Authors:
Navya Sivaraman
and
Simin Nadjm-Tehrani
Affiliation:
Department of Computer and Information Science, Linköping University, Sweden
Keyword(s):
5G Xn Handover Protocol, Forward Security, Protocol Verification, Formal Analysis.
Abstract:
5G mobility management is dependent on a couple of complex protocols for managing handovers, based on the available network interfaces (such as Xn and N2). In our work, we focus on the 5G Xn handover procedure, as defined by the 3GPP standard. In Xn handovers, the source base station hands the user equipment (UE) over to a target base station through two different mechanisms: horizontal or vertical key derivation. To ascertain the security of these complex protocols, recent works have formally described the protocols and proved some security properties. In this work, we formulate a new property, forward security, which ensures the secrecy of future handovers following a session key exchange in one handover. Using a formal model and the Tamarin prover, we show that forward security breaks in the 5G Xn handover in presence of an untrusted base station. We also propose a solution to mitigate this counter-example with a small modification of the 3GPP Xn handover procedures based on the p
erceived source base station state.
(More)