COMPETITIVE DIRECT ACCESS PROCEDURE FOR MOBILE COMMUNICATION

DE602021050950T2Active Publication Date: 2026-04-01DEUTSCHE TELEKOM AG
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-02-06
Publication Date
2026-04-01

AI Technical Summary

Technical Problem

Existing contention based random access procedures in 4G and 5G networks are vulnerable to fraud and resource misuse due to malicious UEs intercepting and mimicking the UE contention resolution identity, leading to unresolved contention and resource consumption.

Method used

Implementing a hash-based approach where the base station calculates a defined part of the hash value of the UE contention resolution identity and includes it in the contention resolution message, while the mobile terminal verifies the identity using the same hash algorithm, ensuring a secure and reliable contention resolution process.

Benefits of technology

Prevents fraud and misuse by ensuring only legitimate UEs can successfully complete the contention resolution, reducing resource wastage and enhancing network security.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

Technical field

[0001] The present invention refers to a contention based random access procedure for use in a mobile communication system. The invention also refers to a mobile terminal, e.g. a user equipment, and a base station, e.g. an eNodeB suitably adapted to execute the contention based random access procedure. Furthermore, the invention provides a special format of a contention resolution message signalled during the contention based random access procedure.Technical background

[0002] Both, 4G LTE networks and 5G networks offer contention based random access procedures, i.e. the random access procedure implies an inherent risk of collision.

[0003] EP 3 627 950 A1 provides a random access method, a terminal device, and a network device, so as to reduce a transmission delay and signaling overheads. The method includes: determining a physical channel resource and a preamble sequence, where the physical channel resource and / or the preamble sequence are / is associated with a first beam that is used by a network device for performing downlink transmission and that is determined by the terminal device; sending the preamble sequence on the physical channel resource; receiving a random access response message and a paging message, where the random access response message includes a preamble identifier, the paging message includes first identification information of one or more to-be-paged terminal devices, and the paging message is sent on the first beam; when the preamble identifier is corresponding to the preamble sequence, and a first identifier of the terminal device matches the first identification information, sending a second identifier of the terminal device; receiving first indication information sent by the network device; and determining, based on the first indication information, to complete a random access procedure.

[0004] US 2020 / 068547 A1 provides a data transmission method. The method includes: sending, by a terminal device, a first indication to an access network device, wherein the first indication is used to indicate early data transmission; and performing, by the terminal device, the early data transmission between the terminal device and the access network device.

[0005] WO 2019 / 241999 A1 relates to techniques, base stations, and user equipment devices (UEs) for performing base station authentication through access stratum signaling transmissions.

[0006] Such a contention based random access procedure is being described in more detail with respect to Figure 1. A detailed description of the random access procedure can be also found in 3GPP TS 36.321 (for 4G) and in 3GPP TS 38.321 (for 5G). Figure 1 shows the contention based RACH (Random Access Channel) procedure in a 5G network. A similar contention based RACH procedure can be performed in a 4G network. The RACH procedure consists of four "steps". First, a mobile terminal, here realized by a user equipment (UE), selects a random access resource, i.e. a PRACH resource, a preamble and the next available subframe, for PRACH transmission and transmits 101 a random access preamble (MSG1) on the Physical Random Access Channel (PRACH) to a base station, e.g. to eNodeB (4G) or gNodeB (5G), depending on which network is used. The random access preamble is selected by the user equipment from a set of available random access preambles reserved by eNodeB (4G) or gNodeB (5G) for contention based random access. In 4G LTE networks as well as in 5G networks, there are 64 preambles per cell which can be used for contention based random access. After eNodeB (4G) or gNodeB (5G) has detected a RACH preamble, it sends 102 a Random Access (RACH) Response (RAR) as MSG2 on the PDSCH (Physical Downlink Shared Channel) addressed on the PDCCH (Physical Downlink Control Channel). If multiple user equipments (UEs) transmitted the same RACH preamble in the same PRACH resource, there is a collision and the respective UEs would receive the same RACH response (MSG2). The RACH response itself comprises the detected RACH preamble, i.e. in the RACH response the preamble is echoed back to the UE, hence the UE knows that it has been "heard" by the eNodeB (4G) or the gNodeB (5G). Due to the limited amount of only 64 preambles, the probability of choosing the same preamble by different UEs accessing the same cell in the very same moment can be high in certain scenarios.

[0007] These are the cases when the multiple UEs, which have chosen the same preamble, may also simultaneously react upon single downlink RACH response, sending 103 simultaneously RRC (Radio Resource Channel) Connection Requests (for RRC connection establishment and RRC connection reestablishment) with their UE identities included, on CCCH (Common Control Channel) logical channel, i.e. initial layer 3 message (MSG3) is a CCCH SDU (Server Data Unit). Such a UE identity comprises generally 40 bits and is represented by a random value or by a S-TMSI (Sender-Temporary Mobile Subscriber Identity). In the following, such UE identity is also called user equipment contention resolution identity.

[0008] In response to the RACH response received from the eNodeB (4G) or gNodeB (5G), the user equipment transmits 103 a first scheduled (uplink) transmission message (MSG3) on the resources assigned within the RACH response. This first scheduled uplink transmission message comprises the RRC connection request. In case of a preamble collision having occurred, i.e. multiple user equipments have sent the same preamble on the same PRACH resource, the colliding user equipments will also collide in the same uplink resources when transmitting 103 their respective first scheduled transmission message. This may result in interference that no transmission from a colliding user equipment can be decoded at the eNodeB (4G) or the gNodeB (5G), and the user equipments will restart the contention based random access procedure after having reached a given maximum number of retransmission for their scheduled transmission message. In case the scheduled transmission message from one user equipment is successfully decoded by eNodeB (4G) or gNodeB (5G), the contention remains unsolved for the other user equipments.

[0009] For resolution of the contention, the eNodeB or gNodeB sends 104 a contention resolution message addressed to the one successful user equipment, and echoes the 40-bit user equipment contention resolution identity contained in the first scheduled transmission message. Only the user equipment which detects its user equipment contention resolution identity continues further data transmission. Other user equipments (UEs) realize that there was a collision at step 101 and can quickly exit the current contention based RACH procedure and starts another one.

[0010] Only one of them will be accepted by the network, i.e. by the eNodeB (4G) or the gNodeB (5G) which will be signalled back in a contention resolution message (MSG4) by echoing the accepted UE contention resolution identity, e.g. the 40-bit UE identity. Those other UEs which did not recognize their UE contention resolution identity, have to restart the random access procedure. Contention resolution is, therefore, based upon reception of contention resolution identity MAC CE (Medium Access Control Control Element). In this case, a new CRNTI (Cell Radio Network Temporary Identity) is allocated to the respective UE.

[0011] In order to check whether the UE will be accepted by the network, i.e. by the eNodeB (4G) or the gNodeB (5G) (depending on which network is used), the following test is performed on UE side: If (CCCH SDU was included in MSG3) && If (PDCCH transmission is addressed to its Temporary CRNTI) && If(MAC PDU is successfully decoded) && If(MAC PDU contains a UE Contention Resolution Identity MAC control element) { If (UE Contention Resolution Identity included in the MAC control element == CCCH SDU transmitted in MSG3) Then Consider Contention Resolution successful. }

[0012] PDU is an abbreviation for protocol data unit.

[0013] The precondition of the check: UE Contention Resolution Identity included in the MAC control element == CCCH SDU transmitted in MSG3

[0014] is that the UE contention resolution identity sent by the UE in MSG3, i.e. in the first scheduled transmission message, is signalled back by echoing the accepted UE contention resolution identity, e.g. the 40-bit UE identity, from the cell, i.e. from the eNodeB or gNodeB, in downlink in MSG4, i.e. in the contention resolution message. Current standards do this exactly 1:1, a fact that could be exploited by malicious UEs, located within the same cell to transfer messages via misusing this feature. This can be happen as follows: If in uplink a UE_A injects a value that is not random but represents each time 5 symbols of a message (corresponding to / representing 40 bits of a UE contention resolution identity) that it wants to transmit, the base station, e.g. eNodeB (4G) or gNodenB (5G), would echo it in downlink on the DL-SCH (Downlink Shared Channel) that could be intercepted by a UE_B to receive the message without leaving any trace on the network. This would be a potential fraud and might consume resources.

[0015] Therefore, it is an object of the present invention to provide a possibility to prevent such kind of misuse in a contention based random access procedure.Summary of the invention

[0016] The above-mentioned object is solved by the contention resolution message, the mobile terminal, the base station, the system and the random access procedure with the features of the respective independent claims. Further embodiments are presented by the following description and the respective dependent claims.

[0017] In a 4G network, the base station may be represented by a eNodeB, in a 5G network, the base station may be represented by a gNodeB. The mobile terminal may be represented by a user equipment, UE. Within the scope of the present disclosure, the terms "mobile terminal" and "user equipment" and "UE" are used synonymously. Within the scope of the present disclosure, the terms "mobile terminal contention resolution identity" and "user equipment contention resolution identity" and "UE contention resolution identity" and "UE CRI" are used synonymously.

[0018] The following description is presented to enable any person skilled in the art to make, use and / or practice the disclosed subject matter, and is provided in the context of one or more particular implementations. Various modifications to the disclosed implementations will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other implementations and applications.

[0019] The details of one or more implementations of the subject matter of this specification are set forth in the accompanying drawings and the description. Other features, aspects, and advantages of the subject matter will become apparent from the description, the drawings, and the claims.Brief description of the drawings

[0020] Fig. 1 shows a schematic diagram illustrating a contention based random access procedure according to the state of the art. Fig. 2 shows a schematic diagram illustrating a contention based random access procedure according to the state of the art and indicating a potential misuse scenario. Fig. 3 shows a schematic diagram illustrating an embodiment of a contention based random access procedure according to the present invention which is executed, using an embodiment of a system according to the present invention. Detailed description of the drawings

[0021] Figure 1 shows schematically a schematic diagram illustrating a contention based random access procedure according to the state of the art and has already been described hereinbefore.

[0022] Figure 2 shows a schematic diagram illustrating a contention based random access procedure according to the state of the art and indicating a potential misuse scenario.

[0023] Figure 2 shows the contention based RACH (Random Access Channel) procedure in a 5G network. A similar contention based RACH procedure can be performed in a 4G network. The present invention concerns the RACH procedure performed in a 4G network. The RACH procedure performed in a 5G network does not form part of the present invention. RACH procedure consists, as already shown in

[0024] Figure 1, of four "steps". First, a mobile terminal, here realized by UE_A, selects a random access resource, i.e. a PRACH resource, a preamble and the next available subframe, for PRACH transmission and transmits 201 a random access preamble as MSG1 on the Physical Random Access Channel (PRACH) to eNodeB (4G) or gNodeB (5G). After eNodeB (4G) or gNodeB (5G) has detected a RACH preamble, it sends 202 a Random Access (RACH) Response as MSG2 on the PDSCH (Physical Downlink Shared Channel) addressed on the PDCCH (Physical Downlink Control Channel). If multiple user equipments transmitted the same RACH preamble in the same PRACH resource, there is a collision and the respective user equipments would receive the same RACH response. The RACH response itself comprises the detected RACH preamble, i.e. in the RACH response the preamble is echoed back to the UE_A, hence the UE_A knows that it has been "heard" by the eNodeB (4G) or the gNodeB (5G).

[0025] UE_A reacts upon single downlink RACH response by sending 203 a first scheduled (uplink) transmission message as MSG3 which comprises a RRC (Radio Resource Channel) Connection Request (for RRC connection establishment and RRC connection reestablishment) with its UE contention resolution identity MAC CE included, as MSG3 on CCCH (Common Control Channel) logical channel. Such a UE identity, i.e. UE contention resolution identity, comprises generally 40 bits and is represented by a random value or by S-TMSI (Sender-Temporary Mobile Subscriber Identity).

[0026] In case the first scheduled transmission message from UE_A is successfully decoded by eNodeB (4G) or gNodeB (5G), for resolution of the contention, the eNodeB or gNodeB (5G) sends 204 a contention resolution message addressed to UE_A, and echoes the UE contention resolution identity, e.g. the 40-bit user equipment identity contained in the first scheduled transmission message (MSG3).

[0027] The precondition of checking whether the request was successful is that the UE contention resolution identity sent by the UE_A in MSG3 is signalled back by echoing the accepted contention resolution identity, e.g. the accepted 40-bit UE identity, from the cell, i.e. from the eNodeB or gNodeB, in downlink in MSG4. Current standards do this exactly 1:1, a fact that could be exploited by malicious UEs, such as UE_B, located within the same cell to transfer messages via misusing this feature. This can be happen as follows: If in uplink the UE_A injects a value that is not random but represents each time 5 symbols of a message (corresponding to / representing 40 bits of a UE identity) that it wants to transmit, eNodeB (4G) or gNodeB (5G) would echo it in downlink on the DL-SCH (Downlink Shared Channel) that could be intercepted 205 by UE_B to receive the message without leaving any trace on the network. This means that UE_B can collect 206 the symbols of the message. Thus, UE_A and UE_B can communicate without being accepted and registered by the network. This would be a potential fraud and might consume resources.

[0028] Figure 3 shows a schematic diagram illustrating a contention based random access procedure according to the present invention. The respective format of the messages MSG1, MSG2 and MSG3 which are transferred in steps 301, 302 and 303 between the UE_A and the eNodeB (4G) or gNodeB (5G) correspond to the respective format of MSG1, MSG2, and MSG3 which are transferred in Figure 1 in steps 101, 102, and 103, respectively, and in Figure 2 in steps 201, 202, and 203, respectively. However, according to the invention, in 4G the contention resolution message which

[0029] is sent 305 as MSG4 from the base station, i.e. eNodeB (4G), to the mobile terminal UE_A differs from MSG4 as transferred in step 104 of Figure 1 or in step 204 of Figure 2. The base station does not echo the UE contention resolution identity, e.g. the 40-bit UE identity, 1:1. Rather, in step 304_1, the base station, i.e. eNodeB (4G), calculates a hash value of the UE contention resolution identity, using a hash algorithm, such as SHA-256, and inserts a defined part of the hash value, e.g. its 40 least significant bits in the downlink contention resolution message MSG4 305. Afterwards the contention resolution message 305 is transferred to the mobile terminal UE_A. The UE_A calculates itself in step 304_2 an own hash value using the same hash algorithm as well and performs a modified check, such as: { If (UE Contention Resolution Identity included in the MAC control element == 40 least significant bits(HASH(CCCH SDU transmitted in MSG3)) Then Consider Contention Resolution successful. }

[0030] That means that UE_A compares the defined part of the hash value received from the base station, e.g. eNodeN (4G), with a corresponding defined part of its own hash value, e.g. UE_A compares the least 40 significant bits of the hash value calculated by the base station with the least 40 significant bits of its own hash value. In the case that UE_A states identity, UE_A concludes that the contention resolution was successful and that it is accepted by the base station for transmitting further data within / via the respective cell of the base station. The calculation of the own hash value using the same hash algorithm in step 304_2 can be performed by UE_A at any time between transmitting the first scheduled transmission message 303 and the above mentioned check, i.e. after receiving the contention resolution message 305. It is also possible to do this calculation on the side of UE_A when the UE contention resolution identity is created and / or when the first scheduled transmission message 303 is created. According to the invention, the defined part of the hash value of the user equipment contention resolution identity has the same size as the user equipment contention resolution identity.

[0031] By that, a "normal" UE_B which did not recognize its UE contention resolution identity, would restart the random access procedure; a malicious UE_B would not be able to reconstruct, as indicated by "???", the input of the UE_A, i.e. the UE contention resolution identity, rendering the misuse pointless and, thus mitigating the attack / misuse.

[0032] Herein, the (step of) transmission of a respective message and the respective message itself are designated with the same reference sign, e.g. the contention resolution message including a defined part of a hash value of a mobile terminal contention resolution identity and the transmission of said contention resolution message are both designated with the reference sign 305. The same applies accordingly to the other messages.List of reference signs

[0033] UEuser equipment, mobile terminal UE_Auser equipment, mobile terminal UE_Buser equipment, mobile terminal eNodeBbase station (4G) gNodeBbase station (5G) 101random access preamble transmission, MSG1 102random access response, MSG2 103first scheduled (uplink) transmission, MSG3 104contention resolution, MSG4 201random access preamble transmission, MSG1 202random access response, MSG2 203first scheduled (uplink) transmission, MSG3 204contention resolution, MSG4 205interception by UE_B 206collection of symbols by UE_B 301random access preamble transmission, MSG1 302random access response, MSG2 303first scheduled (uplink) transmission, MSG3 304_1calculation of hash(UE contention resolution identity) 304_2calculation of own hash(UE contention resolution identity) 305contention resolution, MSG4, with hashed CRI MAC CE

Claims

1. A contention resolution message that is configured for transmission from a base station, eNodeB, of a 4G LTE network to a mobile terminal (UE_A) in a contention based random access procedure, wherein the contention resolution message (305) is setup in response to receiving a first scheduled transmission message (303) of the mobile terminal (UE_A) characterized in that the contention resolution message (305) which is to be transferred from the base station, eNodeB, to the mobile terminal device, comprises a defined part of a hash value of a mobile terminal contention resolution identity wherein the hash value of the mobile terminal contention resolution identity is calculated by the base station, eNodeB, using a hash algorithm, and the defined part of the hash value has the same size as the mobile terminal contention resolution identity and is inserted by the base station, eNodeB, in the contention resolution message wherein the mobile terminal contention resolution identity is taken from the first scheduled transmission message (303) which comprises the mobile terminal contention resolution identity included in a MAC control element.

2. The contention resolution message of claim 1 wherein the hash algorithm is public and known to the mobile terminal (UE_A).

3. The contention resolution message of claim 1 or 2 wherein the hash algorithm is SHA-256.

4. A contention based random access procedure for use in a mobile communication system, comprising - transmitting by a mobile terminal (UE_A) a first scheduled transmission message (303) to a base station, eNodeB, of a 4G LTE network, - transmitting by the base station, eNodeB, a contention resolution message (305) in response to receiving the first scheduled transmission message (303) from the mobile terminal (UE_A), characterized in that the contention resolution message (305) comprises a defined part of a hash value of a mobile terminal contention resolution identity, wherein the hash value of the mobile terminal contention resolution identity is calculated by the base station, eNodeB, using a hash algorithm, and the defined part of the hash value has the same size as the mobile terminal contention resolution identity and is inserted by the base station, eNodeB, in the contention resolution message wherein the mobile terminal contention resolution identity being included in a MAC control element of the first scheduled transmission message (303).

5. The random access procedure according to claim 4, further comprising the step of receiving by the mobile terminal (UE_A) the contention resolution message (305) from the base station, eNodeB, and calculating (304_2) an own hash value of the mobile terminal contention resolution identity included in the first scheduled transmission message (303), using the hash algorithm, and checking an identity between the mobile terminal contention resolution identity and said one encoded in the hash value calculated by the base station, eNodeB, by comparing the defined part of the hash value calculated by the base station, eNodeB, with a corresponding defined part of the own hash value.

6. A base station, eNodeB, of a 4G LTE network for performing a contention based random access procedure in a mobile communication system, comprising: a receiver for receiving a first scheduled transmission message (303) from a mobile terminal (UE_A), wherein the first scheduled transmission message (303) comprises a mobile terminal contention resolution identity included in a MAC control element, a transmitter for transmitting a contention resolution message (305) in response to receiving the first scheduled transmission message (303) characterized in that the contention resolution message (305) comprises a defined part of a hash value of the mobile terminal contention resolution identity, and a calculating unit for calculating (304_1) the hash value of the mobile terminal contention resolution identity, using a hash algorithm, wherein the defined part of the hash value has the same size as the mobile terminal contention resolution identity, and for extracting the defined part of the hash value.

7. A mobile terminal (UE_A) for performing a contention based random access procedure in a mobile communication system, comprising: a transmitter for transmitting a first scheduled transmission message (303) to a base station, eNodeB, of a 4G LTE network, wherein the first scheduled transmission message (303) comprises a mobile terminal contention resolution identity included in a MAC control element, a receiver for receiving a contention resolution message (305) from the base station, eNodeB, in response to the first scheduled transmission message (303) wherein the contention resolution message (305) comprises a defined part of a hash value of the mobile terminal contention resolution identity, the hash value being calculated, by the base station, eNodeB, using a hash algorithm, and the defined part of the hash value having the same size as the mobile terminal contention resolution identity and being inserted, by the base station, eNodeB, in the contention resolution message (305), a calculating unit for calculating (304_2) an own hash value of the mobile terminal contention resolution identity, using the hash algorithm, and for identifying a part of the own hash value which corresponds to the defined part of the hash value, and a comparing unit for comparing the corresponding part of the own hash value with the defined part of the hash value of the contention resolution message (305).

8. A system comprising at least one mobile terminal according to claim 7 and at least one base station according to claim 6 and configured to execute a contention based random access procedure according to any one of claims 4 to 5.

9. A computer program product with a computer-readable medium and a computer program stored on the computer-readable medium with program coding means that are configured to execute a contention based random access procedure according to any one of claims 4 to 5 when the computer program is run on at least two computer units as components of a system according to claim 8.