战场5G:面向战术5G独立组网的基于双PKI与TPM的用户设备认证
Battlefield 5G: Dual-PKI and TPM-Based UE Attestation for Tactical 5G Standalone Networks
浏览论文内容
中文总结 AI 辅助
本文针对战术5G组网的设备认证缺陷,提出Battlefield 5G预认证框架,结合双X.509证书检查与TPM启动认证,可阻断多种攻击,仅增加少量接入延迟开销。
中文摘要 AI 辅助
标准化5G认证与密钥协商(5G-AKA)会对通用用户身份模块(USIM)中存储的用户凭证进行认证,但不会对持有该凭证的物理设备进行认证,也不会验证其启动状态。这一缺陷在战术5G部署中尤为突出,因为用户设备可能被捕获、篡改、重新投入使用,或与移植的用户凭证搭配使用。本文提出Battlefield 5G,这是一种面向5G独立组网的预认证框架,结合双X.509设备证书检查与基于可信平台模块(TPM)的启动状态认证,再接受标准注册流程。该设计在5G基站(gNB)处设置外部证书质询,在5G核心网的接入与移动性管理功能(AMF)处设置独立的内部证书质询,同时由5G核心网侧的认证代理验证TPM平台配置寄存器(PCR)引用。gNB侧的无线资源控制(RRC)转发门与AMF侧的保存重放机制,可在不修改任何3GPP非接入层(NAS)消息结构或新增NAS消息类型的前提下,将多轮证书与认证质询应答交换插入注册路径。我们通过扩展软件无线电系统(srsRAN)的无线接入网、gNB、软件无线电系统用户设备(srsUE),并在基于B210的通用无线电外设(USRP)测试平台中集成UE端硬件TPM 2.0,同时结合Open5GS实现上述功能。该原型可阻断SIM移植、恶意证书、固件篡改及重放攻击。在6次测试中,Battlefield 5G将平均接入延迟从1886毫秒提升至2260毫秒,增加了373.4毫秒的预认证开销,同时保留了标准5G-AKA、安全模式及分组数据单元(PDU)会话流程。
英文摘要
The standardized 5G Authentication and Key Agreement (5G-AKA) authenticates a subscriber credential stored on a Universal Subscriber Identity Model (USIM) but does not authenticate the physical device that holds that credential or verify its boot state. This gap is significant in tactical 5G deployments, where user equipment may be captured, modified, returned to service, or used with transplanted subscriber credentials. We present Battlefield 5G, a pre-authentication framework for 5G Standalone networks that combines dual X.509 device-certificate checks with Trusted Platform Module (TPM) -based boot attestation before standard registration is accepted. The design places an outer certificate challenge on the 5G base-station called gNB, an independent inner certificate challenge on the Access and Mobility Management Function (AMF) in the 5G core network, and a TPM PCR (Platform Configuration Register) quote verified by an attestation proxy on the 5G core network side. A gNodeB (gNB) side Radio Resource Control (RRC) forwarding gate and an AMF-side save-and-replay mechanism enable multi-round certificate and attestation challenge-response exchanges to be inserted into the registration path without modifying any 3GPP Non-Access Stratum (NAS) message structures or adding new NAS message types. We implement these capabilities by extending the Radio Access Network of the Software Radio System (srsRAN), gNB, User Equipment of the Software Radio System (srsUE) and Open5GS in a B210-based Universal Radio Peripheral (USRP) testbed with a hardware TPM 2.0 in the UE. The prototype blocks SIM-transplant, rogue-certificate, firmware-tampering, and replay attacks. Across six trials, Battlefield 5G increases average onboarding latency from 1886 ms to 2260 ms, adding 373.4 ms of pre-authentication overhead while preserving standard 5G-AKA, security mode, and packet data unit (PDU) session procedures.