Watching your call: Breaking VoLTE Privacy in LTE/5G Networks
Zishuai Cheng, Mihai Ordean, Flavio D. Garcia, Baojiang Cui, Dominik, Rys

TL;DR
This paper demonstrates a novel privacy attack on LTE/5G networks that can recover call details and link identifiers to phone numbers using a mobile-relay adversary, exposing vulnerabilities in VoLTE/NR privacy protections.
Contribution
The authors introduce a new undetectable mobile-relay attack that can analyze encrypted LTE/5G traffic to recover VoLTE/NR call details and link network identifiers to phone numbers.
Findings
Successfully recovered call details with 100% accuracy
Linked network identifiers to phone numbers undetected
Validated attack on four modern smartphones and two network carriers
Abstract
Voice over LTE (VoLTE) and Voice over NR (VoNR) are two similar technologies that have been widely deployed by operators to provide a better calling experience in LTE and 5G networks, respectively. The VoLTE/NR protocols rely on the security features of the underlying LTE/5G network to protect users' privacy such that nobody can monitor calls and learn details about call times, duration, and direction. In this paper, we introduce a new privacy attack which enables adversaries to analyse encrypted LTE/5G traffic and recover any VoLTE/NR call details. We achieve this by implementing a novel mobile-relay adversary which is able to remain undetected by using an improved physical layer parameter guessing procedure. This adversary facilitates the recovery of encrypted configuration messages exchanged between victim devices and the mobile network. We further propose an identity mapping method…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInternet Traffic Analysis and Secure E-voting · Advanced Authentication Protocols Security · Wireless Communication Security Techniques
