Chuan Yu 0003

dblp:50/790-3 · DBLP profile ↗
← Back
6ranked-venue papers
6as first author
4since 2021 · last 2024
0000-0003-3616-5571ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 3 · 3 first-author · 2 since 2021Security and privacy · 3 · 3 first-author · 2 since 2021
YearPublicationVenuePosition
2024 Protecting unauthenticated messages in LTE/5G mobile networks: A two-level Hierarchical Identity-Based Signature (HIBS) solution
Chuan Yu 0003, Shuhui Chen, Qianqian Xing, Ziling Wei
Comput. Networks1
2024 Toward a Truly Secure Telecom Network: Analyzing and Exploiting Vulnerable Security Configurations/ Implementations in Commercial LTE/IMS Networks
abstract
Authentication and data protection (both integrity and confidentiality) between the network and cellular devices are two fundamental security features in LTE and IMS networks. The first is implemented via authentication and key agreement mechanisms and can be compromised by relaying authentication parameters. The second security feature builds on the first one and is activated through corresponding security setup procedures. This work intends to investigate whether these basic security procedures are securely implemented and deployed in commercial networks. We analyzed the de facto situation of these security features in three major operators in China and found several new and previously disclosed configuration and implementation flaws that do not conform to specifications. These vulnerabilities allow attackers to disable LTE and IMS data protection mechanisms. We further propose novel proof-of-concept attacks to exploit the identified vulnerabilities includingIMEIandPhone Number Catching,SMSandCall ImpersonationandInterceptionattacks. To show the urgency of addressing these security issues and thus secure the real-world telecom networks, we successfully demonstrated these attacks in practice using open-source SDR tools as they have serious implications. For instance, the interception attacks undermine the widely-used SMS verification code security mechanism. We also discuss countermeasures to resist the proposed attacks.
Chuan Yu 0003, Shuhui Chen, Ziling Wei, Fei Wang 0076
IEEE Trans. Dependable Secur. Comput.1
2023 SecChecker: Inspecting the security implementation of 5G Commercial Off-The-Shelf (COTS) mobile devices
Chuan Yu 0003, Shuhui Chen, Ziling Wei, Fei Wang 0076
Comput. Secur.1
2021 Improving 4G/5G air interface security: A survey of existing attacks on different LTE layers
Chuan Yu 0003, Shuhui Chen, Fei Wang 0076, Ziling Wei
Comput. Networks1
2019 On Effects of Mobility Management Signalling Based DoS Attacks Against LTE Terminals
abstract
Long Term Evolution (LTE) has become the most mature and stable mobile communication network technology worldwide so far. Billions of mobile subscribers are using LTE networks to surf the Internet, make phone calls, and send text messages every day. Meanwhile, Denial-of- Service (DoS) attacks seriously threaten the availability of LTE networks. In this paper, we focus on the research into the effects of reject signalling based DoS attacks against LTE terminals. We revealed a new DoS attack vulnerability in the authentication procedure after a detailed exploration in 3GPP standard specifications and verified it using software radio tools. Moreover, we specifically tested the impacts of such device-targeted DoS attacks on users under different test conditions (e.g. different operators, chip vendors, etc and we classified the actual test results into 6 different impact levels to better evaluate the effects on subscribers. Several possible countermeasures are also discussed to defend the attacks.
Chuan Yu 0003, Shuhui Chen
IPCCC1
2019 LTE Phone Number Catcher: A Practical Attack against Mobile Privacy
abstract
Phone number is a unique identity code of a mobile subscriber, which plays a more important role in the mobile social network life than another identification number IMSI. Unlike the IMSI, a mobile device never transmits its own phone number to the network side in the radio. However, the mobile network may send a user’s phone number to another mobile terminal when this user initiating a call or SMS service. Based on the above facts, with the help of an IMSI catcher and 2G man-in-the-middle attack, this paper implemented a practicable and effective phone number catcher prototype targeting at LTE mobile phones. We caught the LTE user’s phone number within a few seconds after the device camped on our rogue station. This paper intends to verify that mobile privacy is also quite vulnerable even in LTE networks as long as the legacy GSM still exists. Moreover, we demonstrated that anyone with basic programming skills and the knowledge of GSM/LTE specifications can easily build a phone number catcher using SDR tools and commercial off-the-shelf devices. Hence, we hope the operators worldwide can completely disable the GSM mobile networks in the areas covered by 3G and 4G networks as soon as possible to reduce the possibility of attacks on higher-generation cellular networks. Several potential countermeasures are also discussed to temporarily or permanently defend the attack.
Chuan Yu 0003, Shuhui Chen, Zhiping Cai
Secur. Commun. Networks1