Search papers, labs, and topics across Lattice.
This paper introduces Battlefield 5G, a pre-authentication framework for 5G Standalone networks that enhances security by integrating dual X.509 device-certificate checks and Trusted Platform Module (TPM)-based boot attestation. This approach addresses critical vulnerabilities in tactical 5G deployments, where user equipment can be compromised, by ensuring both the device's identity and its boot state are verified before registration. The implementation, tested on a B210-based Universal Radio Peripheral testbed, effectively mitigates risks such as SIM-transplant and firmware-tampering attacks, albeit with a modest increase in onboarding latency.
Battlefield 5G blocks SIM-transplant and rogue-certificate attacks while only adding 373.4 ms to onboarding latency, proving that enhanced security can be achieved without sacrificing efficiency.
The standardized 5G Authentication and Key Agreement (5G-AKA) authenticates a subscriber credential stored on a Universal Subscriber Identity Model (USIM) but does not authenticate the physical device that holds that credential or verify its boot state. This gap is significant in tactical 5G deployments, where user equipment may be captured, modified, returned to service, or used with transplanted subscriber credentials. We present Battlefield 5G, a pre-authentication framework for 5G Standalone networks that combines dual X.509 device-certificate checks with Trusted Platform Module (TPM) -based boot attestation before standard registration is accepted. The design places an outer certificate challenge on the 5G base-station called gNB, an independent inner certificate challenge on the Access and Mobility Management Function (AMF) in the 5G core network, and a TPM PCR (Platform Configuration Register) quote verified by an attestation proxy on the 5G core network side. A gNodeB (gNB) side Radio Resource Control (RRC) forwarding gate and an AMF-side save-and-replay mechanism enable multi-round certificate and attestation challenge-response exchanges to be inserted into the registration path without modifying any 3GPP Non-Access Stratum (NAS) message structures or adding new NAS message types. We implement these capabilities by extending the Radio Access Network of the Software Radio System (srsRAN), gNB, User Equipment of the Software Radio System (srsUE) and Open5GS in a B210-based Universal Radio Peripheral (USRP) testbed with a hardware TPM 2.0 in the UE. The prototype blocks SIM-transplant, rogue-certificate, firmware-tampering, and replay attacks. Across six trials, Battlefield 5G increases average onboarding latency from 1886 ms to 2260 ms, adding 373.4 ms of pre-authentication overhead while preserving standard 5G-AKA, security mode, and packet data unit (PDU) session procedures.