Vadim Yanitskiy
Circuit switched and Packet Switched domains
MM
, RR
)
CC
)
SS
)
*100#
)
SM
)
GMM
)
SM
) - SMS-over-GPRS
MS (Mobile Station) - mobile phone + SIM-card
BTS (Base Transceiver Station)
BSC (Base Station Controller)
PCU (Packet Control Unit)
HLR (Home Location Register)
VLR (Visitor Location Register)
MSC (Mobile Switching Center)
SGSN (Serving GPRS Support Node)
GGSN (GPRS Gateway Support Node)
Axillary nodes
UMTS specific elements
Similar infrastructure, different abbreviations
Basic principles of the cellular coverage
Service provider identification
901/70
, 262/42
internet.provider.com
internet.provider.com
- Internet traffic
wap.provider.com
- WAP traffic
mms.provider.com
- MMS messages
Subscriber identification (1)
Subscriber identification (2)
Subscriber identification (3)
Shared medium access
Shared medium access
TDMA frame / slot hierarchy
Control TDMA frame structure
Traffic TDMA frame structure
Convolutional coding
Data transfer technologies (plugins)
Subscriber identity masquerading
Periodic Location Updating
)
TMSI Reallocation
)
TMSI Reallocation
may be initiated by the network only, not by the MS itself
Authentication
A3(RAND, Ki) = SRAND
A3(RAND, Ki') == SRAND
?
The A5/x encryption
Ciphering Mode Command
)
A5(Kc, TDMA Fn, Burst bits) -> gamma
burst XOR gamma -> encrypted burst
The myth of frequency hopping
MAI = f(HSN, MAIO, MA, TDMA Fn)
IMSI / TMSI Detach Attack
IMSI Detach
)
Paging Response Race Condition
2G GSM
A8(Ki, RAND)
2.5G (E)GPRS
A8(Ki, RAND)
3G UMTS (1)
3G UMTS (2)
f4(K, RAND)
4G LTE (1)
4G LTE (2)
4G LTE (3)
IMSI catchers coming soon…
Questions?