing process of the second embodiment of the present invention. As shown in Fig. 6, if the processing circuit 102 chooses to tamper with the third IP address UE_IP (i.e., the IP address of a legitimate user) obtained from the packet extraction unit 100, the first security testing process of this embodiment includes the following steps:

[0038] Step S1521: The third IP address is tampered with.

[0039] Step S1522: Generate an encrypted and integrity protected first test packet based on at least one integrity key and at least one encryption key, where the content of the first test packet includes a second IP address, a TEID, and a tampered third IP address.

[0040] Step S1523: Send a first test packet to the user plane of the central unit through the third interface based on the first IP address.

[0041] Step S1524: Determine whether the user plane of the central unit sends a first test packet to the UPF entity of the core network through the fourth interface. If it is determined that the first test packet has been sent, the first security test process of this embodiment proceeds to step S1525. If it is determined that the first test packet has not been sent, the first security test process of this embodiment proceeds to step S1526.

[0042] Step S1525: The central unit determines that it does not have the first security mechanism for checking the third IP address.

[0043] Step S1526: The central unit determines that it has a first security mechanism for checking the third IP address. The relevant details are similar to those described above, and are not detailed again here.

[0044] Similarly, please refer to Fig. 7. Fig. 7 is a flow chart of the first security testing process of the third embodiment of the present invention. As shown in Fig. 7, when the processing circuit 102 chooses to tamper with the second IP address DU_IP (i.e., the first source Internet Protocol address S1_IP) obtained from the packet extraction unit 100, the first security testing process of this embodiment includes the following steps:

[0045] Step S1531: The second IP address is tampered with.

[0046] Step S1532: Generate a first test packet with encryption and integrity protection based on at least one integrity key and at least one encryption key, and the content of the first test packet includes the TEID, the third IP address and the second IP address after tampering.

[0047] Step S1533: Send a first test packet to a user plane of the central unit through a third interface based on the first IP address.

[0048] Step S1534: Determine whether the user plane of the central unit sends the first test packet to the UPF entity of the core network through the fourth interface. If it is determined that the first test packet has been sent, the first security test process of this embodiment proceeds to step S1535. If it is determined that the first test packet has not been sent, the first security test process of this embodiment proceeds to step S1536.

[0049] Step S1535: The central unit determines that it does not have the first security mechanism for checking the first source Internet Protocol address.

[0050] Step S1536: The central unit determines that it has a first security mechanism for checking the first source Internet Protocol address. The relevant details are similar to those described above, and will not be further detailed here.

[0051] As may be necessary, in another embodiment, the processing circuit 102 may rotate through the first security testing processes of Figures 5, 6 and 7 to determine whether the central unit 142 has a first security mechanism for checking the TEID, the third IP address UE_IP and the first source Internet Protocol address S1_IP.

[0052] Furthermore, as shown in FIG. 2, in order to test the confidentiality and integrity protection function of the central unit 142, the information security testing method of this embodiment may include the following steps.

[0053] Step S160: Perform a second security test process, which generates a second test packet based on the at least one integrity key, the at least one encryption key, the TEID, the first IP address, the second IP address and the third IP address, and sends it to the user plane of the central unit through the third interface to determine whether the central unit has a second security mechanism for performing encryption protection or integrity protection.

[0054] For convenience, the steps S110 to S160 can be abbreviated as step S10. Please refer to FIG. 8. FIG. 8 illustrates a configuration in which a processing circuit of an information security testing device according to an embodiment of the present invention performs a second security testing process. As shown in FIG. 8, the processing circuit 102 generates a first integrity key K RRCint , a second integrity key K UPint , the first encryption key K RRCenc , and a second encryption key K UPenc Based on the first IP address UP_IP, the processing circuit 102 can generate a second test packet TP2 encrypted and without integrity protection, or a second test packet TP2 without encryption and with integrity protection, and the content of the second test packet TP2 includes the second IP address DU_IP, the TEID, and the third IP address UE_IP. Based on the first IP address UP_IP, the processing circuit 102 can send the second test packet TP2 to the user plane 1422 of the central unit 142 through the third interface 23 (i.e., the F1-U interface).

[0055] Next, the processing circuit 102 can determine whether the user plane 1422 of the central unit 142 has sent the second test packet TP2 to the UPF entity 162 of the core network 16 through the fourth interface 24 (i.e., the N3 interface). If it is determined that the user plane 1422 of the central unit 142 has not sent the second test packet TP2 to the UPF entity 162 of the core network 16 through the fourth interface 24, the processing circuit 102 can determine that the central unit 142 has a second security mechanism for implementing encryption protection or integrity protection.

[0056] Further, referring to Fig. 9, Fig. 9 is a flowchart of steps of the second security test process of the first embodiment of the present invention. As shown in Fig. 9, in a situation where the processing circuit 102 generates a second test packet TP2 with encryption and without integrity protection, the second security test process of this embodiment includes the following steps:

[0057] Step S1611: Generate a second test packet with encryption and no integrity protection based on at least one integrity key and at least one encryption key, where the content of the second test packet includes a second IP address, a TEID, and a third IP address.

[0058] Step S1612: Send a second test packet to the user plane of the central unit through a third interface based on the first IP address.

[0059] Step S1613: Determine whether the user plane of the central unit sends a second test packet to the UPF entity of the core network through the fourth interface. If it is determined that the second test packet has been sent, the second security test process of this embodiment proceeds to step S1614. If it is determined that the second test packet has not been sent, the second security test process of this embodiment proceeds to step S1615.

[0060] Step S1614: Determine that the central unit does not have a second security mechanism for performing integrity protection.

[0061] Step S1615: Determine that the central unit has a second security mechanism for performing integrity protection.

[0062] Please also refer to Figure 10. Figure 10 is a flow chart of a second security test process of the second embodiment of the present invention. As shown in Figure 10, when the processing circuit 102 generates an unencrypted integrity-protected second test packet TP2, the second security test process of this embodiment includes the following steps:

[0063] Step S1621: Generate a second test packet based on at least one integrity key and at least one encryption key, where the second test packet is unencrypted and integrity protected, and includes a second IP address, a TEID, and a third IP address as content.

[0064] Step S1622: Send a second test packet to the user plane of the central unit through the third interface according to the first IP address.

[0065] Step S1623: judge whether the user plane of the central unit sends the second test packet to the UPF entity of the core network through the fourth interface. If it is judged that it is sent, the second security test process of this embodiment proceeds to step S1624. If it is judged that it is not sent, the second security test process of this embodiment proceeds to step S1625.

[0066] Step S1624: Determine that the central unit does not have the second security mechanism for implementing encryption protection.

[0067] Step S1625: Determine that the central unit has a second security mechanism for providing encryption protection.

[0068] Similarly, in other embodiments, the processing circuit 102 may rotate through the second security test processes of Figures 9 and 10 to determine whether the central unit 142 has a second security mechanism for providing encryption and integrity protection.

[0069] On the other hand, in addition to testing the central unit 142 of the base station 14, the information security testing device 10 of this embodiment can also perform information security testing on the UPF entity 162 of the core network 16. Therefore, please refer to Figure 11. Figure 11 is a flowchart of an information security testing method according to a second embodiment of the present invention, and the parts common to Figure 2 need not be described in detail again.

[0070] As shown in FIG. 11, compared with FIG. 2, the information security testing method of this embodiment can include the following steps:

[0071] Step S170: Obtain the TEID and the fourth IP address of the UPF entity of the core network through a fifth signaling sent from the core network to the base station through the first interface.

[0072] Step S180: Obtain a fifth IP address of the base station through a sixth signaling sent from the base station to the core network through the first interface.

[0073] Step S190: Generate a third test packet based on the TEID, the third IP address, the fourth IP address and the fifth IP address, and send it to the UPF entity of the core network through the fourth interface to perform a third security testing process to determine whether the UPF entity of the core network has a third security mechanism for inspecting the TEID, the third IP address or the second source IP address.

[0074] For ease of the following description, the above steps S170 to S180 can be defined as a second test parameter acquisition process, and the packet extraction unit 100 of the information security test device 10 is arranged to execute the second test parameter acquisition process. Please refer to Fig. 12. Fig. 12 is a diagram showing that the packet extraction unit of the information security test device of the embodiment of the present invention executes the second test parameter acquisition process.

[0075] 12, the packet extraction unit 100 acquires the TEID and the fourth IP address UPF_IP of the UPF entity 162 of the core network 16 from the fifth signaling M5 transmitted from the AMF entity 160 of the core network 16 through the first interface 21 (e.g., the N2 interface) to the base station 14. Also, the packet extraction unit 100 acquires the fifth IP address gNB_IP of the base station 14 from the sixth signaling M6 transmitted from the base station 14 through the first interface to the AMF entity 160 of the core network 16.

[0076] In this embodiment, the fifth signaling M5 is, for example, a PDU Session Resource Setup Request signaling including a TEID and a fourth IP address UPF_IP, and the sixth signaling M6 is, for example, a PDU Session Resource Setup Response signaling including a fifth IP address gNB_IP, but the present invention is not limited thereto. Furthermore, for the UPF entity 162 of the core network 16, the fifth IP address gNB_IP of the base station 14 is also called a second source IP address S2_IP (not shown), and the UPF entity 162 of the core network 16 can be equipped with a third security mechanism for checking the second source IP address S2_IP.

[0077] Therefore, the processing circuit 102 can test whether the UPF entity 162 of the core network 16 has a third security mechanism for checking the TEID, the third IP address UE_IP, or the second source IP address S2_IP by tampering with the TEID, the third IP address UE_IP, or the fifth IP address gNB_IP acquired by the packet extraction unit 100. For convenience of the following description, the TEID, the third IP address UE_IP, and the fifth IP address gNB_IP acquired by the packet extraction unit 100 can be defined as a plurality of second test parameters. Please also refer to FIG. 13. FIG. 13 is a diagram showing how the processing circuit of the information security test apparatus according to the embodiment of the present invention is configured to perform a third security test process.

[0078] 13, after tampering with one of the second test parameters, the processing circuit 102 can generate a third test packet TP3, and the content of the third test packet TP3 includes the tampered second test parameter (hereinafter referred to as the second target test parameter) and other untampered second test parameters. Furthermore, based on the fourth IP address UPF_IP, the processing circuit 102 can send the third test packet TP3 to the UPF entity 162 of the core network 16 through the fourth interface 24 (i.e., the N3 interface).

[0079] Next, processing circuit 102 may determine whether UPF entity 162 of core network 16 has sent third test packet TP3 to data network 18 through fifth interface 25 (i.e., N6 interface). In response to determining that UPF entity 162 of core network 16 has not sent third test packet TP3 to data network 18 through fifth interface 25, processing circuit 102 may determine that UPF entity 162 of core network 16 has a third security mechanism for inspecting the second target test parameter.

[0080] Specifically, processing circuit 102 can obtain and analyze the signal transmitted on fifth interface 25 through packet extractor 100 to determine whether UPF entity 162 has sent third test packet TP3 to data network 18 through fifth interface 25. However, the present invention is not limited to the specific embodiment in which processing circuit 102 determines whether UPF entity 162 has sent third test packet TP3 to data network 18 through fifth interface 25.

[0081] Further, please refer to Fig. 14. Fig. 14 is a flowchart of a third security testing process in the first embodiment of the present invention. As shown in Fig. 14, if the processing circuit 102 chooses to tamper with the TEID obtained from the packet extraction unit 100, the third security testing process of this embodiment can include the following steps.

[0082] Step S1911: The TEID is tampered with.

[0083] Step S1912: A third test packet is generated, and the content of the third test packet includes the third IP address, the fifth IP address, and the tampered TEID.

[0084] Step S1913: Send a third test packet to a UPF entity of the core network through a fourth interface based on a fourth IP address.

[0085] Step S1914: Determine whether the UPF entity of the core network sends the third test packet to the data network through the fifth interface. If it is determined that the third test packet has been sent, the third security test process of this embodiment proceeds to step S1915. If it is determined that the third test packet has not been sent, the third security test process of this embodiment proceeds to step S1916.

[0086] Step S1915: The UPF entity of the core network determines that it does not have a third security mechanism for checking the TEID.

[0087] Step S1916: Determine that the UPF entity of the core network has a third security mechanism for checking the TEID.

[0088] Also refer to Figure 15. Figure 15 is a flowchart of the third security testing process of the second embodiment of the present invention. As shown in Figure 15, if the processing circuit 102 chooses to tamper with the third IP address UE_IP obtained by the envelope extraction unit 100, the third security testing process of this embodiment can include the following steps.

[0089] Step S1921: The third IP address is tampered with.

[0090] Step S1922: Generate a third test packet, the content of which includes the fifth IP address, the TEID, and the tampered third IP address.

[0091] Step S1923: Send a third test packet to a UPF entity of the core network through a fourth interface based on the fourth IP address.

[0092] Step S1924: Determine whether the UPF entity of the core network has sent the third test packet to the data network through the fifth interface. If it has, the third security test process of this embodiment proceeds to step S1925. If it has not, the process proceeds to step S1926.

[0093] Step S1925: Determine that the UPF entity of the core network does not have a third security mechanism for checking the third IP address.

[0094] Step S1926: Determine that the UPF entity of the core network has a third security mechanism for checking the third IP address.

[0095] Also refer to Figure 16. Figure 16 is a step flow diagram of a third security testing process in the third embodiment of the present invention. As shown in Figure 15, when the processing circuit 102 selects tampering with the fifth IP address gNB_IP (i.e., the second source IP address S2_IP) acquired by the packet extraction unit 100, the third security testing process of this embodiment can include the following steps.

[0096] Step S1931: The fifth IP address is tampered with.

[0097] Step S1932: Generate a third test packet, where the content of the third test packet includes the TEID, the third IP address, and the tampered fifth IP address.

[0098] Step S1933: Send a third test packet to a UPF entity of the core network through a fourth interface based on the fourth IP address.

[0099] Step S1934: Determine whether the UPF entity of the core network has sent the third test packet to the data network through the fifth interface. If it is determined that the third test packet has been sent, the third security test process of this embodiment proceeds to step S1935. If it is determined that the third test packet has not been sent, the third security test process of this embodiment proceeds to step S1936.

[0100] Step S1935: Determine that the UPF entity of the core network does not have a third security mechanism for checking the second source IP address.

[0101] Step S1936: Determine that the UPF entity of the core network has a third security mechanism for checking the second source IP address.

[0102] Similarly, in another embodiment, the processing circuit 102 rotates through the third security testing processes of Figures 14, 15 and 16 to determine whether the UPF entity 162 of the core network 16 has a third security mechanism for checking the TEID, the third IP address UE_IP and the second source IP address S2_IP. The relevant details of Figures 14, 15 and 16 have been described above, and therefore will not be described in further detail here.

[0103] Meanwhile, the information security test method may also include only steps S140, S170, S180 and S190, and perform an information security test individually on the UPF entity 162. That is, in another embodiment, if only an information security test on the UPF entity 162 is required, the information security test device 10 may also perform only steps S140, S170, S180 and S190 after the user equipment 12, the base station 14 and the core network 16 establish a communication connection. The details are as described above, and will not be described here.

[0104] As described above, the present invention provides an information security test method and an information security test device, which extract and analyze signals transmitted on an interface to obtain the TEID and IP address of a legitimate user, and use the obtained TEID and IP address to test whether the central unit has a security mechanism for checking the TEID or IP address. Therefore, compared with the prior art, the information security test method and information security test device of the present invention can accelerate the test process and improve the test efficiency, and can accurately determine the security mechanism for checking the TEID or IP address of the central unit. In addition, the information security test method and information security test device of the present invention can also test the agility and integrity protection function of the central unit, and can also perform information security tests on the UPF entity of the core network, and can determine whether the UPF entity has a security mechanism for checking the TEID or IP address.

[0105] The contents disclosed above are merely preferred possible embodiments of the present invention, and do not limit the scope of the claims of the present invention. Therefore, all equivalent technical modifications made based on the contents of the specification and accompanying drawings of the present invention are intended to be included in the scope of the claims of the present invention. [Explanation of symbols]

[0106] 10. Security Test Equipment 100 Packet Extraction Unit 102 Processing circuit 12 User Equipment 14 Base station 140 Distribution Units 142 Central Unit 1420 Control Surface 1422 User Interface 16 Core Network 160 AMF Entities 162 UPF Entities 21,22,23,24 Interface M1,M2,M3,M4,M5,M6 signaling K RRCint ,K UPint Integrity Key K RRCenc ,K UPenc Encryption Key TEID Tunnel End Point Identifier UP_IP, DU_IP, UE_IP, UPF_IP, gNB_IP IP addresses TP1, TP2, TP3 test packets 18 Data Network S110~S190,S1511~S1516,S1521~S1526,S1531~S1536,S1611~S1615,S1621~S1625,S1811~S1816,S1821~S1826,S1831~S1836,S10 Step

Claims

1. An information security test method implemented by an information security test device after a communication connection is established between a user equipment (UE), a base station including a distribution unit (DU) and a central unit (CU) having a control plane and a user plane, and a core network, the method comprising: obtaining a base station key from first signaling transmitted from the core network over a first interface to the base station, and deriving at least one integrity key and at least one encryption key based on the base station key; Obtain a General Packet Radio Service Tunneling Protocol (GPRS Tunneling Protocol, GTP) Tunnel End Identifier (TEID) and a first Internet Protocol (IP) address of the user plane from a second signaling transmitted from the control plane of the CU to the DU through a second interface; Obtaining a second IP address of the DU from third signaling sent from the DU through the second interface to the control plane of the CU; Obtaining a third IP address of the UE from a fourth signaling transmitted from the control plane of the CU to the DU through the second interface; performing a first security testing process, which determines whether the CU has a first security mechanism for inspecting the TEID, the third IP address, or a first source IP address by generating and sending a first test packet to the user plane of the CU through a third interface based on the at least one integrity key, the at least one encryption key, the TEID, the first IP address, the second IP address, and the third IP address; 1. An information security testing method comprising:

2. The first security testing process includes: falsifying the TEID; and generating the first test packet, which is encrypted and integrity protected, including the second IP address, the third IP address, and the tampered TEID based on the at least one integrity key and the at least one encryption key; Sending the first test packet to the user plane of the CU through the third interface based on the first IP address; Determining whether the user plane of the CU has sent the first test packet to a User Plane Function (UPF) entity of the core network through a fourth interface; In response to determining that the user plane of the CU has sent the first test packet to the UPF entity of the core network through the fourth interface, determining that the CU has the first security mechanism for inspecting the TEID; 2. The information security testing method of claim 1, comprising:

3. The first security testing process includes: falsifying the third IP address; generating the first test packet, which is encrypted and integrity protected, based on the at least one integrity key and the at least one encryption key, the first test packet including the second IP address, the TEID, and the third IP address that has been tampered with; Sending the first test packet to the user plane of the CU through the third interface based on the first IP address; Determining whether the user plane of the CU has sent the first test packet to a UPF entity of the core network through the fourth interface; In response to determining that the user plane of the CU does not transmit the first test packet to the UPF entity of the core network through the fourth interface, determining that the CU has the first security mechanism for inspecting the third IP address of the UE; 2. The information security testing method of claim 1, comprising:

4. The first security testing process includes: falsifying the second IP address; generating the first test packet, which includes the TEID, the third IP address, and the tampered second IP address, and is encrypted and integrity protected based on the at least one integrity key and the at least one encryption key; Sending the first test packet to the user plane of the CU through the third interface based on the first IP address; Determining whether the user plane of the CU has sent the first test packet to a UPF entity of the core network through the fourth interface; In response to determining that the user plane of the CU is not sending the first test packet to the UPF entity of the core network through the fourth interface, determining that the CU has the first security mechanism that inspects the first source Internet Protocol address; 2. The information security testing method of claim 1, comprising:

5. 2. The information security testing method of claim 1, further comprising: performing a second security testing process to determine whether the CU has a second security mechanism for performing encryption or integrity protection by generating and sending a second test packet to a user plane of the CU through the third interface based on the at least one integrity key, the at least one encryption key, the TEID, the first IP address, the second IP address, and the third IP address.

6. The second security testing process includes: generating the second test packet with encryption and no integrity protection, the second test packet including the second IP address, the TEID, and the third IP address based on at least one integrity key and at least one encryption key; Sending the second test packet to the user plane of the CU through the third interface based on the first IP address; Determining whether the user plane of the CU has sent the second test packet to a UPF entity of the core network through a fourth interface; determining that the CU has the second security mechanism for performing integrity protection in response to determining that the user plane of the CU does not transmit the second test packet to the UPF entity of the core network through the fourth interface; 6. The information security testing method of claim 5, comprising:

7. The second security testing process includes: generating the second test packet, based on the at least one integrity key and the at least one encryption key, the second test packet including the second IP address, the TEID, and the third IP address, with no encryption and with integrity protection; Sending the second test packet to the user plane of the CU via the third interface based on the first IP address; Determining whether the user plane of the CU has sent the second test packet to a UPF entity of the core network through a fourth interface; In response to determining that the user plane of the CU is not transmitting the second test packet to the UPF entity of the core network through the fourth interface, determining that the CU has the second security mechanism for performing encryption protection; 6. The information security testing method of claim 5, comprising:

8. obtaining the TEID and a fourth IP address of a UPF entity of the core network from a fifth signaling sent from the core network to the base station through the first interface; obtaining a fifth IP address of the base station from sixth signaling sent from the base station to the core network through the first interface; performing a third security testing process, generating a third test packet based on the TEID, the third IP address, the fourth IP address, and the fifth IP address, and sending the third test packet to the UPF entity of the core network via the fourth interface, thereby determining whether the UPF entity of the core network has a third security mechanism for inspecting the TEID, the third IP address, or a second source IP address; 6. The information security testing method of claim 5, comprising:

9. The third security testing process includes: falsifying the TEID; and generating the third test packet including the third IP address, the fifth IP address, and the TEID after tampering; sending the third test packet to the UPF entity of the core network through the fourth interface based on the fourth IP address; determining whether the UPF entity of the core network has sent the third test packet to a data network through a fifth interface; determining that the UPF entity of the core network has the third security mechanism for checking the TEID in response to determining that the UPF entity of the core network has not sent the third test packet to the data network through the fifth interface; 9. The information security testing method of claim 8, comprising:

10. The third security testing process includes: falsifying the third IP address; and generating the third test packet, the third test packet including the fifth IP address, the TEID, and the third IP address that has been tampered with; sending the third test packet to the UPF entity of the core network through the fourth interface based on the fourth IP address; determining whether the UPF entity of the core network has sent the third test packet to a data network through the fifth interface; determining that the UPF entity of the core network has the third security mechanism for checking the third IP address in response to determining that the UPF entity of the core network has not sent the third test packet to the data network through the fifth interface; 9. The information security testing method of claim 8, comprising:

11. The third security testing process includes: falsifying the fifth IP address; and generating the third test packet including the TEID, the third IP address, and the fifth IP address that has been tampered with; sending the third test packet to the UPF entity of the core network through the fourth interface based on the fourth IP address; determining whether the UPF entity of the core network has sent the third test packet to a data network through the fifth interface; determining that the UPF entity of the core network has the third security mechanism for inspecting the second source Internet Protocol address in response to determining that the UPF entity of the core network has not transmitted the third test packet to the data network through the fifth interface; 9. The information security testing method of claim 8, comprising:

12. 1. An information security testing device comprising: a packet extractor; and a processing circuit coupled to the packet extractor, The packet extraction unit is configured to extract a packet from a user equipment (UE), a base station including a distribution unit (DU) and a central unit (CU) having a control plane and a user plane, and a core network after the base station establishes a communication connection with the core network. obtaining a base station key from first signaling sent from the core network over a first interface to the base station, and deriving at least one integrity key and at least one encryption key based on the base station key; Obtaining a General Packet Radio Service Tunneling Protocol (GPRS Tunneling Protocol, GTP) Tunnel End Identifier (TEID) and a first Internet Protocol (IP) address of the user plane from a second signaling sent from the control plane of the CU to the DU through a second interface; Obtaining a second IP address of the DU from third signaling sent from the DU through the second interface to the control plane of the CU; Obtaining a third IP address of the UE from a fourth signaling sent from the control plane of the CU to the DU through the second interface; Run The processing circuitry includes: performing a first security testing process, which determines whether the CU has a first security mechanism for inspecting the TEID, the third IP address, or a first source IP address by generating and sending a first test packet to the user plane of the CU through a third interface based on the at least one integrity key, the at least one encryption key, the TEID, the first IP address, the second IP address, and the third IP address; An information security testing device comprising:

13. The first security testing process includes: falsifying the TEID; and generating the first test packet, which is encrypted and integrity protected, including the second IP address, the third IP address, and the tampered TEID based on the at least one integrity key and the at least one encryption key; Sending the first test packet to the user plane of the CU through the third interface based on the first IP address; Determining whether the user plane of the CU has sent the first test packet to a User Plane Function (UPF) entity of the core network through a fourth interface; In response to determining that the user plane of the CU has sent the first test packet to the UPF entity of the core network through the fourth interface, determining that the CU has the first security mechanism for inspecting the TEID; 13. The information security testing device of claim 12, comprising:

14. The first security testing process includes: falsifying the third IP address; generating the first test packet, which is encrypted and integrity protected, based on the at least one integrity key and the at least one encryption key, the first test packet including the second IP address, the TEID, and the third IP address that has been tampered with; Sending the first test packet to the user plane of the CU through the third interface based on the first IP address; Determining whether the user plane of the CU has sent the first test packet to a UPF entity of the core network through the fourth interface; In response to determining that the user plane of the CU does not transmit the first test packet to the UPF entity of the core network through the fourth interface, determining that the CU has the first security mechanism for inspecting the third IP address of the UE; 13. The information security testing device of claim 12, comprising:

15. The first security testing process includes: falsifying the second IP address; generating the first test packet, which includes the TEID, the third IP address, and the tampered second IP address, and is encrypted and integrity protected based on the at least one integrity key and the at least one encryption key; Sending the first test packet to the user plane of the CU through the third interface based on the first IP address; Determining whether the user plane of the CU has sent the first test packet to a UPF entity of the core network through the fourth interface; In response to determining that the user plane of the CU is not sending the first test packet to the UPF entity of the core network through the fourth interface, determining that the CU has the first security mechanism that inspects the first source Internet Protocol address; 13. The information security testing device of claim 12, comprising:

16. The processing circuitry further comprises: The information security testing device of claim 12, further comprising: performing a second security testing process to determine whether the CU has a second security mechanism for performing encryption or integrity protection by generating and sending a second test packet to the user plane of the CU through the third interface based on the at least one integrity key, the at least one encryption key, the TEID, the first IP address, the second IP address, and the third IP address.

17. The second security testing process includes: generating the second test packet with encryption and no integrity protection, the second test packet including the second IP address, the TEID, and the third IP address based on at least one integrity key and at least one encryption key; Sending the second test packet to the user plane of the CU through the third interface based on the first IP address; Determining whether the user plane of the CU has sent the second test packet to a UPF entity of the core network through a fourth interface; determining that the CU has the second security mechanism for performing integrity protection in response to determining that the user plane of the CU does not transmit the second test packet to the UPF entity of the core network through the fourth interface; 17. The information security testing device of claim 16, comprising:

18. The second security testing process includes: generating the second test packet, based on the at least one integrity key and the at least one encryption key, the second test packet including the second IP address, the TEID, and the third IP address, with no encryption and with integrity protection; Sending the second test packet to the user plane of the CU via the third interface based on the first IP address; Determining whether the user plane of the CU has sent the second test packet to a UPF entity of the core network through a fourth interface; In response to determining that the user plane of the CU is not transmitting the second test packet to the UPF entity of the core network through the fourth interface, determining that the CU has the second security mechanism for performing encryption protection; 17. The information security testing device of claim 16, comprising:

19. The packet extraction unit further obtaining the TEID and a fourth IP address of a UPF entity of the core network from a fifth signaling sent from the core network to the base station through the first interface; obtaining a fifth IP address of the base station from sixth signaling sent from the base station to the core network through the first interface; Run The processing circuitry further comprises: performing a third security testing process, generating a third test packet based on the TEID, the third IP address, the fourth IP address, and the fifth IP address, and sending the third test packet to the UPF entity of the core network via the fourth interface, thereby determining whether the UPF entity of the core network has a third security mechanism for inspecting the TEID, the third IP address, or a second source IP address; 17. The information security testing device of claim 16, comprising:

20. The third security testing process includes: falsifying the TEID; and generating the third test packet including the third IP address, the fifth IP address, and the TEID after tampering; sending the third test packet to the UPF entity of the core network through the fourth interface based on the fourth IP address; determining whether the UPF entity of the core network has sent the third test packet to a data network through a fifth interface; determining that the UPF entity of the core network has the third security mechanism for checking the TEID in response to determining that the UPF entity of the core network has not sent the third test packet to the data network through the fifth interface; 20. The information security testing device of claim 19, comprising:

21. The third security testing process includes: falsifying the third IP address; and generating the third test packet, the third test packet including the fifth IP address, the TEID, and the third IP address that has been tampered with; sending the third test packet to the UPF entity of the core network through the fourth interface based on the fourth IP address; determining whether the UPF entity of the core network has sent the third test packet to a data network through the fifth interface; determining that the UPF entity of the core network has the third security mechanism for checking the third IP address in response to determining that the UPF entity of the core network has not sent the third test packet to the data network through the fifth interface; 20. The information security testing device of claim 19, comprising:

22. The third security testing process includes: falsifying the fifth IP address; and generating the third test packet including the TEID, the third IP address, and the fifth IP address that has been tampered with; sending the third test packet to the UPF entity of the core network through the fourth interface based on the fourth IP address; determining whether the UPF entity of the core network has sent the third test packet to a data network through the fifth interface; determining that the UPF entity of the core network has the third security mechanism for inspecting the second source Internet Protocol address in response to determining that the UPF entity of the core network has not transmitted the third test packet to the data network through the fifth interface; 20. The information security testing device of claim 19, comprising: