Compromised Equipment Detection via Protocol Error Injection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional communication systems lack effective methods to detect compromised user equipment (UE) and access point equipment that maliciously exploit network functionalities, particularly in 5G networks, where AI/ML models are used for network optimizations, and existing protocols do not provide transparent detection mechanisms.

Innovation Solution

Intentionally introducing errors in communication protocol layers and using error counters to verify whether user equipment, access points, or network entities are compromised, allowing for detection without the malicious equipment being aware of the detection techniques.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If conventional communication protocols are used in 5G networks, then network efficiency and subscriber convenience are improved, but security against compromised equipment deteriorates

Engineering Contradiction:
Improvenetwork efficiencyVSAvoidsecurity against compromised equipment
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary actions by intentionally introducing errors into communication protocols before actual malicious activity occurs. Error indicators are proactively injected at protocol layers (e.g., PDCP layer MAC-I verification failures) to establish a baseline for detecting compromised equipment before real security threats can exploit the network.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Error indicators serve as an intermediary mechanism between the network and compromised equipment. Instead of directly detecting malicious behavior, the system uses error indicators as a mediator that compromised equipment cannot distinguish from legitimate errors, allowing indirect detection of security breaches while maintaining normal protocol operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If error indicators are introduced to detect compromised equipment, then security detection capability is improved, but device complexity increases

Engineering Contradiction:
Improvecompromised equipment detectionVSAvoidprotocol layer complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The error indicator mechanism serves multiple functions simultaneously: it maintains backward compatibility with existing 5G protocols, provides security detection capability, and operates across multiple protocol layers (particularly PDCP layer integrity verification). This multi-functionality reduces the need for separate dedicated detection systems, thereby limiting the increase in overall device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system changes parameters within existing protocols rather than introducing entirely new mechanisms. By modifying error indicator parameters (such as MAC-I verification failure counts) within the framework of existing 5G protocols, the system achieves enhanced detection capability while minimizing structural complexity additions to the protocol stack.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If AI/ML models are used for network optimization, then network performance is improved, but vulnerability to manipulation by compromised equipment increases

Engineering Contradiction:
Improvenetwork performanceVSAvoidmanipulation vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system applies preliminary anti-action by introducing error indicators that preemptively counteract manipulation attempts before they can affect AI/ML models. Error indicators are injected into the network traffic that compromised equipment cannot distinguish from legitimate errors, preventing them from successfully manipulating AI/ML-based network optimization functions.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The system converts the presence of compromised equipment attempting manipulation into a beneficial detection opportunity. By monitoring error indicators that arise during manipulation attempts, the system transforms harmful activities into useful security detection data, allowing AI/ML models to be protected while maintaining their performance benefits.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS20240056476A1Security management with compromised-equipment detection in a communication system
Publication Date: 2024.02.15 NOKIA TECHNOLOGIES OY
  • US20240056476A1 patent drawing
  • US20240056476A1 patent drawing
  • US20240056476A1 patent drawing

AI summary

Techniques for security management with compromised-equipment detection in a communication system are disclosed. For example, a method comprises causing intentional introduction of one or more errors in at least one communication protocol layer of a communication network, wherein the communication network has a plurality of user equipment connected thereto via at least one access point. The method further comprises causing verification of one or more received error indicators against one or more expected error indicators to decide whether any of: (i) the plurality of user equipment; (ii) the at least one access point; or (iii) one or more network entities, may be compromised. In other examples, verifications may be correlated with other logs including, for example, security event logs.