Base Station Authenticity Validation in 5G RRC Idle State

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G wireless communication systems, there is a lack of mechanisms to authenticate base stations and information received by user equipment in RRC idle states, leading to potential service denial and interference due to incorrect resource configuration and fake cell connections.

Innovation Solution

A method and system for authenticating base stations and information received by user equipment, involving the generation and transmission of authenticity information, such as message authentication codes or digital signatures, associated with system information, to ensure the authenticity of the cell and information received.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If user equipment camps on a cell without authentication in RRC idle state, then the UE can perform basic operations like monitoring paging channel and acquiring system information, but the UE may connect to fake cells or receive incorrect system information leading to service denial and interference

Engineering Contradiction:
ImproveUE ability to camp on cell and perform basic operationsVSAvoidauthenticity of base station and system information
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The base station generates authenticity information (digital signature or MAC) in advance and includes it in the system information broadcast before the UE camps on the cell. This preliminary authentication mechanism allows the UE to verify the authenticity of the base station and system information without requiring additional authentication steps after cell selection, thus resolving the contradiction between ease of operation and reliability.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the base station transmits authenticity information with system information, then the UE can validate the authenticity of the base station and system information, but the system complexity and signaling overhead increase

Engineering Contradiction:
Improveauthenticity validation capabilityVSAvoidsystem complexity for generating and processing authenticity information
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The base station acts as an intermediary that signs the system information using its private key to generate authenticity information. The UE uses the corresponding public key to verify this signature. This intermediary authentication mechanism enables reliable authenticity validation without requiring complex mutual authentication protocols between multiple entities, thus resolving the contradiction between reliability and system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the base station uses digital signature for authenticity information, then the UE can securely validate the base station identity, but the processing time and computational complexity at the UE increase

Engineering Contradiction:
Improvesecurity of base station authenticationVSAvoidtime for UE to process and validate authenticity information
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system uses digital signature authentication which provides complete security validation but requires significant processing time. As an alternative, the patent also describes using Message Authentication Codes (MAC) which provide sufficient authentication for the application needs with much lower computational complexity and processing time. This gives the system flexibility to choose the appropriate authentication strength based on security requirements versus processing constraints, resolving the contradiction between security and processing time.

Inventive Principle:
Principle #16Partial or excessive action

4Reliability

If the UE validates system information authenticity before using it, then the UE avoids service denial and interference from incorrect configurations, but the UE cannot use resources immediately and service setup time increases

Engineering Contradiction:
Improvecorrectness of resource configurationVSAvoidtime for authenticity validation
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The authenticity information (digital signature or MAC) is generated by the base station and included in the system information broadcast before the UE needs to use the resources. The UE performs validation of this pre-included authenticity information as part of the system information acquisition process, not as a separate subsequent step. This allows the UE to immediately use the validated system information for resource configuration without additional validation delays, resolving the contradiction between reliability and service setup time.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10306470B2System and method for validating authenticity of base station and/or information received from base station
Publication Date: 2019.05.28 SAMSUNG ELECTRONICS CO LTD
  • US10306470B2 patent drawing
  • US10306470B2 patent drawing
  • US10306470B2 patent drawing

AI summary

A communication method and a system for converging a 5th-Generation (5G) communication system for supporting higher data rates beyond a 4th-Generation (4G) system with a technology for internet of things (IoT) are provided. The present disclosure may be applied to intelligent services based on the 5G communication technology and the IoT-related technology, such as smart home, smart building, smart city, smart car, connected car, health care, digital education, smart retail, security and safety services. A system and a method for validating authenticity of a base station and/or information received from the base station are provided. The method for determining authenticity of system information received from a base station and a cell operated by the base station includes receiving, from a base station, system information, receiving, from a base station, system information, receiving, from the base station, first authenticity information associated with the system information, determining whether the system information is authentic based on the first authenticity information, and determining that a cell operated by the base station is authentic if the system information is authentic.