System Information Integrity Verification via AS SMC Hash Values
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wireless communication systems face challenges in detecting modifications to system information, particularly in unprotected messages, which can lead to attacks by fake base stations, causing performance degradation, service denial, and roaming issues.
Innovation Solution
A method and apparatus for user equipment (UE) to determine the authenticity of received system information by calculating and comparing hash values, using access stratum (AS) security mode command (SMC) messages, allowing for detection of modifications and re-transmission of integrity-protected system information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If system information is transmitted in unprotected messages, then the UE can receive system information before security context is established, but the information may be modified by fake base stations causing security vulnerabilities
Solution Approach 1:
The base station calculates hash values of system information blocks before transmitting them in unprotected messages. These pre-calculated hash values are included in the unprotected transmission, allowing the UE to perform integrity verification without requiring a security context. This preliminary preparation of verification data enables early system information reception while maintaining security.
Solution Approach 2:
Hash values serve as an intermediary mechanism between the base station and UE for verifying system information integrity. Instead of directly protecting the system information blocks with security contexts, the patent uses hash values as a mediator that can be transmitted unprotected yet still enable verification. The UE compares received hash values with independently calculated hash values to detect modifications without needing cryptographic security setup.
2Reliability
If hash values are transmitted in protected AS SMC messages, then system information authenticity can be verified, but additional signaling overhead is introduced
Solution Approach 1:
The patent combines the transmission of hash values with the existing AS Security Mode Command (SMC) message exchange. Instead of introducing separate dedicated signaling for hash value transmission, the hash values are merged into the already-necessary AS SMC messages that are part of the security setup procedure. This consolidation leverages existing signaling infrastructure to carry additional verification data without proportionally increasing overhead.
Solution Approach 2:
The AS SMC messages, which originally serve the single function of establishing security contexts, are enhanced to serve multiple functions: they simultaneously establish security contexts and convey hash values for system information verification. This multi-functionality allows the same signaling mechanism to handle both security setup and integrity verification, reducing the need for separate dedicated signaling channels.
3Productivity
If the UE processes unprotected messages from fake base stations, then initial connection can be established, but performance degradation and service denial may occur
Solution Approach 1:
The UE performs hash value verification of system information blocks before fully processing unprotected messages from potential fake base stations. By calculating hash values independently and comparing them against received hash values in advance, the UE can detect modified system information early in the connection establishment process. This preliminary verification prevents the UE from proceeding with connection setup based on compromised system information, thereby avoiding performance degradation and service denial while maintaining fast connection establishment for legitimate base stations.
Data Source
AI summary
A user equipment (UE) may receive system information from a base station and may calculate a hash value using the system information as input to a hashing function. Similarly, prior to transmitting the system information, a valid base station may calculate a hash value using the system information as input to a hashing function. The base station may transmit the calculated hash value (e.g., which represent or be included in a set of hash values) to the UE in an access stratum (AS) security mode command (SMC) message. The UE may determine whether the received system information was modified based on the hash value (e.g., by comparing the UE calculated hash value and the set of hash values received from the base station in the AS SMC). If the UE indicates a mismatch of hash information, the base station may re-transmit the system information (e.g., in an integrity protected message).


