Diffie-Hellman Picture Show: Key Exchange Stories from Commercial VoWiFi Deployments

Gabriel K. Gegenhuber (University of Vienna), Florian Holzbauer, Philipp É. Frenzel, Edgar Weippl, Adrian Dabrowski

33rd USENIX Security Symposium · Day 1 · USENIX Security '24 · USENIX Security '24

Overview

This talk, "Diffie-Hellman Picture Show," presented by Gabriel K. Gegenhuber from the University of Vienna, delves into the critical security landscape of Voice over Wi-Fi (VoWiFi), also known as Wi-Fi Calling. VoWiFi has become a preferred channel for mobile operators due to its cost-effectiveness and reliance on existing Wi-Fi infrastructure, making it a ubiquitous and essential service for millions of subscribers globally. The research uncovers significant vulnerabilities in the key exchange mechanisms underpinning VoWiFi security, exposing user communications to potential eavesdropping and decryption.

Watch on YouTube

Visual summary for Diffie-Hellman Picture Show: Key Exchange Stories from Commercial VoWiFi Deployments by Gabriel K. Gegenhuber, Florian Holzbauer, Philipp É. Frenzel, Edgar Weippl, Adrian Dabrowski
Visual summary for Diffie-Hellman Picture Show: Key Exchange Stories from Commercial VoWiFi Deployments by Gabriel K. Gegenhuber, Florian Holzbauer, Philipp É. Frenzel, Edgar Weippl, Adrian Dabrowski

Key moments

  1. 0:00 Introduction to VoWiFi and technical architecture
  2. 2:50 Initial finding: Diffie-Hellman Group 2 (1024-bit) weakness
  3. 4:00 How Diffie-Hellman group standards evolved over time
  4. 5:00 Real-world: Pre-loaded configs still use weak DH groups
  5. 6:00 Explaining the general Diffie-Hellman downgrade vulnerability
  6. 6:40 Severe MediaTek downgrade to arbitrary Diffie-Hellman groups
  7. 7:30 Servers widely support weak and even unspecified DH groups

Diffie-Hellman Picture Show: Key Exchange Stories from Commercial VoWiFi Deployments

Speakers: Gabriel K. Gegenhuber; Florian Holzbauer; Philipp É. Frenzel; Edgar Weippl; Adrian Dabrowski

Conference: USENIX Security '24

YouTube: https://www.youtube.com/watch?v=2bdGt5C8PBE

Overview

This talk, "Diffie-Hellman Picture Show," presented by Gabriel K. Gegenhuber from the University of Vienna, delves into the critical security landscape of Voice over Wi-Fi (VoWiFi), also known as Wi-Fi Calling. VoWiFi has become a preferred channel for mobile operators due to its cost-effectiveness and reliance on existing Wi-Fi infrastructure, making it a ubiquitous and essential service for millions of subscribers globally. The research uncovers significant vulnerabilities in the key exchange mechanisms underpinning VoWiFi security, exposing user communications to potential eavesdropping and decryption.

The core of the presentation addresses the widespread and continued use of outdated and cryptographically weak Diffie-Hellman (DH) key exchange groups within commercial VoWiFi deployments. Beyond mere misconfigurations, the researchers identify critical downgrade vulnerabilities and, most alarmingly, the sharing of identical private keys across multiple, unrelated operators. These findings reveal systemic weaknesses in operator infrastructure and device implementations, posing a substantial risk to the privacy and confidentiality of voice and messaging traffic for an estimated 140 million subscribers. This work serves as a stark reminder of the challenges in securing complex telecommunications ecosystems, even when established cryptographic protocols are in place.

Background

▶ Watch: Introduction to VoWiFi and technical architecture (0:00)

In modern 4G and 5G cellular networks, subscribers can connect to their mobile operator either traditionally via a cell tower or through a Wi-Fi access point using Voice over Wi-Fi (VoWiFi). VoWiFi is increasingly favored by operators as it reduces their infrastructure costs by leveraging existing Wi-Fi networks. From a technical perspective, a smartphone (User Equipment, UE) connects to an operator's network via a Wi-Fi Access Point, which then routes traffic through an evolved Packet Data Gateway (ePDG), an internet-exposed component, before reaching the IP Multimedia Subsystem (IMS), which handles Voice over IP (VoIP) services.

To secure this Wi-Fi-based connection, IPsec is mandated, establishing three distinct tunnels. The foundational layer is the Internet Key Exchange (IKE) protocol, responsible for signaling and managing the security associations. On top of IKE, an IPsec tunnel in tunnel mode provides a VPN-like connection, assigning the UE an IP address within the operator's range. Finally, the voice traffic itself, typically using Session Initiation Protocol (SIP), is protected by IPsec in transport mode. The security of this entire stack heavily relies on the initial IKE handshake, particularly the Diffie-Hellman (DH) key exchange, which establishes a shared secret key between the UE and the ePDG.

The speaker's initial observation revealed that his phone was proposing Diffie-Hellman group 2, a 1024-bit prime group, during the IKE handshake. This immediately raised a red flag, as the Logjam paper (CCS 2015) had estimated that a nation-state actor could break 1024-bit prime groups, and an academic team could break 768-bit groups. Since 2015, computational power has only increased, making such attacks more feasible. Industry standards bodies, like ETSI and 3GPP, recognized this vulnerability. DH group 2 was discouraged in 2011 and officially deprecated in 2016, with Diffie-Hellman group 14 (a 2048-bit prime group) recommended as the secure replacement. The research aimed to determine if these recommendations were actually implemented in commercial VoWiFi deployments or if the industry lagged behind cryptographic best practices.

Key Findings

▶ Watch: How Diffie-Hellman group standards evolved over time (4:00)

The research uncovered several critical security vulnerabilities and widespread non-compliance with cryptographic best practices in commercial VoWiFi deployments:

  1. Prevalence of Weak Diffie-Hellman Groups: Despite being deprecated by 3GPP and ETSI since 2016, Diffie-Hellman group 2 (1024-bit prime) remains widely popular. Analysis of pre-loaded configurations on various smartphones (Apple, Samsung, Qualcomm generic) confirmed its common use. Server-side measurements further revealed that DH group 2 was still the most popular group supported by ePDGs, and shockingly, Diffie-Hellman group 1 (768-bit prime), which was never specified for use in the telecom world, was supported by 40% of servers. This widespread support for weak groups creates a fertile ground for downgrade attacks.
  1. Downgrade Vulnerabilities:
  • General Downgrade Attack: The researchers identified a vulnerability where an attacker could force a client to use a weaker DH group. During the IKE handshake, clients typically propose a preferred strong group (e.g., DH group 14) but also signal support for weaker alternatives. If a server does not support the preferred group, it can ask the client to switch to a weaker, mutually supported group (e.g., DH group 2). A malicious on-path attacker can inject a downgrade packet, tricking the client into believing the server only supports a weaker group. This attack is feasible because 41% of tested servers tolerate weak DH group choices, effectively enabling an attacker to reduce the cryptographic strength of the connection.
  • MediaTek Specific Downgrade Vulnerability: A more severe vulnerability was discovered in devices using MediaTek IKE clients. In this specific case, an attacker could downgrade the connection to an arbitrary Diffie-Hellman group, even one not explicitly supported or signaled by the client. The MediaTek client failed to properly validate if the server's requested DH group was actually among its supported options. This flaw, combined with the widespread server-side support for weak DH groups, allowed an attacker to force the weakest possible key exchange, significantly simplifying passive decryption.
  1. Shared Private Keys Across Operators: Perhaps the most alarming discovery was the identification of identical Diffie-Hellman key exchange values being used by 16 distinct and geographically unrelated mobile operators. These operators were located across Europe, South America, and Asia. Identical key exchange values strongly imply that these operators were using the same private keys for their ePDG deployments. This critical misconfiguration affected an estimated 140 million subscribers. Any entity possessing these shared private keys could passively decrypt the VoWiFi traffic of all affected customers, compromising their privacy and security. Further analysis traced the root cause to ZTE core equipment, where private keys intended for integration testing were accidentally included in production images.
  1. Resurrection of Shared Keys Post-Disclosure: Following responsible disclosure to GSMA and the affected parties, initial fixes were deployed. MediaTek addressed its vulnerability via an Android security update, and ZTE acknowledged the private key issue. All 16 affected operators eventually applied fixes by June. However, subsequent continuous scanning revealed that in June, some operators began to re-use the previously shared private keys and key exchange values. This highlights a persistent and concerning issue with key management practices within the affected deployments, indicating that the underlying problem was not fully resolved in some cases.

Technical Deep Dive

▶ Watch: Real-world: Pre-loaded configs still use weak DH groups (5:00)

The security of VoWiFi hinges on the robust implementation of IPsec, particularly the Internet Key Exchange (IKE) protocol. IKE is responsible for negotiating Security Associations (SAs), which define the cryptographic algorithms and keys used to protect the subsequent data traffic. The initial phase of IKE involves the Diffie-Hellman (DH) key exchange, a fundamental cryptographic primitive that allows two parties to establish a shared secret over an insecure channel. This shared secret is then used to derive symmetric encryption keys for the IPsec ESP tunnels.

The core vulnerability discussed revolves around the Diffie-Hellman groups used. These groups are defined by their prime modulus size, which dictates the cryptographic strength.

  • Diffie-Hellman group 1 utilizes a 768-bit prime.
  • Diffie-Hellman group 2 employs a 1024-bit prime.
  • Diffie-Hellman group 14 uses a 2048-bit prime.

The Logjam attack (CCS 2015) demonstrated the practical feasibility of breaking 1024-bit DH groups, especially by well-resourced adversaries like nation-states. The attack leveraged precomputation over a large prime field, allowing for efficient computation of discrete logarithms. This rendered 1024-bit DH, once considered strong, effectively insecure for sensitive communications. Recognizing this, 3GPP and ETSI deprecated DH group 2 in 2016, recommending a transition to stronger groups like DH group 14.

The research methodology involved a three-pronged approach to assess the real-world situation:

  1. Pre-loaded Configuration Analysis: The team analyzed operator-specific configuration files present on various smartphones from different manufacturers (Apple, Samsung) and utilized a Qualcomm generic approach to extract this data. This revealed that despite standards, DH group 2 was still commonly configured as a supported or even preferred group on client devices.
  2. User Equipment (UE) IKE Client Probing: This step involved actively probing the IKE clients on user equipment to understand their negotiation behavior. This is where the downgrade vulnerabilities were discovered. A client might propose DH group 14 as its preferred choice but also signal support for weaker groups like DH group 2. An attacker could intercept this negotiation and inject a packet suggesting that the server only supports DH group 2, forcing the client to downgrade. The critical flaw in MediaTek clients was their failure to verify if the server's suggested downgrade group was actually among the client's supported groups, making them susceptible to downgrades to arbitrary and potentially extremely weak DH groups.
  3. Active Measurements Towards ePDGs: To understand server-side support, the researchers conducted active scans against ePDG deployments globally. This involved sending IKE handshake requests with various DH group proposals and observing the server's responses. These measurements confirmed the widespread support for deprecated groups: DH group 2 was the most popular, and DH group 1 (768-bit) was supported by 40% of servers, despite never being specified for telco use. This server-side tolerance for weak groups is a critical enabler for the downgrade attacks.

The most severe finding, the shared private keys, emerged from anomalies in the server-side measurement logs. Identical public key values observed across 16 unrelated operators indicated that they were using the same underlying private keys. In a secure DH key exchange, each server should generate and use a unique, randomly generated private key. The use of identical keys meant that if an attacker obtained one of these private keys, they could decrypt the VoWiFi traffic of all 140 million subscribers across these 16 operators. This issue was traced to ZTE core equipment, where private keys used for internal integration testing were inadvertently shipped in production firmware images. This represents a catastrophic failure in key management and secure software development lifecycle processes.

The re-emergence of shared keys after initial remediation underscores the deeply ingrained nature of these issues. It suggests that patching efforts might have been incomplete, or that the underlying configuration management and key generation processes were not fundamentally corrected, leading to a recurrence of the vulnerability. The researchers also noted that their server-side results might not reflect the full picture due to geo-blocking implemented by some operators, which limits the visibility of certain ePDGs from their Vienna-based scanning infrastructure.

Demo / Proof of Concept

▶ Watch: Severe MediaTek downgrade to arbitrary Diffie-Hellman groups (6:40)

While the presentation did not feature a live, interactive demonstration of an exploit tool, the core of the research involved a methodical and practical proof-of-concept for the identified vulnerabilities. The speaker's initial discovery using Wireshark to analyze his phone's packet traces served as the foundational step, revealing the use of the outdated Diffie-Hellman group 2. This initial observation led to the development of a comprehensive three-step evaluation approach that effectively acted as a proof-of-concept for the widespread issues.

The downgrade attack itself was demonstrated conceptually through the analysis of IKE handshake negotiation flows. The researchers elucidated how an attacker, by injecting specific packets, could manipulate the client-server negotiation to force the use of weaker, cryptographically vulnerable Diffie-Hellman groups. This involved understanding how clients signal preferred groups and fallback options, and how servers respond. The discovery that 41% of servers tolerated weaker choices, combined with the specific MediaTek client vulnerability (allowing downgrade to arbitrary DH groups), served as compelling evidence of the practicality of these attacks. The researchers' ability to identify these negotiation failures and their implications for security constitutes a robust proof-of-concept for the downgrade vectors.

Furthermore, the most impactful finding, the shared private keys, was a direct result of the server-side measurements. By setting up continuous scanning scripts that probed ePDG servers globally, the researchers were able to collect and analyze thousands of IKE handshake responses. The presence of duplicate Diffie-Hellman key exchange values in these logs, across unrelated operators, was the undeniable proof-of-concept that private keys were being reused. This was not a theoretical construct but an observed reality in commercial deployments. The subsequent responsible disclosure and the operators' acknowledgments, along with the issuance of two CVEs with high severity, further validate these findings as concrete vulnerabilities demonstrated through empirical evidence, even if a user-facing exploit video wasn't the focus of the conference talk. The subsequent re-emergence of the shared keys, detected by the same continuous scanning methodology, further solidified the practical implications and persistent nature of the problem.

Defensive Implications

▶ Watch: Servers widely support weak and even unspecified DH groups (7:30)

The findings from the "Diffie-Hellman Picture Show" talk highlight several critical areas where mobile operators, device manufacturers, and even end-users need to take immediate and sustained action to enhance VoWiFi security:

  1. Strict Enforcement of Strong Cryptographic Primitives:
  • Operators must immediately cease support for deprecated Diffie-Hellman groups. This includes DH group 2 (1024-bit) and especially DH group 1 (768-bit), which was never specified for telco use but is still supported by a significant percentage of servers.
  • Configure ePDGs to strictly demand and only support strong DH groups, such as DH group 14 (2048-bit) or higher. Server-side logic should reject any IKE proposals that fall below a strong cryptographic threshold, preventing downgrade attacks. The fact that 41% of servers tolerate weak choices is a critical vulnerability that must be addressed.
  1. Robust Key Management Practices:
  • Implement stringent processes for generating and managing private keys for ePDG deployments. Each ePDG instance, and indeed each operator, must use unique, randomly generated private keys. The incident with ZTE core equipment underscores the catastrophic risk of reusing integration testing keys or having insufficient key management lifecycle policies.
  • Conduct regular audits of key exchange values to detect any accidental reuse of private keys across deployments or within an operator's own infrastructure. Automated tools should be deployed for continuous monitoring.
  1. Device Software Updates and Validation:
  • Device manufacturers, particularly those whose IKE clients were found vulnerable (e.g., MediaTek), must ensure robust validation of key exchange parameters. Clients should strictly verify that any DH group proposed by the server during negotiation is genuinely supported by the client, preventing arbitrary downgrades.
  • End-users must prioritize installing Android security updates and other device firmware updates as soon as they become available. These updates often contain critical patches for vulnerabilities like the MediaTek specific downgrade flaw.
  1. Supply Chain Security and Vendor Accountability:
  • Operators need to demand higher security standards from their core network equipment vendors (e.g., ZTE). This includes rigorous secure development lifecycles, comprehensive testing for cryptographic misconfigurations, and clear guidelines on key management.
  • Vendors must ensure that production images are free from development or testing artifacts, especially sensitive cryptographic material like private keys.
  1. Continuous Monitoring and Incident Response:
  • Operators should establish continuous scanning and monitoring of their ePDG deployments to detect non-compliant configurations, weak cryptographic support, and, crucially, the re-emergence of shared private keys, as observed in this research.
  • Develop robust incident response plans for cryptographic compromises, including procedures for key revocation and rapid deployment of patched configurations. The observed re-use of shared keys post-disclosure highlights a need for more effective and permanent remediation strategies.
  1. Awareness and Education:
  • The industry needs greater awareness of the critical importance of strong cryptography in core network functions like VoWiFi. Cryptographic best practices, once established, must be rigorously maintained and updated as computational capabilities evolve.

By addressing these defensive implications, the mobile telecommunications ecosystem can significantly harden VoWiFi against the types of sophisticated key exchange attacks and widespread compromises uncovered by this important research.

Key Takeaways

  • VoWiFi relies on IPsec and IKE for security, but widespread vulnerabilities exist in key exchange implementations.
  • Deprecated and cryptographically weak Diffie-Hellman groups (1024-bit DH group 2 and even 768-bit DH group 1) are still prevalent in pre-loaded device configurations and on a significant portion of operator ePDG servers, despite being known insecure since 2015 and deprecated by standards bodies.
  • Downgrade attacks are feasible: Attackers can force clients to use weaker DH groups due to client/server negotiation weaknesses, notably a critical vulnerability in MediaTek IKE clients allowing arbitrary downgrades.
  • A catastrophic key management failure led to 16 unrelated operators sharing identical private keys, affecting approximately 140 million subscribers and enabling passive decryption of their VoWiFi traffic. This was traced to ZTE core equipment accidentally including integration testing keys in production images.
  • Even after disclosure and initial fixes, some operators re-introduced the shared private keys, indicating persistent issues in key management and configuration processes.
  • Mobile operators must strictly enforce strong DH groups (e.g., 2048-bit DH group 14), disable support for weak groups, implement robust unique key management, and ensure timely updates and audits to protect subscriber privacy.

About the Speaker(s)

The primary speaker for "Diffie-Hellman Picture Show" was Gabriel K. Gegenhuber, who is affiliated with the University of Vienna in Austria. He presented the findings of this detailed research into the security of commercial Voice over Wi-Fi deployments. The paper and the talk represent a collaborative effort with co-authors Florian Holzbauer, Philipp É. Frenzel, Edgar Weippl, and Adrian Dabrowski, all presumably from similar academic or research institutions, contributing to the rigorous analysis and discovery of these critical vulnerabilities. Their work underscores a strong focus on practical telecommunications security and cryptographic assessments.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

This research uncovers catastrophic vulnerabilities in commercial VoWiFi, from widespread use of deprecated Diffie-Hellman groups and critical downgrade flaws to the shocking discovery of 16 operators sharing identical private keys affecting 140 million subscribers. The methodical analysis and the revelation of persistent key management failures in core network equipment make this a crucial, must-see deep dive into telco security.

Heather Calloway (CISO) — MUST SEE

This research exposes catastrophic failures in VoWiFi security, from widespread use of deprecated cryptography to operators sharing identical private keys across 16 providers, affecting 140 million subscribers. The re-emergence of these shared keys post-disclosure highlights deep-seated issues in vendor supply chain security, key management, and operator accountability. This is a critical examination of institutional failures that directly impact millions and demands immediate executive action.

→ Top-rated talks at 33rd USENIX Security Symposium

All talks from 33rd USENIX Security Symposium