Authenticated RRCReject Messages for False Base Station Defense
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing approach to handling RRCReject messages in NR/NG-RAN is insecure, as these messages are not integrity protected and can be misused by false base stations for attacks like Denial of Service.
Innovation Solution
Implementing authenticated RRCReject messages using digital signatures based on asymmetric cryptography, where each gNB has a private key and UEs have the corresponding public keys, to verify the authenticity of the RRCReject messages.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If RRCReject messages are not integrity protected to simplify processing and reduce overhead, then device complexity and processing time are reduced, but security is compromised and false base stations can perform attacks
Solution Approach 1:
The patent applies preliminary action by pre-configuring UEs with public keys of legitimate gNBs before they need to verify RRCReject messages. This allows UEs to immediately verify message authenticity without adding complex real-time cryptographic operations, thus maintaining security while minimizing processing overhead and complexity.
Solution Approach 2:
The patent replaces the mechanical approach of trusting all RRCReject messages (no verification) with a cryptographic verification mechanism. By substituting simple acceptance with public key-based signature verification, the system achieves both security and efficiency, as modern cryptographic operations are computationally lightweight compared to the security risks they prevent.
2Quantity of substance
If RRCReject messages are transmitted without digital signatures to reduce message size and transmission overhead, then network bandwidth consumption is reduced, but security against false base station attacks is compromised
Solution Approach 1:
The patent pre-configures UEs with the public keys of legitimate gNBs through secure provisioning mechanisms during initial network access or device setup. This preliminary action enables UEs to verify RRCReject message signatures without requiring the public keys to be transmitted with each message, thus avoiding significant message size increases while maintaining security against false base station attacks.
Solution Approach 2:
The patent introduces digital signatures as an intermediary mechanism that provides security without substantially increasing message size. The signature is a compact cryptographic value that can be verified using pre-configured public keys, acting as a lightweight mediator that proves message authenticity without requiring transmission of large cryptographic materials like full key pairs or certificates.
3Productivity
If UEs automatically act on all received RRCReject messages to ensure proper network control, then network management efficiency is improved, but vulnerability to Denial of Service attacks from false base stations increases
Solution Approach 1:
The patent pre-configures UEs with public keys of legitimate gNBs before they need to verify RRCReject messages. This preliminary configuration enables UEs to automatically verify message authenticity and act on verified messages without manual intervention, maintaining network management efficiency while preventing false base station attacks through cryptographic verification.
Solution Approach 2:
The patent implements a feedback mechanism where UEs verify RRCReject message signatures using pre-configured public keys and only act on messages with valid signatures. This feedback loop ensures that network management actions are triggered only by authenticated messages, maintaining efficiency while providing automatic rejection of fraudulent messages from false base stations.
Data Source
AI summary
A method performed by a wireless device includes receiving a Radio Resources Control Reject (RRCReject) message and determining whether to act on the RRCReject message based on a configuration of the wireless device. The method may also include receiving a configuration message that includes the configuration from a network node.


