5G Handover: When Forward Security Breaks
Navya Sivaraman, Simin Nadjm-Tehrani
2023
Abstract
5G mobility management is dependent on a couple of complex protocols for managing handovers, based on the available network interfaces (such as Xn and N2). In our work, we focus on the 5G Xn handover procedure, as defined by the 3GPP standard. In Xn handovers, the source base station hands the user equipment (UE) over to a target base station through two different mechanisms: horizontal or vertical key derivation. To ascertain the security of these complex protocols, recent works have formally described the protocols and proved some security properties. In this work, we formulate a new property, forward security, which ensures the secrecy of future handovers following a session key exchange in one handover. Using a formal model and the Tamarin prover, we show that forward security breaks in the 5G Xn handover in presence of an untrusted base station. We also propose a solution to mitigate this counter-example with a small modification of the 3GPP Xn handover procedures based on the perceived source base station state.
DownloadPaper Citation
in Harvard Style
Sivaraman N. and Nadjm-Tehrani S. (2023). 5G Handover: When Forward Security Breaks. In Proceedings of the 20th International Conference on Security and Cryptography - Volume 1: SECRYPT; ISBN 978-989-758-666-8, SciTePress, pages 503-510. DOI: 10.5220/0012128400003555
in Bibtex Style
@conference{secrypt23,
author={Navya Sivaraman and Simin Nadjm-Tehrani},
title={5G Handover: When Forward Security Breaks},
booktitle={Proceedings of the 20th International Conference on Security and Cryptography - Volume 1: SECRYPT},
year={2023},
pages={503-510},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0012128400003555},
isbn={978-989-758-666-8},
}
in EndNote Style
TY - CONF
JO - Proceedings of the 20th International Conference on Security and Cryptography - Volume 1: SECRYPT
TI - 5G Handover: When Forward Security Breaks
SN - 978-989-758-666-8
AU - Sivaraman N.
AU - Nadjm-Tehrani S.
PY - 2023
SP - 503
EP - 510
DO - 10.5220/0012128400003555
PB - SciTePress