Sunteți pe pagina 1din 6

GSM Network Architecture

 Which related to the security system


Network and Switching Subsystem

Permanen Temporer
IMSI Ki MSRN Kc
HLR MSISDN SRES RAND
BTS
LAI A5
IMSI Ki Kc A3
AUC SRES RAND A8

IMSI MSRN
VLR TMSI MSISDN LAI
Mobile Station ME

SIM
• IMSI : International Mobile Subscriber Identity
• TMSI : Temporary Mobile Subscriber Identity
• MSRN : Mobile Station Roaming Number
IMSI Ki A3 A8 A5
• MSISDN : Mobile Station ISDN
• LAI : Local Area Identity
• Ki : authentication key
• Kc : ciphering key
• SRES : Signed Response
• RAND : random number
GSM Security Algorithms

Ki A3 SRES
128 bit 32 bit

TDMA
RAND A8 Kc frame
128 bit 64 bit
number

A5
• A3 : Subscriber authentication
S2 S1
algorithm downlink
• A8 : Cipher key generation
Plain text Cipher text
algorithm 114 bit 114 bit
• A5 : Ciphering/deciphering uplink
algorithm
GSM Security System Basic Services

• TMSI assignment
• Authentication
• Signaling and voice data confidentiality
• SIM and ME identification
TMSI Assignment

IMSI IMSI

VLR
BTS
E(TMSI) A5 TMSI

• Objective : to protect the IMSI.


• 5 digit TMSI replace at each location update procedure.
• TMSI sent encrypted by A5 algorithm from BTS to MS.
Weaknesses:
 No protection for IMSI which transmitted between MS and fixed network.
 TMSI only encrypted between BTS and MS.
Authentication
challenge

RAND
RAND SRESnetwork
Ki

A3
SRESMS
No
=
SRESMS SRESnetwork Deny access
SRESMS
?
response
MS Access Yes
granted
Fixed network

• Objective : to know subscriber identity fidelity.


• Known as Challenge-Response method.
Weaknesses:
 No protection for RAND and SRESMS which transmitted.
Ciphering - Deciphering

Kc Nomor Frame Kc Nomor Frame


64 bit 22 bit 64 bit 22 bit

Codeword downlink
114 bit
Algoritma A5 Algoritma A5
S1 S1

Plaintext
Ciphertext Plaintext
S2 S2
114 bit 114 bit 114 bit

Codeword uplink
BTS MS
114 bit

• Ciphering process are held on BTS and MS, using A5 algorithm.


• Symmetry cryptography.

S-ar putea să vă placă și