by Holtmanns, Silke (Nokia - FI/Espoo)
I'm part of security research and we are mainly interested in the core network part and not on the UE part.
What we want to do is have a PGW which has some the EPC "machinery" behind to get a TEID and have MME, HSS, SGW initialized and some not real UEs i.e. the fake UEs would sit in or next to the eNB.
In the end we are interested in plugging this EPC next to a real one with a real S8 connection.
We do not need real internet connection for the "fake UE" and user plane is also not that important for us.
So how can we get a "fake UE" into the eNB, so that is makes all the protocol runs for data communication set-up.