Dynamic Routing Indicator for 5G Network Replay Attack Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing 5G/NR networks are vulnerable to malicious actors who can disrupt operations by sending repeated malicious configuration or registration requests using fixed and limited routing indicators, leading to resource wastage and potential denial of service to authentic users.
Innovation Solution
Implementing a unique routing indicator specific to each user equipment (UE) and request, which is shared with the network, and independently generating a new routing indicator using a shared encryption technique for subsequent requests, thereby increasing the number of possible indicators and reducing the risk of malicious attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If fixed routing indicators are used for network connection requests, then device complexity is reduced and ease of operation is improved, but the network becomes vulnerable to malicious attacks and resource wastage increases
Solution Approach 1:
The patent implements dynamic routing indicators that change over time through periodic updates and event-triggered changes. The routing indicator is no longer fixed but evolves based on time intervals, security events, or network conditions, making it difficult for malicious actors to predict or exploit while maintaining operational simplicity for legitimate users
Solution Approach 2:
The patent changes the parameter of the routing indicator from a static fixed value to a dynamic value that varies based on time, security events, or network conditions. This parameter transformation increases the security space and prevents replay attacks while the network manages the complexity of generation and validation
2Device complexity
If fixed routing indicators are used, then device complexity is reduced, but resource wastage increases due to processing malicious requests
Solution Approach 1:
The patent implements preliminary validation of routing indicators before processing authentication requests. The network validates whether the routing indicator is current and legitimate before allocating authentication resources, preventing waste on malicious requests while keeping the validation mechanism simple and efficient
Solution Approach 2:
The patent implements feedback mechanisms where the network monitors routing indicator usage patterns and adjusts validation strictness or updates indicators based on detected threats. This feedback loop optimizes resource allocation by intensifying security measures only when necessary, reducing overall resource wastage
3Ease of operation
If fixed routing indicators are used, then ease of operation is improved, but reliability of network service deteriorates due to denial of service attacks
Solution Approach 1:
The dynamic routing indicator mechanism ensures service reliability by preventing denial of service attacks through replay exploitation. Legitimate users experience no operational difficulty as the network automatically manages indicator updates and validation, while malicious replay attacks are blocked due to the changing indicator values
4Object-affected harmful factors
If unique routing indicators are generated for each request, then security against malicious attacks is improved, but device complexity and processing overhead increase
Solution Approach 1:
The patent segments the security function by separating routing indicator generation and validation responsibilities. The network handles complex generation and validation logic, while user devices simply use provided indicators, distributing complexity appropriately and reducing overall system burden
Solution Approach 2:
The routing indicator serves multiple functions simultaneously: it acts as a routing identifier, a security token for replay prevention, and a validation mechanism. This multi-functionality reduces the need for separate security components, managing complexity while enhancing security
Data Source
AI summary
In some implementations, a device of a network may receive, from a user equipment (UE), a request associated with enabling the UE to access a network, wherein the request includes a first routing indicator. The device may identify an authentication manager, of the network, that is mapped to the first routing indicator in an entry of a routing table of the network. The device may route the request to the authentication manager of the network to permit the authentication manager to authenticate the UE. The device may purge, based on the request being routed to the authentication manager, the entry to remove the first routing indicator from the routing table. The device may store, after purging the entry, a second routing indicator in the entry to map the second routing indicator to the authentication manager, wherein the second routing indicator is different from the first routing indicator.


