Mincheol Son

dblp:236/4147 · DBLP profile ↗
← Back
9ranked-venue papers
1as first author
8since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 1 first-author · 8 since 2021
YearPublicationVenuePosition
2025 CITesting: Systematic Testing of Context Integrity Violations in LTE Core Networks
abstract
Cellular networks increasingly support critical infrastructure, yet their security remains an ongoing concern. While prior research has focused mainly on downlink vulnerabilities, uplink security—how user equipment (UE) affects the core network—has received limited attention. We study a class of uplink vulnerabilities, which we define as context integrity violations (CIVs), where an unauthenticated or improperly authenticated UE modifies the internal state of other subscribers. Prior work identified a few instances of CIVs, but the broader attack surface remains unexplored. We present CITesting, the first framework for systematically detecting CIVs in LTE core networks. CITesting explores diverse procedure chains, tests a broad range of Information Elements (IEs), and validates behavior across UE connection states. It introduces stateful dual-UE control testing to manage victim UE state and employs a behavioral oracle to detect context modifications in black-box networks. We evaluated CITesting on two open-source (Open5GS, srsRAN) and two commercial (Amarisoft, Nokia) LTE core network implementations, identifying 29, 22, 16, and 59 distinct CIVs after post-analysis. These findings enable remote attacks including UE detachment, IMSI exposure, and presence detection attacks. Note that traditional attack models such as fake base station and active SigOver require the active attacker to be co-located in the same cell. In contrast, our attacks require the active attacker to be in the same MME region (significantly broader than a cell) as the victim UE. All findings were responsibly disclosed, and patches were contributed to Amarisoft and Open5GS.
Mincheol Son, Beomseok Oh 0001, CheolJun Park, Yongdae Kim
CCS1
2025 sfPolocolo: A ZK-Friendly Hash Function Based on S-Boxes Using Power Residues
Jincheol Ha, Seongha Hwang, Jooyoung Lee 0001, Mincheol Son
EUROCRYPT (4)5
2025 Relaxed Vector Commitment for Shorter Signatures
Seongkwang Kim, ByeongHak Lee, Mincheol Son
EUROCRYPT (4)3
2023 AIM: Symmetric Primitive for Shorter Signatures with Stronger Security
abstract
Post-quantum signature schemes based on the MPC-in-the-Head (MPCitH) paradigm are recently attracting significant attention as their security solely depends on the one-wayness of the underlying primitive, providing diversity for the hardness assumption in post-quantum cryptography. Recent MPCitH-friendly ciphers have been designed using simple algebraic S-boxes operating on a large field in order to improve the performance of the resulting signature schemes. Due to their simple algebraic structures, their security against algebraic attacks should be comprehensively studied.
Seongkwang Kim, Jincheol Ha, Mincheol Son, ByeongHak Lee, Dukjae Moon, Joohee Lee, Sangyub Lee 0002, Jihoon Kwon, Jooyoung Lee 0001
CCS3
2023 Preventing SIM Box Fraud Using Device Model Fingerprinting
Beomseok Oh 0001, Junho Ahn, Sangwook Bae, Mincheol Son, Yonghwa Lee, Min Suk Kang, Yongdae Kim
NDSS4
2023 LTESniffer: An Open-source LTE Downlink/Uplink Eavesdropper
abstract
LTE sniffers are important for security and performance analysis because they can passively capture the wireless traffic of users in LTE network. However, existing open-source LTE sniffers have only limited functionality and cannot decode data traffic. This paper introduces LTESNIFFER, the first open-source LTE sniffer that can passively decode both uplink and downlink data traffic. Implementing a sniffer is not trivial because one needs to understand detailed configurations and parameters to successfully decode each user's traffic. Using multiple techniques, we found mechanisms to understand these, which improves our decoding performance. We evaluated the performance of LTESNIFFER on both testbed and commercial network environments. We also compare the performance of LTESNIFFER with AirScope, a popular commercial LTE sniffer. Additionally, LTESNIFFER provides a proof-of-concept API with three functions that can be used for security applications, including identity mapping, identity collecting, and device capability profiling. We release LTESNIFFER as open-source for future research.
Tuan Dinh Hoang, CheolJun Park, Mincheol Son, Taekkyung Oh, Sangwook Bae, Junho Ahn, Beomseok Oh 0001, Yongdae Kim
WISEC3
2022 Rubato: Noisy Ciphers for Approximate Homomorphic Encryption
Jincheol Ha, Seongkwang Kim, ByeongHak Lee, Jooyoung Lee 0001, Mincheol Son
EUROCRYPT (1)5
2022 Watching the Watchers: Practical Video Identification Attack in LTE Networks
Sangwook Bae, Mincheol Son, Dongkwan Kim 0001, CheolJun Park, Sooel Son, Yongdae Kim
USENIX Security Symposium2
2019 Hiding in Plain Signal: Physical Signal Overshadowing Attack on LTE
Hojoon Yang, Sangwook Bae, Mincheol Son, Song Min Kim, Yongdae Kim
USENIX Security Symposium3