The network architecture of GPRS [3] is presented in Fig-
ure 1. A GPRS user owns a Mobile Station (MS) that pro-
vides access to the wireless network. From the network
side, the Base Station Subsystem (BSS) is a network part
that is responsible for the control of the radio path. BSS
consists of two types of nodes: the Base Station Controller
(BSC) and the Base Transceiver Station (BTS). BTS is
responsible for the radio coverage of a given geographi-
cal area, while BSC maintains radio connections towards
MSs and terrestrial connections towards the fixed part of
the network (core network).
The GPRS Core Network (CN) uses the network el-
ements of GSM such as the Home Location Register
(HLR), the Visitor Location Register (VLR), the Au-
thentication Centre (AuC) and the Equipment Identity
Register (EIR). HLR is a database used for the man-
agement of permanent data of mobile users. VLR is a
database of the service area visited by an MS and contains
all the related information required for the MS service
handling. AuC maintains security information related to
subscribers identity, while EIR maintains information re-
lated to mobile equipments’ identity. Finally, the Mobile
Service Switching Centre (MSC) is a network element re-
sponsible for circuit-switched services (e.g., voice call) [3].
As presented previously, GPRS reuses the majority of
the GSM network infrastructure. However, in order to
build a packet-oriented mobile network some new network
elements (nodes) are required, which handle packet-based
traffic. The new class of nodes, called GPRS support
nodes (GSN), is responsible for the delivery and routing
of data packets between a MS and an external packet data
network (PDN). More specifically, a Serving GSN (SGSN)
is responsible for the delivery of data packets from, and
to, a MS within its service area. Its tasks include packet
routing and transfer, mobility management, logical link
management, and authentication and charging functions.
A Gateway GSN (GGSN) acts as an interface between
the GPRS backbone and an external PDN. It converts
the GPRS packets coming from the SGSN into the ap-
propriate packet data protocol (PDP) format (e.g., IP),
and forwards them to the corresponding PDN. Similar is
the functionality of GGSN in the opposite direction. The
communication between GSNs (i.e., SGSN and GGSN) is
based on IP tunnels through the use of the GPRS Tun-
nelling Protocol (GTP).
In order to meet security objectives, GPRS employs a set
of security mechanisms that constitutes the GPRS secu-rity architecture.
of security mechanisms that constitutes the GPRS secu-rity architecture.
Most of these mechanisms have been
originally designed for GSM, but they have been modi-
fied to adapt to the packet-oriented traffic nature and the
GPRS network components. The GPRS security architec-
ture, mainly, aims at two goals: a) to protect the network
against unauthorized access, and b) to protect the privacy
of users. It includes the following components [11]:
• Subscriber Identity Module (SIM);
• Subscriber identity confidentiality;
• Subscriber identity authentication;
• User data and signaling confidentiality between the
MS and the SGSN;
• GPRS backbone security.
originally designed for GSM, but they have been modi-
fied to adapt to the packet-oriented traffic nature and the
GPRS network components. The GPRS security architec-
ture, mainly, aims at two goals: a) to protect the network
against unauthorized access, and b) to protect the privacy
of users. It includes the following components [11]:
• Subscriber Identity Module (SIM);
• Subscriber identity confidentiality;
• Subscriber identity authentication;
• User data and signaling confidentiality between the
MS and the SGSN;
• GPRS backbone security.
No comments:
Post a Comment