Authentication Capability Protection Against Bidding-Down Attacks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current telecommunications systems, such as UMTS and LTE, fail to protect authentication capabilities during the authentication process, making them vulnerable to bidding-down attacks and compromising security, as the protection of these capabilities occurs after authentication and relies on secure key management which may not always be guaranteed.

Innovation Solution

Integrating authentication capabilities into the authentication procedure by using the authentication capabilities information to determine cryptographic values on both the network and terminal sides, ensuring that any discrepancies in these values lead to failure of the authentication process, thus providing explicit or implicit verification of the authentication procedure's success.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication capabilities are protected after authentication using secure key management, then security is improved, but the authentication process becomes vulnerable to bidding-down attacks during the negotiation phase

Engineering Contradiction:
ImprovesecurityVSAvoidbidding-down attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by incorporating authentication capabilities into the authentication procedure itself, rather than protecting them afterward. The network and terminal both determine cryptographic values based on authentication capabilities during the authentication exchange, and any discrepancy causes authentication failure. This prevents bidding-down attacks during the capability negotiation phase by making the protection inherent to the authentication process.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If authentication capabilities are integrated into the authentication procedure, then protection against bidding-down attacks is improved, but the complexity of the authentication process increases

Engineering Contradiction:
Improveprotection against bidding-down attacksVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the authentication capabilities protection mechanism with the existing authentication procedure. Both the network and terminal determine cryptographic values (such as authentication tokens or keys) based on their authentication capabilities during the authentication exchange. This combination eliminates the need for separate capability protection mechanisms, thereby preventing bidding-down attacks without significantly increasing overall system complexity.

Inventive Principle:
Principle #5Merging (Combining)

3Measurement precision

If cryptographic values are determined based on authentication capabilities during authentication, then early detection of tampering is improved, but the risk of authentication failure due to value discrepancies increases

Engineering Contradiction:
Improvedetection of tamperingVSAvoidauthentication success rate
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent implements feedback by having both the network and terminal independently determine cryptographic values based on authentication capabilities and then compare these values. If the values match, authentication succeeds; if they differ, authentication fails. This feedback mechanism ensures that any tampering with authentication capabilities is detected, as it would cause a mismatch between the independently determined cryptographic values, while maintaining authentication success for legitimate cases.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9668139B2Secure negotiation of authentication capabilities
Publication Date: 2017.05.30 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US9668139B2 patent drawing
  • US9668139B2 patent drawing
  • US9668139B2 patent drawing

AI summary

A network (20) comprises an authenticator node (22) and a server (24) such as an authentication, authorization, and accounting (AAA) server. A method comprises a terminal (30) sending authentication capabilities information (AC) across a network access interface (32) to the network (the authentication capabilities information provides an indication of authentication capabilities of the terminal). The network (20) then uses the authentication capabilities information to determine a first cryptographic value. The terminal (30) then uses the authentication capabilities information to determine a second cryptographic value. The network (20) compares the first cryptographic value and the second cryptographic value to authenticate the terminal.