Base Station Origination Address Verification for Handover Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The current radio communication systems face challenges in ensuring security during handovers, particularly in verifying the origination addresses of base stations, which can lead to potential DoS attacks and system failures due to the manual and costly process of setting these addresses, especially in roaming environments.

Innovation Solution

The system transmits information of the origination addresses of neighboring base stations or movement destination base stations from the base station to the mobility management node and gateway, enabling the gateway to verify the safety of packet data received during handovers, thereby reducing manual operations and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the origination address of eNode B is set in S-GW by manual operation of an operator, then the security verification of uplink packet data is ensured, but the operation complexity and cost increase significantly

Engineering Contradiction:
Improvesecurity verificationVSAvoidmanual operation complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables automatic acquisition of eNode B origination address information through signaling messages exchanged between eNode B and S-GW during handover procedures. The eNode B autonomously provides its identification information to the S-GW without requiring manual configuration, allowing the system to self-configure security verification parameters.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The S-GW receives feedback information containing the eNode B's origination address from the eNode B during handover signaling. This feedback mechanism allows the S-GW to automatically update its security verification database with current eNode B addresses, eliminating the need for manual operator input and enabling dynamic security verification.

Inventive Principle:
Principle #23Feedback

2Reliability

If manual setting of origination addresses is performed for each eNode B, then security verification is ensured, but the time required for system setup and expansion increases

Engineering Contradiction:
Improvesecurity verificationVSAvoidsystem setup time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary action by pre-configuring the S-GW to automatically acquire and store eNode B origination address information through standardized signaling protocols. During initial system setup, the S-GW establishes the capability to receive and verify address information automatically, eliminating the need for time-consuming manual configuration of each eNode B individually.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system maintains continuous security verification capability through automated address acquisition during ongoing handover procedures. Rather than requiring one-time manual setup, the S-GW continuously receives and processes origination address information from eNode B signaling messages, ensuring persistent security verification without repeated manual intervention.

Inventive Principle:
Principle #20Continuity of useful action

3Productivity

If automatic acquisition of neighboring base station addresses is implemented, then operational efficiency improves, but the system complexity increases

Engineering Contradiction:
Improveoperational efficiencyVSAvoidsystem architecture complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The existing handover signaling messages between eNode B and S-GW are made multi-functional, serving both the handover control function and the security verification function. The same signaling protocol used for handover management now simultaneously carries origination address information for security verification, eliminating the need for separate dedicated systems and reducing overall complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system merges the address acquisition function with the existing handover signaling mechanism. The S-GW integrates the reception and processing of eNode B origination address information into its existing handover management procedures, combining multiple functions (handover control and security verification) into a unified process rather than creating separate independent systems.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9271195B2Radio communication system, base station, gateway, and radio communication method
Publication Date: 2016.02.23 NEC CORP
  • US9271195B2 patent drawing
  • US9271195B2 patent drawing
  • US9271195B2 patent drawing

AI summary

The radio communication system of the present invention includes a base station (10), a mobility management node (20), and a gateway (30). The base station (10) transmits to the mobility management node (20) information of the origination addresses of neighboring base stations of the base station (10). The mobility management node (20) receives information of the origination addresses of the neighboring base stations from the base station (10) and transmits the information of the origination addresses of the neighboring base stations to the gateway (30). The gateway (30) receives information of the origination addresses of the neighboring base stations from the mobility management node (20).