Physical-Layer Channel Authentication Against MITM and Replay Attacks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless communications systems are vulnerable to security risks such as man-in-the-middle and replay attacks, particularly in public forums, where malicious entities can exploit network protocols to gain unauthorized access and compromise network integrity.

Innovation Solution

A user equipment (UE) authenticates connections with a base station in the physical layer by comparing predicted measurement values of downlink reference signals with actual measurements, using previous measurements to identify unauthorized intervening devices based on velocity and other channel characteristics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If wireless communications are provided in public forums, then network coverage and accessibility are improved, but vulnerability to security attacks increases

Engineering Contradiction:
Improvenetwork coverageVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authentication by comparing predicted channel measurements (based on historical data and UE velocity) with actual measurements before allowing communication. This preliminary security check prevents unauthorized devices from establishing connections, addressing the security vulnerability while maintaining public network accessibility

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication mechanism that acts as a mediator between the UE and the base station. By inserting a verification layer that compares predicted versus actual channel characteristics, the system prevents direct exploitation between malicious devices and the network, resolving the contradiction between open access and security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If channel authentication is implemented, then network security is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system creates a virtual copy of the channel characteristics through prediction algorithms based on historical measurements and UE velocity. Instead of complex cryptographic authentication, it compares the predicted channel state (a copy of expected characteristics) with actual measurements, achieving security through a simpler measurement-based approach

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent transforms the authentication problem from complex protocol verification to simple parameter comparison. By changing the authentication parameters to measurable physical quantities (channel gain, delay spread, Doppler shift) and comparing them against predicted values, the system reduces computational complexity while maintaining security

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP4360350B1Methods and apparatus for maintaining transmission integrity and authenticity through channel measurements and reporting
Publication Date: 2025.11.26 QUALCOMM INC
  • EP4360350B1 patent drawingFigure 1
  • EP4360350B1 patent drawingFigure 2
  • EP4360350B1 patent drawingFigure 3

AI summary

The connection between a user equipment (UE) and a base station may be authenticated in the physical layer, and the presence of an unauthorized intervening device may be identified based on predicted measurement values of downlink reference signals and the actual measurement values for the current downlink reference signals. The predicted measurement values are produced based on previous measurements of downlink reference signals that are known to be received from the base station, e.g., after upper layer initial authentication. The predicted values may be for positioning measurements, channel measurements, or velocity or direction of travel measurements, or a combination thereof. A difference between the predicted and actual measurement values indicates that the previously received reference signals and the currently received reference signals are not from the same entity, and thus, an intervening entity is likely present in the communication channel performing a man in the middle or replay attack.