Loading...

Security Evaluation of Open5GS

Babavali, Yousef | 2025

7 Viewed
  1. Type of Document: M.Sc. Thesis
  2. Language: Farsi
  3. Document No: 58809 (19)
  4. University: Sharif University of Technology
  5. Department: Computer Engineering
  6. Advisor(s): Bayat Sarmadi, Siavash
  7. Abstract:
  8. Fifth-generation mobile data networks are revolutionizing the way we communicate, work, and live. This generation of mobile data promises higher speeds, lower latency ,and greater capacity compared to previous generations. The technology is widely used to build private networks, and a variety of open-source and commercial implementations for its components have been developed. These implementations serve a broad spectrum of users, including academic, laboratory, and industrial environments. Despite its groundbreaking capabilities, service-based 5G networks face serious internal security threats such as identity spoofing and unauthorized access to network functions. Attackers who exploit vulnerabilities in core implementations may gain unauthorized control over network resources or render them unavailable. Consequently ,security evaluation of these networks is critically important. Open-source cores form a key element in constructing the private networks mentioned above. Ensuring interoperability across different platforms requires strict compliance with 3GPP standards. Open5GS is an open-source 5G core that conforms to 3GPP Release 17. This research concentrates on the security assessment of that platform. Based on assessment results —namely, critical gaps in the authentication and authorization of internal Open5GS functions— this study proposes a novel security framework aligned with 3GPP standards for core functions. The results of the proposed solution demonstrate a marked improvement in the network core’s resilience against request forgery and insider attacks. After applying these enhancements, attackers can no longer register with the core without authorization ,and all inter-function requests undergo proper authentication and authorization. This prevents attackers from forging requests to extract information. These methods were implemented without imposing fundamental changes on the infrastructure or 3GPP standards. Before-and-after comparisons confirm the effectiveness of this mechanism in Open5GS
  9. Keywords:
  10. Authentication ; Authorization ; Open5GS Platform ; Fifth Generation Core (5GC) ; Security Evaluation

 Digital Object List

 Bookmark

  • مقدمه
    • نسل پنجم شبکه‌ی داده‌ی سیار
    • امنیت در هسته‌ی نسل پنجم
    • اهداف پژوهش صورت گرفته
    • ساختار پایان‌نامه
  • مفاهیم اولیه
    • شبکه‌ی داده‌ی سیار
    • نسل‌های شبکه‌ی داده‌ی سیار
      • نسل اول: آغاز آنالوگ
      • نسل دوم:انقلاب دیجیتال و استانداردهای جهانی
      • نسل سوم: تحرک پذیری، باند پهن و پیام‌های چندرسانه‌ای
      • نسل چهارم: عصر LTE
      • نسل پنجم: رادیوی جدید
      • مقایسه نسل‌های شبکه
    • تکامل نسل پنجم: نسخه‌های شبکه
      • نسخه ۱۵ 3GPP: استاندارد پایه نسل پنجم
      • نسخه ۱۶ 3GPP: گسترش دامنه عمودی شبکه
      • نسخه ۱۷ 3GPP: تنوع‌بخشی به کاربردها و اکوسیستم دستگاه‌ها
      • نسخه ۱۸ 3GPP: آغاز نسل پنجم پیشرفته
    • هسته شبکه نسل پنجم و عملگرهای آن
      • معماری مبتنی بر سرویس
      • عملگرهای هسته
    • معرفی و مقایسه بسترهای متن باز نسل پنجم
  • کارهای پیشین
    • تحلیل باندپایه
    • کشف و تحلیل آسیب‌پذیری
      • تست داده‌های تصادفی
      • حمله به لایه‌های پایین شبکه
      • حمله سیگنال مخفی‌
      • شنود غیرمجاز
      • حملات پیامکی
      • ردیابی کاربران شبکه
      • امنیت سیم‌کارت
      • حملات صفحه‌داده
      • اثرانگشت‌برداری
    • تحقیقات در حوزه دفاع
      • تغییر پروتکل
      • دفاع در دستگاه کاربر و شناسایی ایستگاه پایه جعلی
    • تحقیقات امنیتی در حوزه O-RAN
    • امنیت قطعه‌بندی شبکه
    • امنیت هسته شبکه‌های سیار
      • ارزیابی امنیت و شناسایی آسیب‌پذیری‌ها در هسته نسل پنج
      • چهارچوب‌های آزمون امنیتی خودکار و تحلیل پروتکل
      • راه‌حل‌های امنیتی و بهبودهای معماری برای هسته نسل پنج
  • استانداردهای احرازهویت و مجازشماری ‌
    • تعاریف بنیادی: احرازهویت و مجازشماری
      • احرازهویت
      • مجازشماری
    • معرفی استانداردهای مدیریت هویت
      • زبان نشانه‌گذاری تأیید امنیتی (SAML)
      • مجازشماری باز (OAuth)
      • Connect OpenID (OIDC)
    • مقایسه استاندارد‌ها
      • مقایسه بر اساس هدف و معماری
      • مقایسه فنی و امنیتی
    • انتخاب استاندارد مجازشماری برای هسته نسل پنجم
  • روش پیشنهادی
    • ثبت‌نام امن
    • احراز هویت مبتنی بر تصدیق اعتبارنامه مشتری (CCA)
      • شیوه استفاده و چهارچوب
      • محتوای توکن CCA
      • مدت عمر CCA
      • فرآیند بررسی
      • رسیدگی به خطاها
    • مجازشماری در هسته نسل پنجم
      • اهداف مجازشماری
      • نقش‌های چهارچوب مجازشماری OAuth 2.0 و ادغام آن در اجزای هسته
      • فرآیند مجازشماری مبتنی بر توکن
      • ارسال درخواست سرویس همراه توکن و اعتبارسنجی توسط تولیدکننده
  • نتایج
    • ثبت‌نام امن
    • احراز هویت
    • مجازشماری
    • جمع‌بندی نتایج
  • جمع‌بندی و نتیجه‌گیری
  • مراجع
  • واژه‌نامه
...see more