Publication:

Securing Mobile Money on Legacy Networks: Protecting Against Downgrade and Rogue Base Station Attacks in Africa With GECKO

Loading...
Thumbnail Image

Files

Debrah_Jelimo_Thesis.pdf (5.44 MB)

Date

2026-04-13

Journal Title

Journal ISSN

Volume Title

Publisher

Research Projects

Organizational Units

Journal Issue

Access Restrictions

Abstract

Mobile money services such as M-PESA, MTN MoMo, and Orange Money collectively handle a significant share of financial transactions across sub-Saharan Africa. These services, executed using USSD sessions and SMS, are provided over GSM and UMTS signaling, and 2G’s lack of mutual authentication allows rogue base stations to silently intercept or rewrite USSD-based transactions. This thesis demonstrates the attack on a software GSM testbed built with Osmocom. An adversary-controlled BSS forces the handset onto a fake BTS, and a proxy on the Abis interface decodes and modifies USSD payloads in transit, confirming that transaction parameters can be altered without detection by the subscriber or the core network. To counter this, the thesis proposes a defense built on GECKO (Geo-Enabled Cryptographic Key Oracle), a geographical PKI that binds each legitimate base station to its operator and physical location through verifiable certificates. On the device side, the defense verifies the serving cell and establishes an authenticated secure channel before sensitive data leaves the handset. Within the core network, it validates signaling against the operator’s infrastructure inventory. The design is deployable incrementally and generalizes to any setting where backward compatibility across network generations creates exploitable downgrade paths.

Description

Type of resource

Princeton University Senior Theses

Keywords

Location

Citation