Detecting Null-Ciphering Channels in Mobile Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

LTE and 5G mobile communication networks are vulnerable to man-in-the-middle attacks that establish unintended null-ciphering channels, allowing attackers to intercept and manipulate communication without encryption, posing risks to subscriber billing and security.

Innovation Solution

A method and apparatus for detecting abnormal traffic by analyzing Non-Access Stratum (NAS) traffic between user equipment and mobility management nodes, identifying terminals that only support null ciphering algorithms, and taking measures to limit access and disconnect risky channels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If null ciphering algorithm is supported for emergency calls, then ease of operation is improved, but network security deteriorates due to MITM attacks

Engineering Contradiction:
Improveemergency call functionalityVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary verification of UE network capability declarations by checking consistency across multiple messages (Attach Request, TAU Request, RA Message) before allowing null ciphering. This advance checking prevents malicious terminals from establishing unencrypted channels while preserving emergency call functionality for legitimate UEs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous monitoring and feedback mechanisms that track UE ciphering algorithm declarations across different signaling messages. When inconsistencies are detected, the system provides feedback by rejecting the connection or alerting the network, thereby preventing MITM attacks while allowing legitimate emergency calls to proceed.

Inventive Principle:
Principle #23Feedback

2Ease of operation

If ciphering is disabled for null ciphering channels, then ease of operation is improved, but loss of information increases due to unencrypted communication

Engineering Contradiction:
Improvecommunication simplicityVSAvoidcommunication security
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The system performs preliminary verification of UE network capability declarations by checking consistency across multiple messages (Attach Request, TAU Request, RA Message) before allowing null ciphering. This advance checking prevents malicious terminals from establishing unencrypted channels while preserving emergency call functionality for legitimate UEs.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If network monitors all NAS traffic for security, then network security is improved, but use of energy increases due to additional processing

Engineering Contradiction:
Improvenetwork securityVSAvoidprocessing energy
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system applies security monitoring selectively rather than uniformly to all traffic. It focuses computational resources on detecting inconsistent ciphering algorithm declarations in NAS messages, which is the specific indicator of potential MITM attacks, rather than encrypting or analyzing all communication content.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11350282B2Method and apparatus for detecting null-ciphering channels
Publication Date: 2022.05.31 KOREA INTERNET & SECURITY AGENCY
  • US11350282B2 patent drawing
  • US11350282B2 patent drawing
  • US11350282B2 patent drawing

AI summary

Provided is a method for detecting abnormal traffic. The method comprises collecting non-access stratum (NAS) traffic between a user equipment (UE) and a mobility management node, identifying a ciphering algorithm supported by the UE from a network access request message transmitted from the UE to the mobility management node, and identifying the UE as a first type of terminal at risk based on a determination that the UE only supports a null ciphering algorithm.