How a 5G Lab Capture Hid a Full VoNR Call Inside GTP Tunnels

A bug report filed against the open-source srsRAN project involved a 5G F1-U interface capture that initially appeared to contain only GTP traffic, with no visible SIP signaling or RTP audio. The hidden content was recoverable because the lab network used NEA0 null ciphering and no SDAP header, meaning stripping a fixed 3-byte PDCP header from each GTP payload exposed 2,960 raw IPv4 packets underneath. Re-framing that data revealed a two-party Voice over New Radio (VoNR) call comprising 1,670 RTP frames and six SIP messages, including an IMS-AKA authentication exchange. The INVITE and subsequent call-control messages were absent from plain view because IMS specifications require all post-registration SIP signaling to travel inside an IPsec tunnel negotiated during the 401 challenge. The technique only works on test networks using NEA0; commercial deployments running NEA1 or NEA2 encryption would make the payload unrecoverable without the device's keys.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in