EDBT 2026 Demo / reviewers in the wild / expert
Chuan Yu 0003
dblp:50/790-3
· DBLP profile ↗
6ranked-venue papers
6as first author
4since 2021 · last 2024
0000-0003-3616-5571ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 3 · 3 first-author · 2 since 2021Security and privacy · 3 · 3 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Protecting unauthenticated messages in LTE/5G mobile networks: A two-level Hierarchical Identity-Based Signature (HIBS) solution
Chuan Yu 0003, Shuhui Chen, Qianqian Xing, Ziling Wei |
Comput. Networks | 1 |
| 2024 | Toward a Truly Secure Telecom Network: Analyzing and Exploiting Vulnerable Security Configurations/ Implementations in Commercial LTE/IMS NetworksabstractAuthentication and data protection (both integrity and confidentiality) between the network and cellular devices are two fundamental security features in LTE and IMS networks. The first is implemented via authentication and key agreement mechanisms and can be compromised by relaying authentication parameters. The second security feature builds on the first one and is activated through corresponding security setup procedures. This work intends to investigate whether these basic security procedures are securely implemented and deployed in commercial networks. We analyzed the de facto situation of these security features in three major operators in China and found several new and previously disclosed configuration and implementation flaws that do not conform to specifications. These vulnerabilities allow attackers to disable LTE and IMS data protection mechanisms. We further propose novel proof-of-concept attacks to exploit the identified vulnerabilities includingIMEIandPhone Number Catching,SMSandCall ImpersonationandInterceptionattacks. To show the urgency of addressing these security issues and thus secure the real-world telecom networks, we successfully demonstrated these attacks in practice using open-source SDR tools as they have serious implications. For instance, the interception attacks undermine the widely-used SMS verification code security mechanism. We also discuss countermeasures to resist the proposed attacks. Chuan Yu 0003, Shuhui Chen, Ziling Wei, Fei Wang 0076 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | SecChecker: Inspecting the security implementation of 5G Commercial Off-The-Shelf (COTS) mobile devices
Chuan Yu 0003, Shuhui Chen, Ziling Wei, Fei Wang 0076 |
Comput. Secur. | 1 |
| 2021 | Improving 4G/5G air interface security: A survey of existing attacks on different LTE layers
Chuan Yu 0003, Shuhui Chen, Fei Wang 0076, Ziling Wei |
Comput. Networks | 1 |
| 2019 | On Effects of Mobility Management Signalling Based DoS Attacks Against LTE TerminalsabstractLong Term Evolution (LTE) has become the most mature and stable mobile communication network technology worldwide so far. Billions of mobile subscribers are using LTE networks to surf the Internet, make phone calls, and send text messages every day. Meanwhile, Denial-of- Service (DoS) attacks seriously threaten the availability of LTE networks. In this paper, we focus on the research into the effects of reject signalling based DoS attacks against LTE terminals. We revealed a new DoS attack vulnerability in the authentication procedure after a detailed exploration in 3GPP standard specifications and verified it using software radio tools. Moreover, we specifically tested the impacts of such device-targeted DoS attacks on users under different test conditions (e.g. different operators, chip vendors, etc and we classified the actual test results into 6 different impact levels to better evaluate the effects on subscribers. Several possible countermeasures are also discussed to defend the attacks. Chuan Yu 0003, Shuhui Chen |
IPCCC | 1 |
| 2019 | LTE Phone Number Catcher: A Practical Attack against Mobile PrivacyabstractPhone number is a unique identity code of a mobile subscriber, which plays a more important role in the mobile social network life than another identification number IMSI. Unlike the IMSI, a mobile device never transmits its own phone number to the network side in the radio. However, the mobile network may send a user’s phone number to another mobile terminal when this user initiating a call or SMS service. Based on the above facts, with the help of an IMSI catcher and 2G man-in-the-middle attack, this paper implemented a practicable and effective phone number catcher prototype targeting at LTE mobile phones. We caught the LTE user’s phone number within a few seconds after the device camped on our rogue station. This paper intends to verify that mobile privacy is also quite vulnerable even in LTE networks as long as the legacy GSM still exists. Moreover, we demonstrated that anyone with basic programming skills and the knowledge of GSM/LTE specifications can easily build a phone number catcher using SDR tools and commercial off-the-shelf devices. Hence, we hope the operators worldwide can completely disable the GSM mobile networks in the areas covered by 3G and 4G networks as soon as possible to reduce the possibility of attacks on higher-generation cellular networks. Several potential countermeasures are also discussed to temporarily or permanently defend the attack. Chuan Yu 0003, Shuhui Chen, Zhiping Cai |
Secur. Commun. Networks | 1 |