Unified Serving Node Packet Deciphering for LTE Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Monitoring ciphered traffic flowing over S1 interfaces in modern LTE networks is challenging due to the lack of access to critical information exchanged between SGSNs and MMEs, which is essential for network performance monitoring.
Innovation Solution
A system that captures and deciphers packets across multiple interfaces, including those between UE and USN, HLR, and HSS, to extract and correlate user identifying information and ciphering keys, enabling the deciphering of NAS ciphered packets using stored mappings and keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If packets are captured only on external network interfaces, then network monitoring coverage is limited, but critical internal information flows are missed
Solution Approach 1:
The monitoring system is nested within the USN architecture, with the USN containing both SGSN and MME functions. This nesting allows the monitoring point to access critical internal information flows between SGSN and MME that are otherwise inaccessible from external interfaces, resolving the contradiction between monitoring coverage and system complexity.
Solution Approach 2:
The USN acts as an intermediary entity that bridges the gap between external network monitoring and internal critical information flows. By positioning the monitoring point at the USN level, the system can capture both external interface traffic and internal SGSN-MME communications without requiring direct access to multiple separate systems.
2Measurement precision
If ciphered packets are monitored without access to deciphering keys, then network security is maintained, but network performance analysis is impaired
Solution Approach 1:
The system performs preliminary capture of deciphering keys and authentication information from authentication vectors before the actual ciphered traffic monitoring begins. This preliminary action stores the necessary keys in the monitoring system, enabling subsequent decryption of NAS ciphered packets without compromising network security during operation.
Solution Approach 2:
The monitoring process is segmented into distinct phases: key capture phase (where authentication vectors and deciphering keys are obtained), and traffic analysis phase (where ciphered packets are decrypted and analyzed). This segmentation allows secure key management separate from the actual monitoring operations, resolving the contradiction between security and analysis capability.
3Loss of information
If multiple interfaces are monitored simultaneously, then comprehensive traffic capture is achieved, but system complexity increases
Solution Approach 1:
The USN monitoring point is designed with multi-functionality, capable of simultaneously monitoring multiple interfaces (S1-MME, S11, S6a) and handling both ciphered and unciphered traffic. This universal monitoring capability achieves comprehensive traffic capture while consolidating complexity into a single multi-functional platform rather than requiring separate systems for each interface.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
First and second pluralities of packets transmitted between UE and the USN over a first interface and a second interface are continuously captured. The first, second and third pluralities contains temporary and permanent identifying information and ciphering key information. A fourth plurality of packets transmitted between the USN and a HSS over a fourth interface is captured. The temporary, permanent identifying information and the ciphering key information are correlated to determine mappings stored in a data repository. A fifth plurality transmitted over a fifth interface is continuously captured. Permanent identifying information corresponding to the temporary identifying information retrieved from the unciphered packets of the fifth plurality is retrieved from the data repository based on the stored mappings. NAS deciphering key information corresponding to the retrieved permanent identifying information is retrieved. The ciphered packets of the fifth plurality of packets are deciphered based on the retrieved NAS deciphering key information.