Skip to content
CY-803 (A) · Mobile and Wireless Security/Quick Revision Short Notes

Mobile and Wireless Security (CY-803 (A)) - Unit 3 Short Notes

UNIT 3: Mobile and Wireless Technologies and Security


I. Wireless Access Technologies

A. Wireless Local Area Networks (WLAN)

  • General Overview: A WLAN is a local area network that uses wireless communication (typically radio waves) to connect devices within a limited area (e.g., home, office, campus). It provides flexibility and mobility compared to wired LANs.

  • Key Components:

    • Access Point (AP): Central device that connects wireless clients to the wired network.

    • Wireless Client/Station (STA): Devices like laptops, smartphones, IoT sensors.

    • Distribution System (DS): The wired backbone (usually Ethernet) connecting APs.

  • Applications: Internet access, file sharing, VoIP, IoT connectivity, public hotspots.

  • Evolution of Wi-Fi Standards (IEEE 802.11 family):

    Wi-Fi standards have evolved significantly in speed, frequency band, and technology.

    | Standard | Year | Max Theoretical Speed | Key Technology/Feature | Frequency Band | | :--- | :--- | :--- | :--- | :--- | | 802.11b | 1999 | 11 Mbps | DSSS (Direct Sequence Spread Spectrum) | 2.4 GHz | | 802.11a | 1999 | 54 Mbps | OFDM (Orthogonal Frequency Division Multiplexing) | 5 GHz | | 802.11g | 2003 | 54 Mbps | OFDM (backward compatible with 802.11b) | 2.4 GHz | | 802.11n (Wi-Fi 4) | 2009 | 600 Mbps | MIMO (Multiple-Input Multiple-Output), 40 MHz channels | 2.4/5 GHz | | 802.11ac (Wi-Fi 5) | 2013 | ~3.5 Gbps | Wider 80/160 MHz channels, 256-QAM, MU-MIMO | 5 GHz | | 802.11ax (Wi-Fi 6/6E) | 2019 | ~9.6 Gbps | OFDMA (Orthogonal Frequency Division Multiple Access), 1024-QAM, BSS Coloring | 2.4/5/6 GHz |

    [!TIP] Exam Focus: Be prepared to explain the significance of MIMO, OFDM, and OFDMA in improving spectral efficiency and handling multiple users.

B. Wireless Personal Area Networks (WPAN)

  • Definition & Distinguishing Characteristics:

    A WPAN is a network for interconnecting devices centered around an individual's workspace, typically within a range of 10 meters.

    • Range: Very short (1-10m).

    • Data Rate: Low to moderate.

    • Topology: Often star or peer-to-peer.

    • Power Consumption: Designed for low power.

    • Distinction from WLAN/WMAN/WPAN:

      • vs WLAN: WLAN covers larger areas (buildings/campuses) with higher data rates.

      • vs WMAN: WMAN covers city-scale areas (e.g., WiMAX).

      • vs WWAN: WWAN is cellular, wide-area (e.g., 4G/5G).

  • Key Technologies:

    • Bluetooth: Short-range RF technology for data exchange and voice. Uses FHSS (Frequency Hopping Spread Spectrum) in 2.4 GHz band. Forms piconets (1 master, up to 7 slaves) and scatternets.

    • Zigbee: Low-power, low-data-rate, long-battery-life technology based on IEEE 802.15.4. Used in IoT, home automation, sensor networks. Supports mesh topologies.

    • RFID (Radio Frequency Identification):

      • Principle of Operation: Uses electromagnetic fields to automatically identify and track tags attached to objects. A reader emits radio waves; a tag (with an antenna and microchip) receives this energy, powers up, and transmits its stored ID/data back to the reader.

      • Tag-Reader Data Transmission:

        1. Reader Activation: Reader emits RF carrier signal.

        2. Tag Power-Up: Tag's antenna captures energy, powers the IC.

        3. Data Modulation: Tag modulates the backscatter of the reader's signal (for passive tags) or transmits its own signal (for active tags) to send its unique ID/data.

        4. Reader Reception & Decoding: Reader receives the modulated signal, decodes the data, and forwards it to a host system.

C. Wireless Metropolitan Area Networks (WMAN)

  • WiMAX (Worldwide Interoperability for Microwave Access):

    • Physical Layer Architecture: Based on IEEE 802.16 standards. Designed for broadband wireless access (BWA) covering several kilometers.

    • Modulation Techniques:

      • OFDM (Downlink): Splits the channel into many orthogonal sub-carriers, robust against multipath fading.

      • SC-FDMA (Uplink): Single Carrier Frequency Division Multiple Access (in 802.16e/mobile WiMAX), reduces peak-to-average power ratio for better mobile device battery life.

      • Adaptive Modulation: Uses QPSK, 16-QAM, 64-QAM based on channel conditions to balance data rate and reliability.

    • Operating Frequency Bands:

      • Fixed WiMAX (802.16-2004): 2-11 GHz, 10-66 GHz (Line-of-Sight).

      • Mobile WiMAX (802.16e): 2.3, 2.5, 3.5, 5.8 GHz (Non-Line-of-Sight).

D. Wireless Mesh Networks

  • Multi-hop Relay: Concept & Significance:

    • Concept: Instead of every node connecting directly to a central AP, nodes (mesh routers) can relay data for other nodes. A packet travels from source to destination via multiple intermediate hops.

    • Significance:

      1. Extended Coverage: Network can cover large areas without wired infrastructure.

      2. Robustness & Reliability: Multiple paths exist; if one node/link fails, traffic can be rerouted.

      3. Self-Configuration & Healing: Nodes can automatically discover neighbors and maintain routes.

      4. Scalability: Adding nodes increases network capacity and coverage.


II. Mobile Cellular Network Evolution

A. 2.5G: General Packet Radio Service (GPRS)

  • Key Features & Capabilities:

    • Packet-switched data service overlay on 2G GSM networks.

    • "Always-on" connectivity (no circuit-switched call setup for data).

    • Higher data rates than Circuit Switched Data (CSD): ~40-100 kbps.

    • Efficient spectrum use: Shares channels among multiple users.

  • Support for Mobile Data Services:

    • Enabled services like WAP (Wireless Application Protocol), mobile email, and basic internet browsing.

    • Introduced EDGE (Enhanced Data rates for GSM Evolution) as an evolution, using 8-PSK modulation for up to ~240 kbps.

B. 3G: Universal Mobile Telecommunication System (UMTS)

  • Short Note: Architecture, Key Features, Capabilities:

    • Architecture: Core Network (CN) + UMTS Terrestrial Radio Access Network (UTRAN). CN includes MSC/VLR, SGSN, GGSN. UTRAN consists of Node B (base station) and Radio Network Controller (RNC).

    • Key Features:

      • High-speed packet-switched data (up to 2 Mbps stationary, 384 kbps mobile).

      • WCDMA (Wideband CDMA) as the radio access technology (5 MHz carrier).

      • Support for multimedia services (video calling, mobile TV).

      • Global roaming capability.

    • Capabilities: Enabled true mobile broadband, video telephony, and location-based services.

C. 4G: Long-Term Evolution (LTE)

  • Key Features & Benefits:

    • All-IP Network: Simplifies architecture, reduces latency.

    • OFDMA (Downlink) & SC-FDMA (Uplink): High spectral efficiency.

    • High Data Rates: Peak ~100 Mbps (mobile), ~1 Gbps (stationary).

    • Low Latency: < 10 ms for control plane, < 5 ms for user plane.

    • Flexible Bandwidth: Supports 1.4 to 20 MHz carrier bandwidths.

    • Improved Spectral Efficiency: ~3-4 times better than 3G.

    • Flat Architecture: Removes RNC, uses eNodeB directly connected to EPC (Evolved Packet Core).

D. Comparative Analysis: 3G vs 4G

  • Technological Differences:

    | Feature | 3G (UMTS) | 4G (LTE) | | :--- | :--- | :--- | | Radio Access | WCDMA, CDMA2000 | OFDMA (DL), SC-FDMA (UL) | | Core Network | Circuit-switched + Packet-switched | All-IP (Packet-switched only) | | Architecture | Hierarchical (Node B, RNC, CN) | Flatter (eNodeB, EPC) | | Bandwidth | Fixed 5 MHz | Scalable 1.4-20 MHz | | Latency | ~100-500 ms | < 10 ms |

  • Performance Metrics & Capabilities:

    • Data Rate: 3G: ~2 Mbps; 4G: ~100+ Mbps (orders of magnitude higher).

    • Spectrum Efficiency: 4G significantly higher (bits/sec/Hz).

    • Latency: 4G offers much lower latency, enabling real-time applications (gaming, video conferencing).

    • Mobility: Both support high mobility, but 4G is optimized for seamless handovers.


III. Mobility and Transport Protocols

A. Mobile IP

  • Mobile IPv4 vs Mobile IPv6: Key Differences:

    | Feature | Mobile IPv4 | Mobile IPv6 | | :--- | :--- | :--- | | Addressing | Uses CoA (Care-of Address) as separate IPv4 addr. | CoA is an IPv6 address, often derived from prefix. | | Encapsulation | Requires IP-in-IP or Minimal Encapsulation. | Uses Route Optimization with Home Address Option; no mandatory tunneling. | | Routing | Triangle Routing (via HA) default. | Direct routing (Route Optimization) is fundamental. | | Security | Often relies on external IPsec. | Integrated with IPsec (mandatory support). | | Agent Discovery | Agent Advertisement/ Solicitation messages. | Uses standard IPv6 Neighbor Discovery. | | Header Overhead | Higher due to encapsulation. | Lower, as extension headers are used. |

  • Encapsulation Headers:

    • Purpose: To tunnel packets from the Home Agent (HA) to the Mobile Node's (MN) current location (Care-of Address, CoA). The original packet is carried as payload inside a new IP header.

    • Structural Comparison:

      • IPv4 Encapsulation (IP-in-IP): New outer IPv4 header (src=HA, dst=CoA) + original IPv4 packet.

      • IPv6 Encapsulation: New outer IPv6 header + IPv6 Mobility Header (type 2 for binding update) + original IPv6 packet. The Home Address Option in the destination options header allows the MN to reveal its permanent home address to the correspondent node.

B. Routing in Mobile Ad Hoc Networks (MANETs)

  • Proactive (Table-Driven) Protocols (e.g., DSDV, OLSR):

    • Concept: Each node maintains up-to-date routing tables for all destinations by periodically exchanging routing information (flooding).

    • Pros: Low latency for route discovery.

    • Cons: High overhead in dynamic networks; doesn't scale well.

  • Reactive (On-Demand) Protocols (e.g., DSR, AODV):

    • Concept: Routes are discovered only when needed via Route Request (RREQ) / Route Reply (RREP) flooding. Routes are maintained until they break.

    • Pros: Lower overhead in low-traffic networks.

    • Cons: High route discovery latency during path breaks.

  • Hybrid Protocols (e.g., ZRP - Zone Routing Protocol):

    • Concept: Combines proactive and reactive approaches. The network is divided into zones (around a node). Routing within the zone is proactive; routing outside the zone is reactive.

    • Goal: Balance between low latency (proactive) and low overhead (reactive).

C. TCP over Wireless Networks

  • Short Note: Challenges & Required Adaptations:

    • Challenges:

      1. High Bit Error Rate (BER): Wireless links are noisy, causing packet loss not due to congestion.

      2. Frequent Handoffs: Temporary loss of connectivity during cell switching.

      3. Long Round-Trip Times (RTT): In satellite or wide-area wireless.

      4. Asymmetric Links: Uplink/downlink capacity differs.

    • Required Adaptations:

      • TCP SACK (Selective Acknowledgment): Helps recover from multiple packet losses efficiently.

      • Explicit Congestion Notification (ECN): Marks packets instead of dropping them.

      • Split TCP Connections (e.g., Snoop Protocol): A proxy at the wireless link layer acknowledges packets locally to hide losses from the main TCP connection.

      • TCP Variants: TCP Westwood+ (estimates bandwidth from ACKs), TCP Veno (distinguishes wireless vs congestion loss).


IV. Security in Mobile and Wireless Systems

A. Denial of Service (DoS) Attacks

  • Short Note: Concept & Wireless-Specific Attack Vectors:

    • Concept: Attack aimed at making a machine or network resource unavailable to its intended users, typically by flooding with traffic or exploiting vulnerabilities.

    • Wireless-Specific Vectors:

      1. Physical Layer Jamming: Transmitting noise on the channel to disrupt communication.

      2. Protocol Layer Attacks:

        • 802.11 Deauthentication/Disassociation Attacks: Forcing clients off the AP.

        • RTS/CTS Flooding: Exploiting the virtual carrier sense mechanism to create "phantom" traffic.

      3. Battery Drain Attacks: Sending frequent, unnecessary messages to drain device battery (e.g., in IoT).

      4. Signaling Storm: Exploiting protocols like DHCP or ARP to create broadcast storms.

B. Military Security Models

  • Primary Objectives:

    1. Confidentiality: Prevent unauthorized disclosure of information.

    2. Integrity: Prevent unauthorized modification of information.

    3. Availability: Ensure timely and reliable access to information.

    4. Authentication: Verify the identity of users/systems.

    5. Non-Repudiation: Prevent senders/receivers from denying their actions.

  • Role of Hierarchical Command Structures:

    • The model enforces mandatory access control (MAC) based on security levels (e.g., Top Secret, Secret, Confidential).

    • Hierarchy defines "need-to-know" and "chain of command". Information flows up (reports) and down (orders) following strict clearance and compartmentalization rules.

    • Significance: Prevents unauthorized data flow across command levels, contains breaches, and ensures operational security through structured information flow control.

C. Mobile Commerce and E-commerce Security

  • E-commerce: Definition & Transformation:

    • Definition: Buying and selling of goods or services over the internet, and the transfer of money and data to execute these transactions.

    • Transformation of Traditional Business:

      1. Global Marketplace: Removes geographical barriers.

      2. 24/7 Availability: Always open.

      3. Reduced Costs: Lower overhead (physical stores, staff).

      4. Personalization: Data-driven marketing and recommendations.

      5. New Business Models: Subscriptions, digital goods, peer-to-peer marketplaces.

      6. Direct Consumer Interaction: Bypasses traditional distributors.

  • Electronic Payment Systems:

    • a. Facilitation of Financial Transactions: Enables payment for goods/services electronically. Includes credit/debit cards, digital wallets (PayPal, Apple Pay), bank transfers, cryptocurrencies.

    • b. Underlying Security Mechanisms & Threats:

      • Mechanisms:

        • Encryption (SSL/TLS): Secures data in transit.

        • Tokenization: Replaces sensitive card data with unique tokens.

        • 3-D Secure: Additional authentication step (e.g., Verified by Visa).

        • Digital Signatures: For non-repudiation.

        • Multi-Factor Authentication (MFA).

      • Threats:

        • Eavesdropping/Sniffing: Intercepting unencrypted data.

        • Man-in-the-Middle (MitM): Intercepting and altering communication.

        • Phishing: Tricking users into revealing credentials.

        • Malware/Keyloggers: Stealing stored payment info.

        • Payment Gateway Fraud: Exploiting vulnerabilities in processing systems.

Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in