Paper 2003/092

Provably-Secure Enhancement on 3GPP Authentication and Key Agreement Protocol

Muxiang Zhang

Abstract

This paper analyses the authentication and key agreement protocol adopted by Universal Mobile Telecommunication System (UMTS), an emerging standard for third generation (3G) wireless communications. The protocol, known as {\em 3GPP AKA}, is based on the security framework of GSM and provides significant enhancement to address and correct real and perceived weaknesses in GSM and other wireless communication systems. In this paper, we show that 3GPP AKA is vulnerable to a variant of false base station attack. The vulnerability allows an adversary to re-direct user traffic to an unintended network. It also allows an adversary to use authentication vectors obtained from a corrupted network to impersonate all other networks. In addition, we show that the need of synchronization between a mobile station and its home network incurs considerable difficulty for the normal operation of 3GPP AKA. To provide further enhancement on 3GPP AKA, we present an authentication and key agreement protocol which defeats re-direction attack and drastically lowers the impact of network corruption. The proposed protocol also eliminates synchronization between a mobile station and its home network. Following the multi-party simulatability approach, we have developed a formal model of security for symmetric-key based authentication and key agreement protocols in the mobile setting. Within this model, we have analyzed the security of our protocol against a powerful adversary having full control of the communication channels between a user and a network.

Metadata
Available format(s)
PDF PS
Category
Cryptographic protocols
Publication info
Published elsewhere. Unknown where it was published
Keywords
AuthenticationKey Agreementmobile communication
Contact author(s)
muxiang zhang @ verizon com
History
2003-05-15: revised
2003-05-10: received
See all versions
Short URL
https://ia.cr/2003/092
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2003/092,
      author = {Muxiang Zhang},
      title = {Provably-Secure Enhancement on {3GPP} Authentication and Key Agreement Protocol},
      howpublished = {Cryptology {ePrint} Archive, Paper 2003/092},
      year = {2003},
      url = {https://eprint.iacr.org/2003/092}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.