A theoretical analysis of securing LTE backhaul network using host identity protocol

dc.contributor.authorWeliwita, C.S.
dc.contributor.authorKarunarathne, S.N.
dc.contributor.authorSandirigama, M.
dc.date.accessioned2024-12-18T09:47:38Z
dc.date.available2024-12-18T09:47:38Z
dc.date.issued2016-11-05
dc.description.abstractLong Term Evolution (LTE) is expected to provide end-to-end security with many other promising features. However, with unencrypted transmission in the backhaul network (network segment from evolved node B (eNB/eNodeB) to core network), end-to-end security guarantee is violated. Unlike in legacy standards, security standards for LTE do not specify backhaul security implementation and expects service providers to adapt backhaul security. Third Generation Partnership Project (3GPP) has recommended but not mandated implementing Internet Protocol Security (IPsec) with Internet Key Exchange v2 (IKEv2). Nevertheless, most vendors do not implement IPsec for on various reasons like implementation and maintenance cost, overhead, and lack of experience in security implementation. To assure end-to-end security, backhaul needs to be protected. In order to implement backhaul security, we proposed a new backhaul architecture using Host Identity Protocol (HIP) (HIP-LTE backhaul). HIP is capable of authenticating end nodes in the base exchange process and transmit Internet Protocol (IP) packets using Encapsulated Security Payload (ESP) transport mode by providing encryption and adding integrity protection as ESP – Bounded End to End Transmission (ESP-BEET) mode packets. A Security Gateway (SeGW) is used at the core network and backhaul network interface to work as one end node to reduce overload in HIP processing at core network nodes. eNBs and SeGW are the only nodes needed to implement HIP. We evaluated security of HIP-LTE backhaul network using analytical model based on ISO security architecture. In the study, we identified security mechanisms available and derived security services in HIP-LTE backhaul. Then we performed a compliance evaluation with 3GPP security requirements for LTE backhaul and found that all the security requirements are fulfilled by new architecture with additional security measures as resilience to DoS, MitM, Replay and flooding attacks. Thus HIP-LTE backhaul is capable of providing security in the backhaul segment without direct IPsec implementation. This reduces the operator effort to implement security in backhaul with less cost. HIP-LTE backhaul network can be used as an alternative in securing LTE backhaul networks.
dc.identifier.citationProceedings of the Peradeniya University International Research Sessions (iPURSE) – 2016, University of Peradeniya, P 285
dc.identifier.isbn978-955-589-225-4
dc.identifier.urihttps://ir.lib.pdn.ac.lk/handle/20.500.14444/5009
dc.language.isoen_US
dc.publisherUniversity of Peradeniya, Sri Lanka
dc.subjectLong Term Evolution
dc.subjectHost Identity Protocol
dc.subjectEncapsulated Security Payload
dc.subjectThird Generation Partnership Project
dc.subjectInternet Protocol Security
dc.titleA theoretical analysis of securing LTE backhaul network using host identity protocol
dc.typeArticle

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
iPURSE2016-pages [352].pdf
Size:
157.18 KB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed to upon submission
Description:

Collections