Integrity Protection for Cellular System Broadcast Messages
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cellular mobile networks, including 5G, lack adequate security measures to protect system broadcast messages from attacks like signal overshadowing, which can manipulate user equipment to connect with fake base stations of lower security levels, compromising user communication.
Innovation Solution
The method involves receiving a master information block and system information blocks from a base station, with at least one additional block being transmitted integrity-proofed through cryptographic hashing or encryption, using a key received during connection establishment, and optionally pre-configured in a SIM or UICC, to ensure the integrity and authenticity of system broadcast messages.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If system broadcast messages are transmitted unprotected to maintain ease of operation and network accessibility, then user equipment can easily connect to the network, but the messages become vulnerable to signal-overshadowing attacks and integrity compromises
Solution Approach 1:
The patent applies preliminary action by pre-configuring integrity protection mechanisms and authentication keys in the UE before network connection. The integrity of system broadcast messages is verified using pre-shared keys stored in the UE, allowing the device to authenticate messages before trusting them, thus maintaining both security and ease of operation.
Solution Approach 2:
The patent introduces an intermediary integrity verification mechanism that acts as a mediator between the untrusted broadcast channel and the UE. The verification function using pre-configured keys serves as this intermediary, allowing the UE to selectively trust messages without compromising network accessibility.
2Reliability
If integrity protection mechanisms are implemented on system broadcast messages to prevent attacks, then security against signal-overshadowing is improved, but the complexity of the transmission system increases
Solution Approach 1:
The patent applies local quality by implementing integrity protection selectively on specific system broadcast messages that require security (such as those containing cell selection or mobility information) rather than all broadcast messages. This targeted approach maintains security for critical messages while minimizing added complexity.
Solution Approach 2:
The patent changes the parameter of message authentication from none to integrity-protected for specific messages. By modifying only the authentication parameter of selected broadcast messages and using efficient verification methods with pre-configured keys, the system achieves improved security with minimal complexity increase.
3Reliability
If cryptographic hash functions and integrity operations are applied to system information blocks, then message authenticity is verified, but processing time and computational resources increase
Solution Approach 1:
The patent applies partial action by performing integrity verification only on specific system information blocks that contain critical information (such as cell selection and mobility parameters) rather than all broadcast messages. This selective verification reduces processing time while maintaining security for the most critical messages.
Solution Approach 2:
The patent uses efficient cryptographic hash functions and lightweight integrity verification mechanisms that require minimal computational resources. The use of pre-configured symmetric keys and efficient hash algorithms provides fast verification with low processing overhead.
Data Source
Figure 1
Figure 2
AI summary
The present disclosure relates to a method of ensuring integrity of system broadcast messages in a cellular mobile communications network. The method comprises receiving of a master information block (MIB) by a user equipment (UE) from a base station over a physical broadcast channel (PBCH). At least one system information Block (SIB) is received by the UE from the base station comprising configuration information. At least one additional SIB is received by the UE from the base station which comprises cell selection information and/or cell reselection information and/or neighbouring cell information. At least one of the additional SIBs is transmitted integrity proof.