{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,4]],"date-time":"2026-07-04T16:17:02Z","timestamp":1783181822532,"version":"3.54.6"},"publisher-location":"New York, NY, USA","reference-count":40,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,12,6]],"date-time":"2021-12-06T00:00:00Z","timestamp":1638748800000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["2051621"],"award-info":[{"award-number":["2051621"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,12,6]]},"DOI":"10.1145\/3485832.3485833","type":"proceedings-article","created":{"date-parts":[[2021,12,6]],"date-time":"2021-12-06T13:42:32Z","timestamp":1638798152000},"page":"877-886","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":9,"title":["On Key Reinstallation Attacks over 4G LTE Control-Plane: Feasibility and Negative Impact"],"prefix":"10.1145","author":[{"given":"Muhammad Taqi","family":"Raza","sequence":"first","affiliation":[{"name":"The University of Arizona, United States of America"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yunqi","family":"Guo","sequence":"additional","affiliation":[{"name":"UCLA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Songwu","family":"Lu","sequence":"additional","affiliation":[{"name":"UCLA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Fatima Muhammad","family":"Anwar","sequence":"additional","affiliation":[{"name":"UMASS Amherst"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,12,6]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"[n.d.]. IntelliJudge: WaveJudge LTE packets sniffer. http:\/\/www.sanjole.com\/our-products\/intellijudge-lte\/."},{"key":"e_1_3_2_1_2_1","unstructured":"[n.d.]. QPST\u2014 Qualcomm service programmer tool. https:\/\/github.com\/botletics\/SIM7000-LTE-Shield\/tree\/master\/SIM7000%20Documentation\/Firmware%20Updater%20Tool\/QPST%20Tool."},{"key":"e_1_3_2_1_3_1","unstructured":"[n.d.]. QXDM\u2013 LTE packets capturing tool."},{"key":"e_1_3_2_1_4_1","unstructured":"[n.d.]. Tera-Term-A Terminal Emulator. http:\/\/ttssh2.sourceforge.jp\/index.html.en."},{"key":"e_1_3_2_1_5_1","unstructured":"[n.d.]. ThinkRF: Real-Time Spectrum Analyzer. https:\/\/www.thinkrf.com\/real-time-spectrum-analyzers\/."},{"key":"e_1_3_2_1_6_1","first-page":"24301","volume-title":"Non-Access-Stratum (NAS) protocol for Evolved Packet System (EPS)","unstructured":"3GPP. 2016. TS24.301: Non-Access-Stratum (NAS) protocol for Evolved Packet System (EPS); Stage 3. http:\/\/www.3gpp.org\/ftp\/Specs\/html-info\/24301.htm"},{"key":"e_1_3_2_1_7_1","volume-title":"3GPP SAE","unstructured":"3GPP. 2016. TS33.401: 3GPP SAE; Security architecture."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"crossref","unstructured":"pages=78\u201392 year=2011\u00a0organization=Springer Aumasson Jean-Philippe et al. booktitle=International Conference on Information and Communications Security. [n.d.]. A note on a privacy-preserving distance-bounding protocol.","DOI":"10.1007\/978-3-642-25243-3_7"},{"key":"e_1_3_2_1_9_1","volume-title":"Benjamin and et al. [n.d.]. A messy state of the union: Taming the composite state machines of TLS","author":"Beurdouche","year":"2015","unstructured":"Beurdouche, Benjamin and et al. [n.d.]. A messy state of the union: Taming the composite state machines of TLS. In IEEE Security and Privacy, year=2015."},{"key":"e_1_3_2_1_10_1","first-page":"475","article-title":"Nonce-Disrespecting Adversaries: Practical Forgery Attacks on GCM in TLS.","volume":"2016","author":"B\u00f6ck Hanno","year":"2016","unstructured":"B\u00f6ck, Hanno and et al. 2016. Nonce-Disrespecting Adversaries: Practical Forgery Attacks on GCM in TLS.IACR Cryptology ePrint Archive 2016 (2016), 475.","journal-title":"IACR Cryptology ePrint Archive"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"crossref","unstructured":"Borisov Nikita and Goldberg Ian and Wagner David. 2001. Intercepting mobile communications: the insecurity of 802.11. In ACM Mobicom.","DOI":"10.1145\/381677.381695"},{"key":"e_1_3_2_1_12_1","volume-title":"USENIX Security Symposium.","author":"De Ruiter Joeri","year":"2015","unstructured":"De Ruiter, Joeri and Poll, Erik. 2015. Protocol State Fuzzing of TLS Implementations.. In USENIX Security Symposium."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"crossref","unstructured":"Hong Byeongdo and et al.2018. GUTI Reallocation Demystified: Cellular Location Tracking with Changing Temporary Identifier. (2018).","DOI":"10.14722\/ndss.2018.23349"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"crossref","unstructured":"Hussain Syed Rafiul and et al.2018. LTEInspector: A Systematic Approach for Adversarial Testing of 4G LTE. In NDSS.","DOI":"10.14722\/ndss.2018.23313"},{"key":"e_1_3_2_1_15_1","volume-title":"The codebreakers","author":"Kahn David","year":"1996","unstructured":"Kahn, David. 1996. The codebreakers. New York, NY: Scribner(1996)."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"crossref","unstructured":"Karlof Chris and Sastry Naveen and Wagner David. 2004. TinySec: a link layer security architecture for wireless sensor networks. In ACM SenSys.","DOI":"10.1145\/1031495.1031515"},{"key":"e_1_3_2_1_17_1","volume-title":"Hongil and et al","author":"Kim","year":"2015","unstructured":"Kim, Hongil and et al. 2015. Breaking and fixing volte: Exploiting hidden data channels and mis-implementations. In ACM CCS."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"crossref","unstructured":"Li Chi-Yu and et al.2015. Insecurity of voice solution volte in LTE mobile networks. In ACM CCS.","DOI":"10.1145\/2810103.2813618"},{"key":"e_1_3_2_1_19_1","volume-title":"Marc and et al.2014. Detection and mitigation of uplink control channel jamming in LTE","author":"Lichtman","unstructured":"Lichtman, Marc and et al.2014. Detection and mitigation of uplink control channel jamming in LTE. In IEEE Milcom."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/MCOM.2016.7452266"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"crossref","unstructured":"Mason Joshua and et al.2006. A natural language approach to automated cryptanalysis of two-time pads. In ACM CCS.","DOI":"10.1145\/1180405.1180435"},{"key":"e_1_3_2_1_22_1","unstructured":"MM Galib Asadullah. 2008. Robust wireless communications under co-channel interference and jamming. Ph.D. Dissertation. Georgia Institute of Technology PhD thesis."},{"key":"e_1_3_2_1_23_1","unstructured":"Naseef M. 2014. Vulnerabilities of LTE and LTE-Advanced Communication White Paper. (2014)."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"crossref","unstructured":"Peng Chunyi and et al.2012. Mobile data charging: new attacks and countermeasures. In ACM CCS.","DOI":"10.1145\/2382196.2382220"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"crossref","unstructured":"Peng Chunyi and et al.2014. Real threats to your data bills: Security loopholes and defenses in mobile data charging. In ACM CCS.","DOI":"10.1145\/2660267.2660346"},{"key":"e_1_3_2_1_26_1","volume-title":"Off-path TCP sequence number inference attack-how firewall middleboxes reduce security","author":"Qian Zhiyun","unstructured":"Qian, Zhiyun and Mao, Z Morley. [n.d.]. Off-path TCP sequence number inference attack-how firewall middleboxes reduce security. In IEEE S&P."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"crossref","unstructured":"Raza Muhammad Taqi and et al.2017. Exposing LTE Security Weaknesses at Protocol Inter-layer and Inter-radio Interactions. In SecureComm.","DOI":"10.1007\/978-3-319-78813-5_16"},{"key":"e_1_3_2_1_28_1","volume-title":"29th {USENIX} Security Symposium ({USENIX} Security 20). 73\u201388.","author":"David Rupprecht Katharina Kohls","unstructured":"David Rupprecht, Katharina Kohls, Thorsten Holz, and Christina P\u00f6pper. 2020. Call Me Maybe: Eavesdropping Encrypted {LTE} Calls With ReVoLTE. In 29th {USENIX} Security Symposium ({USENIX} Security 20). 73\u201388."},{"key":"e_1_3_2_1_29_1","volume-title":"David and et al.2018. Breaking LTE on Layer Two","author":"Rupprecht","unstructured":"Rupprecht, David and et al.2018. Breaking LTE on Layer Two. In IEEE S&P."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"crossref","unstructured":"Shaik Altaf and et al.2015. Practical attacks against privacy and availability in 4G\/LTE mobile communication systems. (2015).","DOI":"10.14722\/ndss.2016.23236"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1002\/j.1538-7305.1948.tb01338.x"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"crossref","unstructured":"Stubblefield Adam and et al.2004. A key recovery attack on the 802.11 b wired equivalent privacy protocol (WEP). ACM transactions on information and system security (TISSEC) 7 2(2004) 319\u2013332.","DOI":"10.1145\/996943.996948"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"crossref","unstructured":"Tu Guan-Hua and et al.2013. How voice calls affect data in operational LTE networks. In ACM MobiCom.","DOI":"10.1145\/2500423.2500429"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2015.2404336"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"crossref","unstructured":"Vanhoef Mathy and Piessens Frank. 2017. Key reinstallation attacks: Forcing nonce reuse in WPA2. In ACM CCS.","DOI":"10.1145\/3133956.3134027"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-46035-7_35"},{"key":"e_1_3_2_1_37_1","volume-title":"Secret signaling system (U","author":"Vernam Gilbert Sandford","year":"1919","unstructured":"Vernam, Gilbert Sandford. [n.d.]. Secret signaling system (U, 1919). U.S. Patent 131071([n. d.])."},{"key":"e_1_3_2_1_38_1","volume-title":"Qiben and et al","author":"Yan","year":"2014","unstructured":"Yan, Qiben and et al. 2014. MIMO-based jamming resilient communication in wireless networks. In IEEE Infocom."},{"key":"e_1_3_2_1_39_1","volume-title":"Huacheng and et al","author":"Zeng","year":"2017","unstructured":"Zeng, Huacheng and et al. 2017. Enabling jamming-resistant communications in wireless MIMO networks. In IEEE CNS."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-04474-8_33"}],"event":{"name":"ACSAC '21: Annual Computer Security Applications Conference","location":"Virtual Event USA","acronym":"ACSAC '21"},"container-title":["Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3485832.3485833","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3485832.3485833","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3485832.3485833","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T19:15:21Z","timestamp":1755890121000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3485832.3485833"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,12,6]]},"references-count":40,"alternative-id":["10.1145\/3485832.3485833","10.1145\/3485832"],"URL":"https:\/\/doi.org\/10.1145\/3485832.3485833","relation":{},"subject":[],"published":{"date-parts":[[2021,12,6]]},"assertion":[{"value":"2021-12-06","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}