Gateway IMSI Acquisition via S1AP Message Manipulation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In mobile communication systems, gateways (GWs) face challenges in acquiring a user equipment's (UE) permanent identifier, such as IMSI, without requesting the mobility management entity (MME) to provide it, as temporary identifiers are primarily used and messages are often encrypted, making it difficult for GWs to obtain the permanent identifier during signaling and data exchanges.

Innovation Solution

The GW identifies control messages requesting UE attachment, alters the temporary identifier to a fabricated one that prevents successful identification by the MME, causing the MME to request the UE to provide its permanent identifier, allowing the GW to extract the IMSI from subsequent messages.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the GW uses temporary identifier (GUTI) for UE identification during signaling exchanges, then communication security is improved through encryption, but the GW cannot obtain the permanent identifier (IMSI) needed for accounting and security control

Engineering Contradiction:
Improvecommunication securityVSAvoidpermanent identifier availability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The GW performs preliminary actions by intercepting and modifying the attach request message before it reaches the MME, altering the temporary identifier to trigger an identity request. This preliminary modification sets up the condition for obtaining the IMSI without directly requesting it, resolving the contradiction between maintaining security and obtaining identification information.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The GW acts as an intermediary between the UE and MME, manipulating the signaling messages to indirectly obtain the IMSI. By modifying the attach request and relaying it to the MME, the GW enables the MME to send an identity request to the UE, which then provides the IMSI in an unencrypted form that the GW can capture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the GW directly requests the MME to provide the permanent identifier, then obtaining the IMSI becomes straightforward, but system complexity increases and direct access to MME internal data is required

Engineering Contradiction:
ImproveIMSI acquisition simplicityVSAvoidgateway-MME interaction complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

Instead of the GW directly requesting the IMSI from the MME, the system uses self-service by triggering the UE to voluntarily provide its own IMSI in response to an identity request. The UE itself serves as the source of its identification information, eliminating the need for complex direct GW-MME data access mechanisms.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Rather than the GW directly obtaining the IMSI from the MME through a direct request, the approach is inverted: the GW modifies messages to trigger the MME to request the IMSI from the UE, and the GW intercepts the UE's response. This indirect approach simplifies the GW-MME interaction while achieving the same goal.

Inventive Principle:
Principle #13The other way round (Inversion)

3Loss of information

If existing methods are used to obtain IMSI without MME request, then the GW can acquire the permanent identifier, but these methods require deliberate network failure which compromises system reliability

Engineering Contradiction:
Improvepermanent identifier accessibilityVSAvoidnetwork stability
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The GW applies preliminary anti-action by preemptively modifying the attach request message to contain an altered temporary identifier, preventing the MME from successfully identifying the UE with the original GUTI. This prevents the need for deliberate network failure while still triggering the identity request mechanism, thereby maintaining system reliability while achieving IMSI acquisition.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS10064048B1Acquiring permanent identifier of user equipment by gateway in mobile communication system
Publication Date: 2018.08.28 HONG KONG APPLIED SCI & TECH RES INST
  • US10064048B1 patent drawing
  • US10064048B1 patent drawing
  • US10064048B1 patent drawing

AI summary

A gateway (GW) acquires an International Mobile Subscriber Identity (IMSI) of a user equipment (UE) without requesting a mobile management entity (MME) of a core network (CN) to provide it. The GW detects arrival of a S1AP message for the UE. If the GW does not have the IMSI of the UE, and if a NAS payload of the S1AP message is ciphered, send to the UE a rejecting message indicating detaching the UE from the CN, causing the UE to request re-attaching to the CN in a S1AP message that is an Initial UE Message, which contains a temporary identifier of the UE. Then alter the Initial UE Message with a fabricated temporary identifier not recognizable by the MME and send the altered message to the MME, causing the MME to ask the UE to identify itself with the IMSI, which is read by the GW.