Enabling Physical Localization of Uncooperative Cellular Devices

Taekkyung Oh,Sangwook Bae,Junho Ahn,Yonghwa Lee,Tuan Dinh Hoang,Min Suk Kang,Nils Ole Tippenhauer,Yongdae Kim
2024-09-26
Abstract:In cellular networks, authorities may need to physically locate user devices to track criminals or illegal equipment. This process involves authorized agents tracing devices by monitoring uplink signals with cellular operator assistance. However, tracking uncooperative uplink signal sources remains challenging, even for operators and authorities. Three key challenges persist for fine-grained localization: i) devices must generate sufficient, consistent uplink traffic over time, ii) target devices may transmit uplink signals at very low power, and iii) signals from cellular repeaters may hinder localization of the target device. While these challenges pose significant practical obstacles to localization, they have been largely overlooked in existing research. This work examines the impact of these real-world challenges on cellular localization and introduces the Uncooperative Multiangulation Attack (UMA) to address them. UMA can 1) force a target device to transmit traffic continuously, 2) boost the target's signal strength to maximum levels, and 3) uniquely differentiate between signals from the target and repeaters. Importantly, UMA operates without requiring privileged access to cellular operators or user devices, making it applicable to any LTE network. Our evaluations demonstrate that UMA effectively overcomes practical challenges in physical localization when devices are uncooperative.
Cryptography and Security
What problem does this paper attempt to address?
The problem that this paper attempts to solve is: in a cellular network, how to physically locate uncooperative user equipment. Specifically, the paper focuses on the challenges faced by law - enforcement agencies and mobile network operators (MNOs) when tracking criminals or illegal devices, especially in the following three key issues: 1. **Insufficient Uplink Traffic** (C1): - The target device must generate sufficient and consistent uplink traffic over a period of time in order to be accurately located. If the target user equipment (UE) does not actively transmit uplink traffic, location will become impossible. 2. **Low Signal Power** (C2): - When the target device is close to the base station, its uplink signal power may be significantly reduced, especially in the case of dense base station deployment in urban environments, which will impede signal detection and location determination. 3. **Interference from Repeaters** (C3): - Cellular repeaters widely used in modern indoor environments will amplify and relay cellular signals, thereby introducing severe noise and affecting the determination of the target device's location. To address these challenges, the paper proposes a method named "Uncooperative Multiangulation Attack" (UMA). The main features of UMA are as follows: - **Applicability across the Network**: Unlike existing technologies, UMA not only relies on physical - layer measurements (such as Angle of Arrival (AoA), Time of Arrival (ToA), Timing Advance (TA)), but also addresses the systemic challenges overlooked when operating location techniques without device cooperation. - **Universality**: UMA can operate effectively in any LTE network that adheres to the core - mandatory standard features, without relying on optional features. - **End - to - End Capability**: UMA provides an open - end - to - end demonstration from the target phone number to its physical location, demonstrating the feasibility of fine - grained cellular location. Through UMA, the researchers have demonstrated a method that can manipulate downlink and uplink signals in real - time with existing limited operator support to achieve the physical location of uncooperative devices. Specifically, UMA includes two main methods: 1. **Scheduling Manipulation**: By simulating the target UE and reporting false data transmission requests to the eNB, ensure that the target device is always active and continuously transmits uplink traffic. 2. **Power Enhancement**: By injecting forged transmission power control commands, force the target UE to increase its uplink transmission power to the maximum level (23 dBm) to overcome the challenges brought by low signal power and repeater interference. In summary, this paper aims to identify the practical obstacles in cellular location, develop a universally applicable solution, and demonstrate a comprehensive process to achieve fine - grained physical location of uncooperative cellular devices.