vix.ing · top · new · best · stats · spec

Retrofitting mutual authentication to GSM using RAND hijacking

2016/07/04 by Mohammed Shafiul Alam Khan, Khan, Mohammed Shafiul Alam, Chris J. Mitchell +1
Computer Science · Engineering · #Advanced Authentication Protocols Security #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #IPv6, Mobility, Handover, Networks, Security #User Authentication and Security Systems

paper · pdf · doi:10.48550/arxiv.1607.00729

openalex publication_date 2016/07/04 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28

Abstract

As has been widely discussed, the GSM mobile telephony system only offers unilateral authentication of the mobile phone to the network; this limitation permits a range of attacks. While adding support for mutual authentication would be highly beneficial, changing the way GSM serving networks operate is not practical. This paper proposes a novel modification to the relationship between a Subscriber Identity Module (SIM) and its home network which allows mutual authentication without changing any of the existing mobile infrastructure, including the phones; the only necessary changes are to the authentication centres and the SIMs. This enhancement, which could be deployed piecemeal in a completely transparent way, not only addresses a number of serious vulnerabilities in GSM but is also the first proposal for enhancing GSM authentication that possesses such transparency properties.

Related