Shahabuddin, Rahaman, Rehman, Ahmad, and Khan
26
reason, in 4G networks, extra security mechanisms are expected to be carried out to
provide the security for reliable communication.
The major concern in 4G security naturally includes that the user who wants to
access the network must be authenticated along with the device that will be connected to the network. For this reason, security credentials, identity, certificates,
username and password, are used for authentication. If we draw a comparison, starting from 2G when security was started to be taken as a major concern in cellular
networks, a unique ID is used on the SIM card in 2G. While in 3G and 4G LTE,
temporary ID and further abstraction is used to limit the possibilities of any sort of
intrusion. In 4G, further secure signaling between the UE and MME (Mobile
Management Entity) is introduced, and also security measures are taken care of
between 3GPP and trusted non‐3GPP users. As mentioned before, because of operating of open IP‐based architecture, security remains the pressing concern in 4G
cellular, and is given strong emphasis. It is important to point out that LTE‐ and
LTE‐Advanced are the same technologies. The label “Advanced” was primarily added
to highlight the relationship between LTE release 10 (LTE‐Advanced) and ITU/IMT‐
Advanced. This does not make LTE‐Advanced a different system from LTE [3,28].
1.7.4 LTE Security Model
Figure 1.12 shows the authentication method of LTE with step‐by‐step details.
The authentication process in LTE is initiated by the authentication server when it
sends Enhance Authentication Protocol request/Identity message (EAP) to the UE. The
UE responds by replying to the EAP‐response/Identity message containing the identity
message and Network Access Identifier (NAI). Upon receipt of the EAP‐response/
identity message, the authentication server tried to access the UE’s certificate from
its record. The authentication server generates the EAP‐Request/Authentication
and Key Agreement (AKA)‐Challenge message using the standard AKA process.
Certificate Record
Retrieve peer’s certificate
by identity
EAP response/Identity(Identity, NAI)
EAP-Request/Identity
EAP-Request/AKA-Challenge(Encrypted
by peer’s public key)
EAP-Response/AKA-Challenge
(Encrypted by EAP server’s public key)
EAP-Success(Result, KEY)
LTE Authentication
server
LTE UE
Figure 1.12 Authentication Process in LTE.
26
reason, in 4G networks, extra security mechanisms are expected to be carried out to
provide the security for reliable communication.
The major concern in 4G security naturally includes that the user who wants to
access the network must be authenticated along with the device that will be connected to the network. For this reason, security credentials, identity, certificates,
username and password, are used for authentication. If we draw a comparison, starting from 2G when security was started to be taken as a major concern in cellular
networks, a unique ID is used on the SIM card in 2G. While in 3G and 4G LTE,
temporary ID and further abstraction is used to limit the possibilities of any sort of
intrusion. In 4G, further secure signaling between the UE and MME (Mobile
Management Entity) is introduced, and also security measures are taken care of
between 3GPP and trusted non‐3GPP users. As mentioned before, because of operating of open IP‐based architecture, security remains the pressing concern in 4G
cellular, and is given strong emphasis. It is important to point out that LTE‐ and
LTE‐Advanced are the same technologies. The label “Advanced” was primarily added
to highlight the relationship between LTE release 10 (LTE‐Advanced) and ITU/IMT‐
Advanced. This does not make LTE‐Advanced a different system from LTE [3,28].
1.7.4 LTE Security Model
Figure 1.12 shows the authentication method of LTE with step‐by‐step details.
The authentication process in LTE is initiated by the authentication server when it
sends Enhance Authentication Protocol request/Identity message (EAP) to the UE. The
UE responds by replying to the EAP‐response/Identity message containing the identity
message and Network Access Identifier (NAI). Upon receipt of the EAP‐response/
identity message, the authentication server tried to access the UE’s certificate from
its record. The authentication server generates the EAP‐Request/Authentication
and Key Agreement (AKA)‐Challenge message using the standard AKA process.
Certificate Record
Retrieve peer’s certificate
by identity
EAP response/Identity(Identity, NAI)
EAP-Request/Identity
EAP-Request/AKA-Challenge(Encrypted
by peer’s public key)
EAP-Response/AKA-Challenge
(Encrypted by EAP server’s public key)
EAP-Success(Result, KEY)
LTE Authentication
server
LTE UE
Figure 1.12 Authentication Process in LTE.
