D2D Discovery Replay Attack Prevention via Network Timing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wireless communication systems face security vulnerabilities in device-to-device (D2D) discovery communications due to the potential for replay attacks, where rogue base stations can hijack and replay D2D discovery messages, compromising the authenticity and integrity of these communications.
Innovation Solution
The solution involves receiving a timing variable from a network while in a connected mode, using it for D2D discovery message authentication, and comparing it with a local timing variable to verify authenticity. This includes generating a Message Integrity Code (MIC) using the timing variable and associated key, and transmitting it with D2D discovery announcements to ensure secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If D2D discovery communication is enabled for direct device communication, then communication efficiency and coverage are improved, but security vulnerabilities arise due to potential replay attacks by rogue base stations
Solution Approach 1:
The network assigns a timing variable to the UE in advance during connected mode before the actual D2D discovery message transmission. This preliminary assignment ensures the UE has a trusted reference timing value that can be used to authenticate future discovery messages, preventing replay attacks while maintaining communication efficiency.
Solution Approach 2:
The timing variable acts as an intermediary authentication element between the network and the UE. Instead of direct cryptographic authentication of each discovery message, the timing variable serves as a trusted mediator that both the network and UE can use to verify message authenticity, simplifying the security mechanism while maintaining reliability.
2Reliability
If timing variable verification is implemented for D2D discovery messages, then security against replay attacks is improved, but device complexity and processing overhead increase
Solution Approach 1:
The patent transforms the security verification from complex cryptographic operations to a simpler timing parameter comparison. By changing the authentication mechanism to use timing variables that can be compared directly, the patent reduces device complexity and processing overhead while maintaining security against replay attacks.
Solution Approach 2:
The timing variable is a simple, easily generated numerical value that expires or changes over time. This disposable-like authentication element can be quickly generated and verified without complex processing, reducing device complexity while providing effective security. The timing variable is replaced or updated periodically, similar to disposable security tokens.
3Measurement precision
If the UE stores and compares timing variables locally, then message authentication accuracy is improved, but memory usage and processing time increase
Solution Approach 1:
The UE stores the timing variable locally in its memory for comparison with received discovery messages. This local storage enables fast, accurate authentication without requiring continuous network communication. The timing variable occupies minimal memory space while providing precise authentication capability for each discovery message.
Solution Approach 2:
Instead of storing multiple authentication credentials or complex security data, the UE stores only the essential timing variable needed for authentication. This partial approach stores only the minimum necessary information to achieve secure authentication, reducing memory usage while maintaining sufficient accuracy for replay attack prevention.
Data Source
AI summary
Methods, systems, and devices are described for device-to-device (D2D) wireless communication. A device may receive a timing variable from a network while the device is in a connected mode. The device may then use the timing variable for D2D discovery message authentication. The device may compare the timing variable with a local timing variable to determine whether a difference between the two variables is within a maximum allowable offset. The device may announce the D2D discovery message to another device when the difference is within the maximum allowable offset.


