We provide professional Training for companies in the telecommunications industry

LTE/IMS/UMTS/GSM User-Network Security

Duration: 2 days
Available as: in-company and public course
Target audience: engineers
Public course:

Who Should Attend
The course is intended for security engineers and developers of GSM/UMTS/LTE/IMS security functions and anyone who needs system-wide technical knowledge on 3GPP mobile network access security.


Course Scope

  1. GSM
    • user identity confidentiality:
      • identifying method,
      • IMSI, TMSI,
      • successful/unsuccessful TMSI reallocation,
      • IMSI/TMSI exchange at inter MSC location update,
      • identification by permanent identity,
    • authentication:
      • AuC/HLR and SIM structure,
      • parameters,
      • generation of Authentication Vectors - AVs,
      • procedure,
      • authentication during a malfunction of the network,
      • re-use of security related information in failure situations,
    • ciphering:
      • user data confidentiality,
      • signalling information element confidentiality,
      • ciphering method,
      • key setting,
      • starting of the ciphering processes,
      • Ciphering Key Sequence Number - CKSN,
      • support of A5 algorithms in MS,
      • negotiation of A5 algorithm,
      • handover,
    • equipment check:
      • composition of IMEI/IMEISV,
      • use of the EIR,
      • procedure,
    • subscription verification,
    • international roaming,
  2. GERAN based GPRS
    • user identity confidentiality,
    • P-TMSI,
    • P-TMSI signature,
    • authentication,
    • ciphering,
    • equipment check,
    • subscription verification,
    • authentication towards PDN,
    • international roaming,
  3. UMTS
    • user identity confidentiality,
    • entity authentication:
      • user authentication,
      • network authentication,
      • Authentication and Key Agreement - AKA,
      • AuC/HLR and (U)SIM structure,
      • parameters,
      • generation of Authentication Vectors - AVs,
      • Sequence Numbers - SQNs,
      • synchronisation failure,
      • re-synchronisation procedure,
      • reporting authentication failures,
    • ciphering:
      • cipher key and integrity key setting,
      • ciphering and integrity mode negotiation,
      • Key Set Identifier - KSI,
      • cipher key and integrity key lifetime,
      • security mode set-up procedure,
      • ciphering method,
    • signalling integrity:
      • integrity protection method,
      • successful / unsuccessful integrity check,
    • UMTS - GSM interworking:
      • UMTS subscriber connected to GERAN,
      • GSM subscribers connected to UTRAN,
      • UTRAN to GERAN CS handover,
      • GERAN to UTRAN CS handover,
      • UTRAN to GERAN PS system change,
      • GERAN to UTRAN PS change,
  4. LTE/EPS
    • user identity confidentiality:
      • identifying method,
      • GUTI,
      • successful / unsuccessful GUTI reallocation,
      • IMSI/GUTI exchange at inter MME location update,
      • identification by permanent identity,
    • authentication:
      • user authentication,
      • network authentication,
      • Authentication and Key Agreement - AKA,
      • HSS and USIM structure,
      • USIM R99, USIM R8,
      • EPS and UMTS security context conflict with USIM R99 - R7,
      • parameters,
      • generation of Authentication Vectors - AVs,
      • Sequence Numbers - SQNs,
      • synchronisation failure,
      • re-synchronisation procedure,
      • reporting authentication failures,
      • EPS key hierarchy,
      • key distribution,
    • ciphering:
      • cipher key and integrity key setting,
      • ciphering and integrity mode negotiation for NAS and AS,
      • Key Set Identifier - KSI,
      • cipher key and integrity key lifetime,
      • security mode set-up procedure,
      • ciphering method,
      • key handling in intra-eNB/X2/S1 handover,
      • horizontal and vertical key derivation,
      • key-change-on-the-fly,
      • periodic local authentication,
    • signalling integrity,
    • E-UTRAN - UTRAN interworking:
      • idle mode mobility from E-UTRAN to UTRAN,
      • mapping of EPS security context to UMTS security context,
      • idle mode mobility from UTRAN to E-UTRAN,
      • handover from E-UTRAN to UTRAN,
      • handover from UTRAN to E-UTRAN,
      • AKA at IRAT-mobility to E-UTRAN,
    • E-UTRAN - GERAN interworking:
      • idle mode mobility from E-UTRAN to GERAN,
      • idle mode mobility from GERAN to E UTRAN,
      • handover from E-UTRAN to GERAN,
      • handover from GERAN to E UTRAN,
    • SRVCC from E-UTRAN to CS UTRAN/GERAN,
  5. IMS
    • authentication:
      • user authentication,
      • network authentication,
      • ISIM,
      • parameters,
      • IMS AKA and UMTS AKA,
      • procedure,
      • user/network authentication failure,
      • synchronisation failure,
      • ISIM and USIM security functions sharing,
    • signalling ciphering and integrity protection:
      • SIP and ESP,
      • security association set-up,
    • subscription verification,
    • international roaming,
  6. Network Domain Security overview (MAPsec, TCAPsec, IPsec).

Course Objectives
This training concentrates on the user-network security procedures, security key sets generation, key handling and security interworking between LTE/EPS, UMTS, GSM/GPRS and IMS.
The course does not cover cryptological analysis of the EPS security algorithms, fraud detection methods, possible attack scenarios nor security of the EPS internal network interfaces.


Pre-requisites

The participants should have attended the EPS/LTE Technology course or should have the general technical knowledge concerning any public digital mobile telecommunication system e.g. GSM/GPRS, UMTS, EPS, D-AMPS, cdmaOne, cdma2000.


Training Structure

Two days training divided into logical parts.

Methodology
Instructor led training.