Authentication Code Freshness in Mobile Handover Signaling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In mobile communications systems, especially in the evolved 3GPP (LTE) network, there is a security issue with replay attacks on NAS tokens during handovers, as the freshness of NAS tokens is not guaranteed beyond idle handovers, allowing attackers to misuse tokens before new E-UTRAN-level NAS messages are sent.

Innovation Solution

Generating an authentication code based on a previous authentication code and storing it for subsequent use, transmitting this code in control messages during access network changes to ensure verification by network entities, thereby enhancing the freshness and security of authentication tokens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a NAS token is used for authentication during handover, then authentication capability is provided, but the freshness of the token cannot be guaranteed beyond idle handovers, allowing replay attacks

Engineering Contradiction:
Improveauthentication capabilityVSAvoidreplay attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by generating a fresh authentication code before each handover event. The authentication code is derived from the previous code combined with a handover identifier, ensuring that a new code is prepared in advance for the upcoming handover. This prevents replay attacks because the code changes with each handover event, making any previously captured code invalid for subsequent handovers.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the parameter of the authentication code by deriving a new code from the previous code using a handover identifier. This parameter change ensures that the authentication code evolves with each handover event, maintaining freshness and preventing replay attacks. The code is no longer static but dynamically changes based on the handover context.

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If sequence numbers are used to ensure NAS token freshness, then replay attacks are prevented, but synchronized event management and system complexity increase

Engineering Contradiction:
Improvereplay attacksVSAvoidsynchronized event management
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent extracts the sequence number management complexity from the authentication mechanism. Instead of using sequence numbers that require synchronized updates and management across multiple entities, the patent uses a simpler authentication code derivation based on the previous code and handover identifier. This extraction eliminates the need for complex synchronized event management while still preventing replay attacks.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses disposable authentication codes that are generated fresh for each handover and then discarded. Rather than maintaining long-lived sequence numbers that require continuous synchronization, the authentication code is created, used once for authentication, and then replaced. This approach simplifies the system by eliminating the need for complex lifecycle management of authentication state.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Device complexity

If NAS tokens are reused across multiple handovers, then system complexity is reduced, but security is compromised due to potential replay attacks

Engineering Contradiction:
ImproveNAS token handlingVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent applies preliminary action by preparing a new authentication code before each handover event. The code is derived from the previous code combined with a handover identifier, ensuring that a fresh code is ready for the upcoming handover. This prevents security compromises because the code changes with each handover, making reused codes invalid and preventing replay attacks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the parameter of the authentication code by deriving a new code from the previous code using a handover identifier. This parameter change ensures that even though the mechanism remains simple, the security is maintained through dynamic code generation. The code evolves with each handover event, preventing reuse and replay attacks while keeping the system simple.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8145195B2Mobility related control signalling authentication in mobile communications system
Publication Date: 2012.03.27 NOKIA TECHNOLOGIES OY
  • US8145195B2 patent drawing
  • US8145195B2 patent drawing
  • US8145195B2 patent drawing

AI summary

In a non-limiting and exemplary embodiment, a method is provided for arranging authentication of mobility related signalling messages in a mobile communications system. An authentication code is generated on the basis of a previous authentication code stored in connection with a preceding authentication code generation event. The newly generated authentication code is stored for subsequent authentication code generation event. In response to change of the mobile device to an access network of the network entity, a control message comprising the authentication code is transmitted from a mobile device to a first network entity, for verifying the authentication code by the first network entity or by a second network entity of a previous access system.