Context Cookies for Connectionless Security in Wireless Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless communication systems, idle user equipment must repeatedly transition to an active state to re-establish a security context for secure data transmission, incurring significant signaling overhead, especially for small messages, and are vulnerable to denial-of-service attacks due to inability to uniquely identify requesting devices.

Innovation Solution

Implementing a connectionless data transmission method using tokens and context cookies to allow idle user equipment to transmit data securely without re-establishing a new security context, with the base station storing AS security contexts and using cookies to identify legitimate requests, thereby preventing resource exhaustion from malicious attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If idle user equipment transitions to active state to re-establish security context for each message transmission, then secure communication is maintained, but signaling overhead increases significantly

Engineering Contradiction:
Improvesecure communicationVSAvoidsignaling overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The base station performs preliminary actions by storing the AS security context and generating a context identifier (cookie) before the user equipment needs to transmit data. This pre-stored context allows the idle user equipment to resume communication without repeating the full service request procedure, thus reducing signaling overhead while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The base station creates a copy of the AS security context and stores it locally, along with generating a context identifier (cookie). This copy enables the base station to quickly authenticate returning user equipment without needing to re-establish the complete security context through MME, significantly reducing the signaling overhead for small messages.

Inventive Principle:
Principle #26Copying

2Reliability

If base station deletes user equipment identification information after communication, then security is maintained, but ability to recognize returning user equipment is lost

Engineering Contradiction:
ImprovesecurityVSAvoiddevice recognition
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The context identifier (cookie) acts as an intermediary between the deleted TMSI and the stored AS security context. The base station deletes the original TMSI for security but retains the cookie which can be used to retrieve the corresponding AS security context when the user equipment returns, thus maintaining both security and the ability to recognize returning devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If base station stores AS security context for connectionless service, then small message transmission efficiency improves, but vulnerability to denial-of-service attacks increases

Engineering Contradiction:
Improvemessage transmission efficiencyVSAvoiddenial-of-service attacks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The base station extracts only the essential AS security context and context identifier (cookie) needed for connectionless service, storing them separately from the complete security establishment procedure. This selective storage allows efficient small message transmission while limiting the exposure to denial-of-service attacks by not storing unnecessary information that could be exploited.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9590962B2Using cookies to identify security contexts for connectionless service
Publication Date: 2017.03.07 NOKIA OF AMERICA CORP
  • US9590962B2 patent drawing
  • US9590962B2 patent drawing
  • US9590962B2 patent drawing

AI summary

A mobility management entity (MME) receives a request for a key to establish a security context for communication between a base station and a user equipment in response to the user equipment requesting connectionless service with the base station. In response to receiving the request, the MME transmits a cookie to identify the security context stored by the base station.