Dynamic Routing Indicator for 5G Network Replay Attack Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing 5G/NR networks are vulnerable to malicious actors who can disrupt operations by sending repeated malicious configuration or registration requests using fixed and limited routing indicators, leading to resource wastage and potential denial of service to authentic users.

Innovation Solution

Implementing a unique routing indicator specific to each user equipment (UE) and request, which is shared with the network, and independently generating a new routing indicator using a shared encryption technique for subsequent requests, thereby increasing the number of possible indicators and reducing the risk of malicious attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If fixed routing indicators are used for network connection requests, then device complexity is reduced and ease of operation is improved, but the network becomes vulnerable to malicious attacks and resource wastage increases

Engineering Contradiction:
Improveease of operationVSAvoidmalicious attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic routing indicators that change over time through periodic updates and event-triggered changes. The routing indicator is no longer fixed but evolves based on time intervals, security events, or network conditions, making it difficult for malicious actors to predict or exploit while maintaining operational simplicity for legitimate users

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of the routing indicator from a static fixed value to a dynamic value that varies based on time, security events, or network conditions. This parameter transformation increases the security space and prevents replay attacks while the network manages the complexity of generation and validation

Inventive Principle:
Principle #35Parameter changes

2Device complexity

If fixed routing indicators are used, then device complexity is reduced, but resource wastage increases due to processing malicious requests

Engineering Contradiction:
Improvedevice complexityVSAvoidresource wastage
Core Design Contradiction:
Device complexityVSLoss of energy

Solution Approach 1:

The patent implements preliminary validation of routing indicators before processing authentication requests. The network validates whether the routing indicator is current and legitimate before allocating authentication resources, preventing waste on malicious requests while keeping the validation mechanism simple and efficient

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the network monitors routing indicator usage patterns and adjusts validation strictness or updates indicators based on detected threats. This feedback loop optimizes resource allocation by intensifying security measures only when necessary, reducing overall resource wastage

Inventive Principle:
Principle #23Feedback

3Ease of operation

If fixed routing indicators are used, then ease of operation is improved, but reliability of network service deteriorates due to denial of service attacks

Engineering Contradiction:
Improveease of operationVSAvoidservice availability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The dynamic routing indicator mechanism ensures service reliability by preventing denial of service attacks through replay exploitation. Legitimate users experience no operational difficulty as the network automatically manages indicator updates and validation, while malicious replay attacks are blocked due to the changing indicator values

Inventive Principle:
Principle #15Dynamics

4Object-affected harmful factors

If unique routing indicators are generated for each request, then security against malicious attacks is improved, but device complexity and processing overhead increase

Engineering Contradiction:
Improvemalicious attacksVSAvoiddevice complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent segments the security function by separating routing indicator generation and validation responsibilities. The network handles complex generation and validation logic, while user devices simply use provided indicators, distributing complexity appropriately and reducing overall system burden

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The routing indicator serves multiple functions simultaneously: it acts as a routing identifier, a security token for replay prevention, and a validation mechanism. This multi-functionality reduces the need for separate security components, managing complexity while enhancing security

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250106639A1Systems and methods for using a unique routing indicator to connect to a network
Publication Date: 2025.03.27 VERIZON PATENT & LICENSING INC
  • US20250106639A1 patent drawing
  • US20250106639A1 patent drawing
  • US20250106639A1 patent drawing

AI summary

In some implementations, a device of a network may receive, from a user equipment (UE), a request associated with enabling the UE to access a network, wherein the request includes a first routing indicator. The device may identify an authentication manager, of the network, that is mapped to the first routing indicator in an entry of a routing table of the network. The device may route the request to the authentication manager of the network to permit the authentication manager to authenticate the UE. The device may purge, based on the request being routed to the authentication manager, the entry to remove the first routing indicator from the routing table. The device may store, after purging the entry, a second routing indicator in the entry to map the second routing indicator to the authentication manager, wherein the second routing indicator is different from the first routing indicator.