Method, system, and computer-readable medium for mitigating location tracking attacks and service disruption (DoS) attacks that utilize an access and mobility management function (AMF) location service
The method and system authenticate AMF location service requests using subscription identifiers and authentication results to prevent unauthorized access and DoS attacks in 5G networks, enhancing security against location tracking and service disruption.
Patent Information
- Application Number
- JP2023551730
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-02-25
- Filing Date
- 2022-01-21
- Publication Date
- 2025-07-10
- Estimated Expiration
- 2042-01-21
AI Technical Summary
In 5G communication networks, unauthorized entities can exploit the AMF location service to obtain location information without authorization, leading to location tracking attacks and denial-of-service (DoS) attacks, as there is no resource object-level authorization for the Namf_Location service.
A method and system that involve a network function (NF) receiving authentication responses, extracting subscription identifiers and authentication results, and using an AMF location service verification database to classify and prevent location tracking or DoS attacks by verifying the authenticity of AMF location service messages.
Effectively mitigates unauthorized access to user equipment location information and prevents DoS attacks by authenticating AMF location service requests, ensuring only authorized entities can access location data.
Smart Images

Figure 0007705947000004 
Figure 0007705947000005 
Figure 0007705947000006
Abstract
Description
Technical Field
[0001] Priority Claim This application claims the benefit of priority of U.S. Patent Application Serial No. 17 / 185,934, filed on February 25, 2021. The disclosure of the patent application is hereby incorporated by reference in its entirety.
[0002] Technical Field The subject matter described herein relates to network security. More specifically, the subject matter described herein relates to methods, systems, and computer-readable media for mitigating location tracking attacks and denial of service (DoS) attacks that utilize access and mobility management function (AMF) location services.
Background Art
[0003] Background In a 5G telecommunications network, network functions that provide services are called producer network functions (NFs), or NF service producers. Network functions that consume services are called consumer NFs, or NF service consumers. A network function can be a producer NF, a consumer NF, or both, depending on whether the network function is consuming, producing, or both consuming and producing a service. The terms "producer NF" and "NF service producer" are used interchangeably herein. Similarly, the terms "consumer NF" and "NF service consumer" are used interchangeably herein.
[0004] A given producer NF may have multiple service endpoints. A service endpoint is a contact point for one or more NF instances hosted by the producer NF. A service endpoint is a combination of an Internet protocol (IP) address and a port number or a fully qualified domain name (which can be decomposed into an IP address and a port number) on the network node hosting the producer NF. An NF instance is an instance of a producer NF that provides a service. A given producer NF may include two or more NF instances. Note that multiple NF instances can share the same service endpoint.
[0005] The producer NF registers with a network function repository function (NRF). The NRF maintains service profiles of available NF instances that identify the services supported by each NF instance. The terms "service profile" and "NF profile" are used interchangeably in this specification. A consumer NF can subscribe to receive information about producer NF instances registered with the NRF.
[0006] In addition to the consumer NF, another type of network node that can subscribe to receive information about NF service instances is a service communication proxy (SCP). The SCP subscribes to the NRF and obtains reachability and service profile information regarding producer NF service instances. The consumer NF connects to the service communication proxy, and the service communication proxy distributes traffic among producer NF service instances that provide the requested service or routes the traffic directly to the destination producer NF instance.
[0007] In addition to the SCP, other examples of intermediate proxy nodes or groups of network nodes that route traffic between the producer NF and the consumer NF include security edge protection proxies (SEPPs), service gateways, and nodes in a 5G service mesh. A SEPP is a network node used to protect control plane traffic exchanged between different 5G public land mobile networks (PLMNs). Therefore, the SEPP performs message filtering, policy-making, and topology hiding for all application programming interface (API) messages transmitted between PLMNs. Summary of the Invention Problems to be Solved by the Invention
[0008] One problem in 5G communication networks is that unauthorized entities may use the AMF location service to obtain location information about subscribers. 3GPP (registered trademark) TS 29.518 defines the Namf_Location service, which enables an NF to request or subscribe to receive geographical location information and positioning information of a target UE. The Namf_Location service is typically used by entities in the UE's home network, such as a gateway mobile location center (GMLC) and a user data management (UDM), to determine the current location of the UE. However, one problem with the Namf_Location service is that there is no resource object-level authorization for this service. Therefore, there is a risk that unauthorized entities, including those outside the UE's home network, may use the Namf_Location service to obtain the UE's location without authorization. Such unauthorized use of the Namf_Location service is referred to herein as a location tracking attack. Similarly, unauthorized entities outside the UE's home network may also use the Namf_Location service to overwhelm the AMF with unauthorized location service request messages. This type of attack is called a denial-of-service (DoS) attack.
[0009] Since it is not desirable to provide the UE's location without authorization, there is a need for methods, systems, and computer-readable media for mitigating location tracking attacks and DoS attacks that utilize the AMF location service. **Means for Solving the Problem**
[0010] Summary A method for mitigating location tracking attacks and DoS attacks using the AMF location service includes steps in a network function (NF) of receiving an authentication response message from a home public land mobile network (HPLMN) of a user equipment (UE). The method further includes steps of the NF extracting a subscription identifier for the UE and an indicator of an authentication result from the authentication response message. The method further includes steps of the NF storing the subscription identifier for the UE and the indicator of the authentication result in an AMF location service verification database. The method further includes steps of the NF receiving an AMF location service message. The method further includes steps of the NF using at least one of the subscription identifier extracted from the AMF location service message and the content of the AMF location service verification database to classify the AMF location service message as a location tracking attack or a DoS attack. The method further includes steps of preventing a location tracking attack or a DoS attack in response to classifying the AMF location service message as a location tracking attack.
[0011] According to another aspect of the subject matter described herein, the NF includes a security edge protection proxy (SEPP).
[0012] According to still another aspect of the subject matter described herein, the SEPP includes a visited SEPP of the UE.
[0013] According to still another aspect of the subject matter described herein, the step of receiving an authentication response message includes steps of receiving a Nausf_UEAuthentication message including an authentication result parameter and a subscription permanent identifier (SUPI).
[0014] According to yet another aspect of the subject matter described herein, the step of storing the subscription identifier and an indicator of the authentication result includes the step of storing the values of the SUPI and the authentication result parameters.
[0015] According to yet another aspect of the subject matter described herein, the step of using at least one of the subscription identifier extracted from the AMF location service message and the content of the AMF location service verification database to identify the AMF location service message as a location tracking attack or a DoS attack includes the steps of extracting the SUPI from the AMF location service message, determining that the source PLMN of the AMF location service message matches the home PLMN of the SUPI extracted from the AMF location service message, performing a lookup in the AMF location service verification database using the SUPI, and classifying the AMF location service message as a DoS attack in response to not being able to find a record corresponding to the SUPI in the AMF location service verification database, or in response to finding a record corresponding to the SUPI in the AMF location service verification database and determining that the record contains a value of an authentication result parameter indicating that the UE authentication was not successful.
[0016] According to yet another aspect of the subject matter described herein, the step of using at least one of the subscription identifier from the AMF location service message and the content of the AMF location service verification database to classify the AMF location service message as a location tracking attack or a DoS attack includes the steps of extracting the subscription permanent identifier (SUPI) from the AMF location service message, identifying the home PLMN from the SUPI, determining the source PLMN of the AMF location service message, and classifying the AMF location service message as a location tracking attack in response to determining that the home PLMN identified from the SUPI does not match the source PLMN of the AMF location service message.
[0017] According to another aspect of the subject matter described herein, the step of determining the source PLMN of the AMF location service message includes the step of determining the source PLMN from the source address of the AMF location service message or the source transport layer security (TLS) certificate.
[0018] According to yet another aspect of the subject matter described herein, the step of receiving the AMF location service message includes the step of receiving a Namf_Location service message.
[0019] According to yet another aspect of the subject matter described herein, the Namf_Location service message includes one of a ProvidePositioningInfo service operation identifier, an EventNotify service operation identifier, and a ProvideLocationInfo service operation identifier.
[0020] According to yet another aspect of the subject matter described herein, a system is provided for mitigating location tracking attacks and DoS attacks that utilize AMF location services. The system includes a network function (NF) that includes at least one processor and memory. The system further includes an AMF location service verification database embodied in the memory. The system further includes an authentication result collector realized by at least one processor to receive an authentication response message from a home public land mobile network (HPLMN) of a user equipment (UE), extract a subscription identifier for the UE and an indicator of an authentication result from the authentication response message, and store the subscription identifier for the UE and the indicator of the authentication result in the AMF location service verification database by the NF. The system further includes an AMF location service verifier realized by at least one processor to receive an AMF location service message, use at least one of a subscription identifier extracted from the AMF location service message and contents of the AMF location service verification database to classify the AMF location service message as a location tracking attack or a DoS attack, and prevent the location tracking attack or the DoS attack in response to classifying the AMF location service message as a location tracking attack.
[0021] According to yet another aspect of the subject matter described herein, when using at least one of a subscription identifier extracted from an AMF location service message and the content of an AMF location service verification database to identify an AMF location service message as a location tracking attack or a DoS attack, the AMF location service verifier extracts a SUPI from the AMF location service message, determines that the source PLMN of the AMF location service message matches the home PLMN of the SUPI extracted from the AMF location service message, performs a lookup in the AMF location service verification database using the SUPI, fails to find a record corresponding to the SUPI in the AMF location service verification database, or, in response to finding a record corresponding to the SUPI in the AMF location service verification database and determining that the record contains a value of an authentication result parameter indicating that the UE authentication was unsuccessful, the AMF location service message is configured to be classified as a DoS attack.
[0022] According to yet another aspect of the subject matter described herein, when using at least one of a subscription identifier from an AMF location service message and the content of an AMF location service verification database to classify an AMF location service message as a location tracking attack or a DoS attack, the AMF location service verifier extracts a subscription permanent identifier (SUPI) from the AMF location service message, identifies a home PLMN from the SUPI extracted from the AMF location service message, determines the source PLMN of the AMF location service message, and in response to determining that the home PLMN identified from the SUPI does not match the source PLMN of the AMF location service message, the AMF location service message is configured to be classified as a location tracking attack.
[0023] According to another aspect of the subject matter described herein, the AMF location service verifier is configured to determine the source PLMN of an AMF location service message by determining the source PLMN from the source address of the AMF location service message or the source transport layer security (TLS) certificate.
[0024] According to yet another aspect of the subject matter described herein, there is provided a non-transitory computer-readable medium storing executable instructions that, when executed by a processor of a computer, control the computer to perform a plurality of steps. The plurality of steps include receiving, by a network function (NF), an authentication response message from a home public land mobile network (HPLMN) of a user equipment (UE). The plurality of steps further include the NF extracting a subscription identifier for the UE and an indicator of an authentication result from the authentication response message. The plurality of steps further include the NF storing the subscription identifier for the UE and the indicator of the authentication result in an AMF location service verification database. The plurality of steps further include the NF receiving an AMF location service message. The plurality of steps further include the NF using at least one of a subscription identifier extracted from the AMF location service message and the contents of the AMF location service verification database to classify the AMF location service message as a location tracking attack. The plurality of steps further include preventing a location tracking attack in response to classifying the AMF location service message as a location tracking attack.
[0025] The subject matter described herein can be implemented in software combined with hardware and / or firmware. For example, the subject matter described herein can be implemented in software executed by a processor. In an exemplary implementation, the subject matter described herein can be realized using a non-transitory computer-readable medium storing computer-executable instructions that control a computer to perform a plurality of steps when executed by a processor of the computer. Exemplary computer-readable media suitable for realizing the subject matter described herein include non-transitory computer-readable media such as disk memory devices, chip memory devices, programmable logic devices, and application specific integrated circuits. Additionally, the computer-readable media for realizing the subject matter described herein may be located on a single device or computing platform, or may be distributed among multiple devices or computing platforms.
Brief Description of Drawings
[0026]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Mode for Carrying Out the Invention
[0027] Detailed Description FIG. 1 is a block diagram showing an exemplary 5G system network architecture. The architecture of FIG. 1 includes an NRF100 and an SCP101 that may be located in the same home public land mobile network (HPLMN). As described above, the NRF100 maintains profiles of available producer NF service instances and the services they support, and enables a consumer NF or SCP to subscribe to a new / updated producer NF service instance and be notified of its registration. The SCP101 may also support service discovery and selection of producer NF instances. The SCP101 may perform load balancing of connections between a consumer NF and a producer NF.
[0028] The NRF100 is a repository for the NF profile or service profile of a producer NF instance. To communicate with a producer NF instance, a consumer NF or SCP must obtain the NF profile or service profile of the producer NF instance from the NRF100. The NF profile or service profile is a JavaScript (registered trademark) Object Notation (JSON) data structure defined in the Technical Specification (TS) 29.510 of the Third Generation Partnership Project (3GPP). The definition of the NF profile or service profile includes at least one of a fully qualified domain name (FQDN), an Internet Protocol (IP) version 4 (IPv4) address, or an IP version 6 (IPv6) address.
[0029] In Figure 1, any of the network functions can be a consumer NF, a producer NF, or both, depending on whether they are requesting a service, providing a service, or both. In the example shown, the NFs include a PCF 102 that performs policy-related operations in the network, a UDM function 104 that manages user data, and an application function (AF) 106 that provides application services.
[0030] The NF shown in FIG. 1 further includes a session management function (SMF) 108 that manages sessions between the access and mobility management function (AMF) 110 and the PCF 102. The AMF 110 performs mobility management operations similar to those performed by the mobility management entity (MME) in the 4G network. The authentication server function (AUSF) 112 provides an authentication service for user equipment (UE) such as the UE 114 seeking access to the network.
[0031] The network slice selection function (NSSF) 116 provides a network slicing service for devices attempting to access specific network capabilities and characteristics associated with a network slice. The network exposure function (NEF) 118 provides an application programming interface (API) for application functions attempting to obtain information about Internet of things (IoT) devices and other UEs connected to the network. The NEF 118 performs a function similar to the service capability exposure function (SCEF) in the 4G network.
[0032] A radio access network (RAN) 120 connects a user equipment (UE) 114 to a network via a wireless link. The radio access network 120 can be accessed using a g-node B (gNB) (not shown in FIG. 1) or other radio access points. A user plane function (UPF) 122 can support various proxy functionalities for user plane services. An example of such proxy functionality is multipath transmission control protocol (MPTCP) proxy functionality. UPF 122 can also support performance measurement functionality, which can be used by UE 114 to obtain network performance measurements. A data network (DN) 124 is also shown in FIG. 1, through which the UE accesses data network services such as Internet services.
[0033] SEPP 126 filters incoming traffic from another PLMN and performs topology concealment for traffic going out of the home PLMN. SEPP 126 can communicate with SEPPs in the external PLMN that manage security for the external PLMN. For this reason, traffic between NFs in different PLMNs can cross two SEPP functions, namely, the SEPP function for the home PLMN and the SEPP function for the external PLMN.
[0034] As described above, one issue in the 3GPP network architecture for 5G communication networks is that the Namf_Location service defined in 3GPP TS 29.518 does not require resource object-level authorization before providing location information about the UE. Table 1 shown below shows various types of messages that can be used in the Namf_Location service to obtain location information about the UE or to initiate a service disruption attack on the AMF.
[0035]
Table 1
[0036] In Table 1, the Namf_Location service includes a positioning information providing service operation, an event notification service operation, a location information providing service operation, and a location cancellation (CancelLocation) service operation. The positioning information providing service operation is used by an NF service consumer such as a Gateway Mobile Location Center (GMLC) to request the current or deferred geodetic and optional civic location of a UE. This operation triggers the AMF to call a service for the location management function (LMF). The event notification service operation notifies the NF service consumer about UE location-related event information related to a security session or a deferred location, i.e., the start, handover, or end of an emergency session, or the completion or activation of a deferred location. The location information providing service operation enables an NF service consumer such as the UDM to request the network provided location information (NPLI) of a target UE. The location cancellation service operation is called by an NF service consumer such as the GMLC to cancel reporting a location triggered by a periodic location or an event.
[0037] All of the service operations shown in Table 1 are triggered by requesting or subscribing to messages from the AMF that is currently providing services to the UE. Figure 2 shows an example of the messages exchanged in the positioning information providing service. Referring to Figure 2, at line 1, the NF service consumer 200 invokes the positioning information providing service by sending an HTTP Post message to the AMF 110. The HTTP Post message contains the positioning information providing URI, which identifies the positioning information providing service operation. The HTTP Post message also includes the individual UE context. The individual UE context includes a UE context ID, which identifies the UE. In one example, the individual UE context may be composed of or created from the UE's Subscription Permanent Identifier (SUPI), which is a global identifier for the UE in the network.
[0038] In response to the post message including the positioning information providing service operation, the AMF 110 may respond as shown in step 2A where the AMF 110 provides the requested UE positioning information, step 2B where the AMF 110 indicates that there is no content for the UE, or step 2C where the AMF 110 indicates that there was a problem when invoking the requested service operation.
[0039] Note that there is no authentication of the NF service consumer 200 as part of the Namf positioning information providing service operation. Similar messages may be exchanged for the other Namf_Location service operations listed in Table 1 above, but none of them have a defined authentication mechanism.
[0040] Figure 3 shows an example of the output from the positioning information providing service operation and the location information providing service operation. As shown in Figure 3, both service operations can output the geographical location or coordinates of the UE. Both service operations can also output the age of the location, which indicates the age or time when a particular UE location was reported. The output of the positioning information providing service operation also includes an estimated speed value, which can suggest how fast the UE is moving. Since the output of both these service operations can be used to accurately identify the UE's location and the time the UE has been at a particular location, it is desirable to prevent unauthorized access to this information. Also, it is desirable to prevent any of the messages in Table 1 from being used to implement a DoS attack against the AMF.
[0041] Figure 4 is a message flow diagram showing exemplary messages exchanged for legitimate access to the Namf_Location service and for location tracking attacks or DoS attacks. Referring to Figure 4, the consumer NF200 and the home SEPP126A are components of the UE's home network. The visited SEPP126B and the AMF110 are components of the visited network where the UE is currently roaming. The attacker 400 is located outside both the home network and the visited network. However, the subject matter described herein can also detect location tracking attacks from within the UE's home network and visited network.
[0042] In line 1 of the message flow shown in Figure 4, the consumer NF200 sends a Namf_Location request message to the H-SEPP126A. In line 2, the H-SEPP126A forwards the Namf_Location service request to the V-SEPP126B located in the visited network. In line 3, the V-SEPP126B forwards the Namf_Location service request to the AMF110.
[0043] At line 4, AMF110 sends a Namf_Location service response to V-SEPP126B. The Namf_Location service response contains the requested location information of the UE. At line 5, V-SEPP126B sends the Namf_Location service response to H-SEPP126A. At line 6, H-SEPP126A transfers the location service response to the consumer NF200, which is the node that requested the data.
[0044] Lines 1 to 6 show the legitimate use of the Namf_Location service by the consumer NF200 located in the home network of the UE. However, at line 7, a consumer NF400, controlled by an attacker and masquerading as a legitimate service user, sends a Namf_Location service request message to V-SEPP126B. At line 8, V-SEPP126B transfers the Namf_Location service request to AMF110. Without performing authentication of the request, at line 9, AMF110 responds with the requested UE location data in a Namf_Location service response message.
[0045] At line 10, V-SEPP126B transfers the Namf_Location service response to the consumer NF400. Since the consumer NF400 has access to the location information regarding the subscriber, the consumer NF400 may report this location to the criminal, and the criminal may use the location information for illegal purposes. In addition, the consumer NF may initiate multiple unauthorized Namf_Location service request messages to AMF110 in order to overwhelm the resources of AMF110 with a DoS attack.
[0046] To mitigate or prevent location tracking attacks such as those shown in Figure 4, and DoS attacks that utilize the Namf Location Service, network functions such as SEPP store subscription identification information and authentication obtained from the UE authentication request from the AUSF, and use the subscription identification information and authentication result information to verify AMF location service messages regarding the UE.
[0047] Figure 5 is a message flow diagram showing exemplary messages exchanged and steps performed by the visited SEPP when obtaining and storing UE subscription identification information and authentication result information from the Nausf authentication procedure. Referring to Figure 5, when the UE registers with the AMF, the AMF sends a Nausf_UEAuthentication_Authenticate request message to the UE's home network, as shown by line 1 of the message flow diagram. The Nausf_UEAuthentication_Authenticate request message includes an encrypted subscription identifier (subscription concealed identifier: SUCI) and an identifier for the service providing network in which the UE is currently located. At line 2 of the message flow diagram, V-SEPP126B forwards the Nausf_UEAuthentication_Authenticate request message to H-SEPP126A. At line 3 of the message flow diagram, H-SEPP126A forwards the Nausf_UEAuthentication message to AUSF112.
[0048] In line 4 of the message flow diagram, AUSF 112 receives the Nausf_UEAuthentication_Authenticate request, determines whether the source AMF in the service providing network is authorized to use the service providing network name in the Nausf_UEAuthentication_Authenticate request, and sends a Nudm_UEAuthentication_Get request message to UDM 104. The Nudm_UEAuthentication_Get request message includes the SUCI and the service providing network name.
[0049] Upon receiving the Nudm_UEAuthentication_Get request, UDM 104 decrypts the SUCI to determine the SUPI. Based on the SUPI, UDM 104 selects an authentication method. In line 5 of the message flow diagram, UDM 104 sends a Nudm_UEAuthentication_Get response message to AUSF 112. The Nudm_UEAuthentication_Get response message includes an authentication vector (AV) containing authentication challenge information according to the selected authentication method. The Nudm_UEAuthentication_Get response message also includes the SUPI. In line 6 of the message flow diagram, AUSF 112 generates a Nausf_UEAuthentication_Authenticate response message containing the authentication vector and the authentication context ID and sends it to H-SEPP 126A. In line 7 of the message flow diagram, H-SEPP 126A forwards the Nausf_UEAuthentication_Authenticate response to V-SEPP 126B. In line 8, V-SEPP 126B forwards the Nausf_UEAuthentication_Authenticate response to AMF 110.
[0050] The AMF 110 receives an Nausf_UEAuthentication_Authenticate response message containing an authentication vector, and sends an authentication request message to the UE together with the authentication vector containing authentication challenge information. The UE calculates an authentication response based on the authentication challenge information. In a certain type of authentication, the authentication response is the Res* value calculated by the UE using a secure hash algorithm. The UE communicates the Res* value to the AMF 110 in the authentication response message. At line 9, the AMF 110 transfers the Res* value to the V-SEPP 126B in the Nausf_UEAuthentication_Authenticate request message. At line 10, the V-SEPP 126B transfers the Nausf_UEAuthentication_Authenticate request message to the H-SEPP 126A. At line 11, the H-SEPP 126A transfers the Nausf_UEAuthentication_Authenticate request to the AUSF 112. At line 12, the AUSF 112 formulates a Nudm_UEAuthentication request message and sends it to the UDM 104. At line 13, the UDM 104 authenticates the UE based on the Res* value and responds to the Nudm_UEAuthentication request message by sending a Nudm_UEAuthentication response message containing the authentication result parameter and the UE's SUPI. The value of the authentication result parameter indicates whether the UE's authentication was successful. At line 14, the AUSF 112 responds to the Nudm_UEAuthentication response by generating a Nausf_UEAuthentication response containing the authentication result and the SUPI and sending it to the H-SEPP 126A. At line 15, the H-SEPP 126A transfers the Nausf_UEAuthentication response to the V-SEPP 126B.
[0051] Instead of simply forwarding the Nausf_UEAuthentication response message to the AMF 110, the V-SEPP 126B extracts the value of the authentication result parameter and the SUPI from the Nausf_UEAuthentication response, and stores the SUPI and the value of the authentication result parameter in the AMF location service verification database. At line 17, the V-SEPP 126B forwards the Nausf_UEAuthentication response message to the AMF 110.
[0052] Once the V-SEPP 126B stores the SUPI and the authentication result, this data can be used to verify future AMF location service requests and subscribe messages. Figure 6 is a message flow diagram showing the use of the stored UE subscription identification information and authentication result information for verifying AMF location service messages and for preventing location tracking attacks or DoS attacks that utilize AMF location service messages. Referring to Figure 6, at line 1, the consumer NF 200 located in the home PLMN sends an AMF location service request message to the H-SEPP 126A. At line 2, the H-SEPP 126A forwards the AMF location service request to the V-SEPP 126B. Instead of simply forwarding the AMF location service request message to the AMF 110, at step 3, the V-SEPP 126B collates the source PLMN in the AMF location service request with the SUPI, checks the authentication result stored for the SUPI, and determines whether the UE is authenticated. Table 2 shown below shows examples of UE content text identification information that may be included in the AMF location service request message.
[0053]
Table 2
[0054] Table 2 is a copy of Table 6.4.3.2.2-1 of 3GPP TS 29.518, which identifies the resource URI variables for the UE context ID carried in the Location Service Request message. As shown in Table 2, the UE context ID includes either the SUPI or the permanent device identifier. The pattern for the SUPI is defined in 3GPP TS 23.501. In this example, it is assumed that the SUPI is present in the AMF Location Service Request message. Section 5.9.2 of 3GPP TS 23.501 states the following regarding the SUPI: "The Global Unique 5G Subscription Permanent Identifier (SUPI) shall be assigned to each subscriber in the 5G system and provisioned in the UDM / UDR. The SUPI shall be used only within the 3GPP system and its privacy shall be specified in TS 33.501
[29] .
[0055] The SUPI may include the following: - An IMSI as defined in TS 23.003
[19] ; or - A network-specific identifier used for private networks as defined in TS 22.261 [2]. - The operator identifier and GLI of the 5GC operator used to support FN-BRG, as further described in TS 23.316
[84] . - The operator identifier and GCI of the 5GC operator used to support FN-CRG and 5G-CRG, as further described in TS 23.316
[84] .
[0056] The SUPI containing the network-specific identifier shall take the form of a Network Access Identifier (NAI) using the NAI RFC 7542
[20] based user ID as defined in TS 23.003
[19] .
[0057] If the UE needs to indicate its SUPI to the network (e.g., as part of the registration procedure), the UE provides the SUPI in encrypted form as defined in TS 23.003
[19] .
[0058] To enable the roaming scenario, the SUPI shall include the address of the home network (e.g., the MCC and MNC in the case of an IMSI-based SUPI).
[0059] To interact with the EPC, the SUPI assigned to a 3GPP UE shall always be IMSI-based to enable the UE to present the IMSI to the EPC.
[0060] As described above in the text from 3GPP TS 23.501, the SUPI includes a global unique identifier for the UE and may also include the address of the home network or the HPLMN. For this reason, the verification of the AMF location service request message in step 3 of Figure 6 can be performed as follows: 1. Extract the SUPI from the AMF location service message; 2. Determine whether the source PLMN of the AMF location service message matches the home PLMN specified in the SUPI of the AMF location service message. As shown in the above excerpt from 3GPP TS 23.501, the SUPI includes the address of the home network, which can take the form of a mobile network code (MNC) and a mobile country code (MCC). These parameters can be compared with the MNC and MCC of the source PLMN of the AMF location service message. The source PLMN of the AMF location service message can be identified from the source TLS certificate or source address of the message (e.g., source IP address or source domain). The AMF location service verification database may include a table that maps the source IP address or domain to the MNC and MCC of a known network. For this reason, the source address extracted from the message may be used to identify the MNC and MCC of the source network, and these parameters may be compared with the MNC and MCC extracted from the SUPI. When the source PLMN from the TLS certificate is used, the source PLMN from the TLS certificate obtained from the AMF location service message may be compared with the MNC, MCC, or other parameters that identify the home network included in or derived from the SUPI; 3. If the source PLMN in the AMF location service message does not match the home PLMN in the SUPI of the AMF location service message, the verification fails; 4. If the source PLMN in the AMF location service message matches the home PLMN in the SUPI of the AMF location service message, perform a lookup for the SUPI in the AMF location service verification database; 5. If the SUPI from the AMF location service message does not exist in the AMF location service verification database, the verification fails; 6. If the SUPI from the AMF Location Service message exists in the AMF Location Service verification database, check the authentication result in the matching database record; 7. If the authentication result in the database record indicates that the UE was not authenticated, the verification fails; 8. If the authentication result in the database record indicates that the UE was authenticated, the verification passes.
[0061] Table 3 shown below shows exemplary records that may exist in the AMF Location Service verification database after storing the authentication results and SUPI information obtained from the Nausf authentication procedure shown in Figure 5.
[0062]
Table 3
[0063] In Table 3, the database record contains SUPI1, which was obtained from the UDM in the subscriber's HPLMN using the procedure of Figure 5. The authentication result of "Authenticated" indicates that the UE's authentication was successful.
[0064] Continuing with the message flow in Figure 6, in the example at step 3, the AMF Location Service request is verified using the steps described above. Thus, at line 4, V-SEPP126B transfers the AMF Location Service request to AMF110. At line 5, AMF110 generates an AMF Location Service response message containing the requested UE location information and sends it to V-SEPP126B. At line 6, V-SEPP126B transfers the AMF Location Service response to H-SEPP126A. At line 7, H-SEPP126A transfers the AMF Location Service response to consumer NF200.
[0065] At line 8 of the message flow shown in FIG. 6, in this example, a consumer NF400, which is a hacker or attacker, sends an AMF location service request to a V-SEPP126B, which is an SEPP for the visited network where the UE is currently roaming. The V-SEPP126B classifies the AMF location service request as a location tracking attack or a DoS attack using the steps described above. Repeating, the AMF location service request is classified as a location tracking attack if the source PLMN of the message does not match the home PLMN in the SUPI and the SUPI does not exist in the AMF location service verification database, or can be classified as a DoS attack if the SUPI exists in the AMF location service verification database and the authentication result stored for the SUPI indicates that the UE authentication has failed. In this case, the V-SEPP126B may prevent the AMF location service request from being transferred to the AMF110, discard the location service request, and optionally, generate a record of the location service request for transmission to the network operator. For this purpose, the SUPI and the authentication result stored during the Namf authentication procedure triggered by the UE registration at the AMF using the steps of FIG. 6 are used to (at step 3) verify the AMF location service request and (at line 8) reject the AMF location service request from the attacker.
[0066] FIG. 7 is a block diagram showing an exemplary architecture for an SEPP that can verify an AMF location service message using the methodology described herein. Referring to FIG. 7, the SEPP that implements the subject matter described herein may be a visited SEPP of a UE whose location information or positioning information is protected. In the example above, for a roaming subscriber registered with the AMF in the VPLMN, the AMF location service verification is performed by the V-SEPP126B.
[0067] In the exemplary architecture shown in FIG. 7, SEPP126B includes at least one processor 700 and a memory 702. SEPP126B includes an AMF location service verification database 704 that stores the SUPI and authentication result information obtained from the Nausf authentication procedure described above. The home or visited SEPP126B further includes a UE authentication result collector 706 for performing the steps described above with respect to FIG. 5 to obtain UE authentication information and SUPI information and store this information in the database 704. SEPP126A further includes an AMF location service verifier 708 for verifying or rejecting an AMF location service message using the SUPI and authentication result information stored in the database 704. In one exemplary implementation, the UE authentication result collector 706 and the AMF location service verifier 708 may be implemented in the memory 702 and using computer-executable instructions executable by the processor 700.
[0068] FIG. 8 is a flowchart showing an exemplary process for mitigating location tracking attacks and DoS attacks. Referring to FIG. 8, at step 800, the process includes a network function receiving an authentication response message from the UE's home public land mobile network. For example, as shown by line 14 of FIG. 5, a SEPP such as visited SEPP126B may receive a Nausf_UEAuthentication response message.
[0069] At step 802, the process includes the NF extracting a subscription identifier for the UE and an indicator of the authentication result from the authentication response message. For example, visited SEPP126B may extract the value of the SUPI and authentication result parameters from the Nausf_UEAuthentication response message.
[0070] In step 804, the process includes the NF storing the subscription identifier and the authentication result in the AMF Location Service Verification Database. For example, the visited SEPP 126B may store the values of the SUPI and the authentication result parameter extracted from the Nausf_UEAuthentication response message in the AMF Location Service Verification Database.
[0071] In step 806, the process includes the NF receiving an AMF Location Service message. For example, the visited SEPP 126B may receive an AMF Location Service message. Here, the AMF Location Service message is any of the message types shown in Table 1 that requests or subscribes to the reception of location information or positioning information regarding the UE. Examples of such messages may include messages carrying a positioning information provision service operation identifier, a location information provision service operation identifier, or an event notification service operation identifier.
[0072] In step 808, the process includes using at least one of the subscription identifier from the AMF Location Service message and the content of the AMF Location Service Verification Database to classify the AMF Location Service message as a location tracking attack or a DoS attack. For example, the visited SEPP 126B may determine that the source PLMN of the message does not match the home PLMN in the SUPI extracted from the message and identify the message as a location tracking attack. If the source PLMN of the message matches the home PLMN included in the SUPI, the SEPP may perform a lookup in the AMF Location Service Verification Database using the SUPI extracted from the AMF Location Service message. If the SUPI does not exist in the database, or if the authentication result obtained from the database does not indicate that the UE has been authenticated, the AMF Location Service message may be classified as a DoS attack.
[0073] In step 810, the process includes preventing a location tracking attack or a DoS attack in response to classifying an AMF location service message as a location tracking attack or a DoS attack. For example, the visited SEPP 126B may prevent the attack by discarding the message in response to classifying the AMF location service message as a location tracking or DoS attack. The visited SEPP 126B may also store the message and send a message identifying the message as being associated with a location tracking attack or DoS to the network operator.
[0074] Advantages of the subject matter described herein include mitigating or reducing the success of location tracking attacks where the location of a UE can be obtained without authorization. The subject matter described herein also mitigates or reduces the success of service disruption attacks at the AMF. This is because unauthorized AMF location service messages identified as being associated with a location tracking attack or DoS attack are stopped at the SEPP and transfer to the AMF is prevented. The subject matter described herein may be implemented in any NF that processes or forwards an AMF location service message, including the visited SEPP of the UE and the AMF to which the UE is registered. The subject matter described herein may also be extended to verify other types of PLMN - to - PLMN messaging for the visited SEPP.
[0075] The disclosure of each of the following references is hereby incorporated by reference in its entirety: References 1. 3GPP TS 33.501 V17.0.0 (2020 - 12) 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security Architecture and Procedures for 5G Systems (Release 17) 2. 3GPP TS 29.573 V16.5.0 (2020 - 12) 3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G Systems; Public Land Mobile Network (PLMN) Interconnection; Stage 3 (Release 16) 3. 3GPP TS 29.572 V16.5.0 (2020 - 12) Third Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Location Management Services; Stage 3 (Release 16) 4. 3GPP TS 29.518 V17.0.0 (2020 - 12) Third Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Access and Mobility Management Services; Stage 3 (Release 17) 5. 3GPP TS 23.502 V16.7.1 (2021 - 01), Third Generation Partnership Project; Technical Specification Group Services and System Aspects; Procedures for the 5G System (5G System: 5GS); Stage 2 (Release 16) 6. 3GPP TS 23.501 V16.7.0 (2020 - 12), Third Generation Partnership Project; Technical Specification Group Services and System Aspects; System Architecture for the 5G System (5GS); Stage 2 (Release 16).
[0076] It will be understood that various details of the subject matter described herein may be changed without departing from the scope of the subject matter described herein. Further, since the subject matter described herein is defined by the claims as set forth below, the above description is for illustrative purposes only and not for purposes of limitation.
Claims
1. A method for mitigating location tracking attacks and service disruption (DoS) attacks that utilize an access and mobility management function (AMF) location service, the method comprising: a network function (NF) receiving an authentication response message from a home public land mobile network (HPLMN) of a user equipment (UE); the NF extracting a subscription identifier and an indicator of an authentication result for the UE from the authentication response message; the NF storing the subscription identifier and the indicator of the authentication result for the UE in an AMF location service verification database; the NF receiving an AMF location service message; the NF using at least one of a subscription identifier extracted from the AMF location service message and contents of the AMF location service verification database to classify the AMF location service message as a location tracking attack or a DoS attack; responding to classifying the AMF location service message as a location tracking attack or a DoS attack, preventing the location tracking attack or the DoS attack. A method comprising.
2. The method according to claim 1, wherein the NF includes a security edge protection proxy (SEPP).
3. The method according to claim 2, wherein the SEPP includes a visited SEPP of the UE.
4. The method according to any one of claims 1 to 3, wherein the step of receiving an authentication response message includes receiving an Nausf_UEAuthentication message including an authentication result parameter and a subscription permanent identifier (SUPI).
5. The method according to claim 4, wherein the step of storing the subscription identifier and the indicator of the authentication result includes storing values of the SUPI and the authentication result parameter.
6. The step of using at least one of the subscription identifier extracted from the AMF location service message and the contents of the AMF location service verification database to classify the AMF location service message as a location tracking attack or a DoS attack includes: extracting the SUPI from the AMF location service message; a step of determining that the source PLMN of the AMF location service message matches the home PLMN of the SUPI extracted from the AMF location service message; a step of performing a lookup in the AMF location service verification database using the SUPI; a step of classifying the AMF location service message as a DoS attack in response to not being able to find a record corresponding to the SUPI in the AMF location service verification database, or finding a record corresponding to the SUPI in the AMF location service verification database and determining that the record contains a value of an authentication result parameter indicating that the authentication of the UE was unsuccessful, the method according to claim 5.
7. The step of using at least one of the subscription identifier extracted from the AMF location service message and the content of the AMF location service verification database to classify the AMF location service message as a location tracking attack or a DoS attack is a step of extracting a subscription permanent identifier (SUPI) from the AMF location service message; a step of identifying the home PLMN from the SUPI; a step of determining the source PLMN of the AMF location service message; a step of classifying the AMF location service message as a location tracking attack in response to determining that the home PLMN identified from the SUPI does not match the source PLMN of the AMF location service message, the method according to claim 1.
8. The step of determining the source PLMN of the AMF location service message includes the step of determining the source PLMN from the source address or the source transport layer security (TLS) certificate of the AMF location service message, the method according to claim 7.
9. The step of receiving an AMF location service message includes the step of receiving a Namf_Location service message, the method according to any one of claims 1 to 8.
10. The method according to claim 9, wherein the Namf_Location service message includes one of a positioning information providing service operation identifier, an event notification service operation identifier, and a location information providing service operation identifier.
11. A system for mitigating location tracking attacks and DoS attacks that utilize an Access and Mobility Management Function (AMF) location service, the system comprising: a Network Function (NF) including at least one processor and memory; an AMF location service verification database embodied in the memory; an authentication result collector implemented by the at least one processor to receive an authentication response message from a Home Public Land Mobile Network (HPLMN) of a User Equipment (UE), extract a subscription identifier and an indicator of an authentication result for the UE from the authentication response message, and store the subscription identifier and the indicator of the authentication result for the UE in the AMF location service verification database; an AMF location service verifier implemented by the at least one processor to receive an AMF location service message, use at least one of a subscription identifier extracted from the AMF location service message and contents of the AMF location service verification database to classify the AMF location service message as a location tracking attack or a DoS attack, and prevent the location tracking attack or the DoS attack in response to classifying the AMF location service message as a location tracking attack or a DoS attack.
12. The system according to claim 11, wherein the NF includes a Security Edge Protection Proxy (SEPP).
13. The system according to claim 12, wherein the SEPP includes a visited SEPP of the UE.
14. The system according to any one of claims 11 to 13, wherein the authentication response message includes a Nausf_UEAuthentication message including an authentication result parameter and a Subscription Permanent Identifier (SUPI).
15. The system according to claim 14, wherein the subscription identifier includes the SUPI, and the indicator of the authentication result includes a value of the authentication result parameter.
16. When using at least one of the subscription identifier extracted from the AMF location service message and the content of the AMF location service verification database to classify the AMF location service message as a location tracking attack or a DoS attack, the AMF location service verifier extracts a SUPI from the AMF location service message, determines that the source PLMN of the AMF location service message matches the home PLMN of the SUPI extracted from the AMF location service message, performs a lookup in the AMF location service verification database using the SUPI, classifies the AMF location service message as a DoS attack in response to not being able to find a record corresponding to the SUPI in the AMF location service verification database, or finding a record corresponding to the SUPI in the AMF location service verification database and determining that the record contains a value of an authentication result parameter indicating that the authentication of the UE was unsuccessful The system according to claim 15, configured as such. **Claim 17** When using at least one of the subscription identifier extracted from the AMF location service message and the content of the AMF location service verification database to classify the AMF location service message as a location tracking attack or a DoS attack, the AMF location service verifier extracts a subscription permanent identifier (SUPI) from the AMF location service message, identifies the home PLMN from the SUPI extracted from the AMF location service message, determines the source PLMN of the AMF location service message, classifies the AMF location service message as a location tracking attack in response to determining that the home PLMN identified from the SUPI does not match the source PLMN of the AMF location service message The system according to claim 11, configured as such. **Claim 18** The AMF location service verifier of the system according to claim 17 is configured to determine the source PLMN of the AMF location service message by determining the source PLMN from the source address of the AMF location service message or the source transport layer security (TLS) certificate.
19. The system according to any one of claims 11 to 18, wherein the AMF location service message includes a Namf_Location service message including one of a positioning information providing service operation identifier, an event notification service operation identifier, and a location information providing service operation identifier.
20. A program including executable instructions for controlling the computer to perform the method according to any one of claims 1 to 10 when executed by a processor of the computer.
Citation Information
Patent Citations
Method, system, and computer-readable medium for Mobility Management Entity (MME) authentication for outbound roaming subscribers using a Diameter Edge Agent (DEA)
JP2020529776A
Method for synchronization of home network key
WO2020179665A1