Skip to main content

Conference Paper

Fixing Insecure Cellular System Information Broadcasts For Good

Alexander J. Ross, Bradley Reaves, Yomna Nasser, Gil Cukierman, and Roger Piqueras Jover

International Symposium on Research in Attacks, Intrusions and Defenses, 2024

LTE and 5G networks can implement backwards-compatible integrity protection for configuration broadcasts with marginal overhead.

Abstract

Cellular networks are essential everywhere, and securing them is increasingly important as attacks against them become more prevalent and powerful. All cellular network generations bootstrap new radio connections with unauthenticated System Information Blocks (SIBs), which provide critical parameters needed to identify and connect to the network. Many cellular network attacks require exploiting SIBs. Authenticating these messages would eliminate whole classes of attack, from spoofed emergency alerts to fake base stations. This paper presents Broadcast But Verify, an efficient backwardscompatible mechanism for SIB authentication. Broadcast But Verify specifies a new signing SIB that encodes authentication signatures and hashes for all other SIBs while building on a standard cellular PKI. We identify the security and functional requirements for such a system, define a scalable and flexible mechanism to meet those requirements, and demonstrate negligible common-case connection latency overhead of 3.220ms in a 4G LTE testbed. We also demonstrate that unmodified mobile devices successfully connect to networks deploying Broadcast But Verify. In contrast to prior proposals, Broadcast But Verify authenticates every SIB broadcasted by a cell. By demonstrating that even 4G LTE has the capacity to authenticate SIBs, we argue that future network generations can and should mandate authenticated SIBs.

Citation (IEEE)

A. J. Ross, B. Reaves, Y. Nasser, G. Cukierman, and R. P. Jover, “Fixing Insecure Cellular System Information Broadcasts For Good,” in International Symposium on Research in Attacks, Intrusions and Defenses, 2024.

BibTeX
@inproceedings{rrn+24,
  author = {Ross, Alexander J. and Reaves, Bradley and Nasser, Yomna and Cukierman, Gil and {Piqueras Jover}, Roger},
  booktitle = {International Symposium on Research in Attacks, Intrusions and Defenses},
  date = {2024-09},
  title = {Fixing Insecure Cellular System Information Broadcasts For Good},
}