Authentication Token Generation for RRC Reestablishment Integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The RRCReestablishmentRequest message in current technologies is not protected against tampering, making it vulnerable to attacks, particularly due to the absence of authentication for the ReestablishmentCause field and potential new fields in future messages.
Innovation Solution
A method for generating an authentication token is introduced, which involves obtaining a request message containing a reestablishment cause value and an identity value, and using these values to create an authentication token, ensuring the integrity of the RRC connection re-establishment procedure by validating the shortMAC-I token.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the RRCReestablishmentRequest message is transmitted without authentication protection, then the message structure remains simple and the procedure is easy to implement, but the message becomes vulnerable to tampering attacks and lacks security
Solution Approach 1:
The patent applies preliminary action by pre-defining the authentication token generation mechanism before the actual message transmission. The network node prepares the authentication token in advance based on the request message content, and the UE is configured to generate and include this token in the RRCReestablishmentRequest message. This preliminary preparation ensures that when the message is transmitted, authentication protection is already in place, preventing tampering without adding complexity during the transmission process itself.
2Reliability
If authentication token generation is implemented for the RRCReestablishmentRequest message, then security against tampering is improved, but the message processing complexity increases
Solution Approach 1:
The patent applies self-service by enabling the UE to autonomously generate the authentication token using its own security context and the request message content. The UE calculates the authentication token based on predefined algorithms and includes it in the message without requiring external assistance. This self-service approach reduces the processing burden on the network node while maintaining strong authentication security, as the UE handles the complex cryptographic operations independently.
3Reliability
If the ReestablishmentCause field is not protected, then the message structure remains simple and future fields can be added easily, but the field becomes susceptible to attacker modification
Solution Approach 1:
The patent applies universality by implementing a comprehensive authentication mechanism that protects the entire RRCReestablishmentRequest message structure, including the ReestablishmentCause field and any future fields that may be added. The authentication token is generated based on all message contents, making the protection mechanism universal across current and future message versions. This approach ensures that new fields added in future specifications will automatically be covered by the same authentication mechanism, maintaining both security and adaptability without requiring field-specific protection strategies.
Data Source
AI summary
Embodiments of the present disclosure includes methods for generating an authentication token. One of the methods comprising obtaining a first request message that comprises: a first field containing a first value, a second field containing a second value, and a third field containing a pre-defined token value; and using the first request message to generate an authentication token.


