Gateway IMSI Acquisition via S1AP Message Manipulation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In mobile communication systems, gateways (GWs) face challenges in acquiring a user equipment's (UE) permanent identifier, such as IMSI, without requesting the mobility management entity (MME) to provide it, as temporary identifiers are primarily used and messages are often encrypted, making it difficult for GWs to obtain the permanent identifier during signaling and data exchanges.
Innovation Solution
The GW identifies control messages requesting UE attachment, alters the temporary identifier to a fabricated one that prevents successful identification by the MME, causing the MME to request the UE to provide its permanent identifier, allowing the GW to extract the IMSI from subsequent messages.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the GW uses temporary identifier (GUTI) for UE identification during signaling exchanges, then communication security is improved through encryption, but the GW cannot obtain the permanent identifier (IMSI) needed for accounting and security control
Solution Approach 1:
The GW performs preliminary actions by intercepting and modifying the attach request message before it reaches the MME, altering the temporary identifier to trigger an identity request. This preliminary modification sets up the condition for obtaining the IMSI without directly requesting it, resolving the contradiction between maintaining security and obtaining identification information.
Solution Approach 2:
The GW acts as an intermediary between the UE and MME, manipulating the signaling messages to indirectly obtain the IMSI. By modifying the attach request and relaying it to the MME, the GW enables the MME to send an identity request to the UE, which then provides the IMSI in an unencrypted form that the GW can capture.
2Ease of operation
If the GW directly requests the MME to provide the permanent identifier, then obtaining the IMSI becomes straightforward, but system complexity increases and direct access to MME internal data is required
Solution Approach 1:
Instead of the GW directly requesting the IMSI from the MME, the system uses self-service by triggering the UE to voluntarily provide its own IMSI in response to an identity request. The UE itself serves as the source of its identification information, eliminating the need for complex direct GW-MME data access mechanisms.
Solution Approach 2:
Rather than the GW directly obtaining the IMSI from the MME through a direct request, the approach is inverted: the GW modifies messages to trigger the MME to request the IMSI from the UE, and the GW intercepts the UE's response. This indirect approach simplifies the GW-MME interaction while achieving the same goal.
3Loss of information
If existing methods are used to obtain IMSI without MME request, then the GW can acquire the permanent identifier, but these methods require deliberate network failure which compromises system reliability
Solution Approach 1:
The GW applies preliminary anti-action by preemptively modifying the attach request message to contain an altered temporary identifier, preventing the MME from successfully identifying the UE with the original GUTI. This prevents the need for deliberate network failure while still triggering the identity request mechanism, thereby maintaining system reliability while achieving IMSI acquisition.
Data Source
AI summary
A gateway (GW) acquires an International Mobile Subscriber Identity (IMSI) of a user equipment (UE) without requesting a mobile management entity (MME) of a core network (CN) to provide it. The GW detects arrival of a S1AP message for the UE. If the GW does not have the IMSI of the UE, and if a NAS payload of the S1AP message is ciphered, send to the UE a rejecting message indicating detaching the UE from the CN, causing the UE to request re-attaching to the CN in a S1AP message that is an Initial UE Message, which contains a temporary identifier of the UE. Then alter the Initial UE Message with a fabricated temporary identifier not recognizable by the MME and send the altered message to the MME, causing the MME to ask the UE to identify itself with the IMSI, which is read by the GW.


