Identity-Based Message Integrity for Wireless Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless communication systems are vulnerable to eavesdropping and attacks from rogue network entities before the establishment of a security context, as messages are transmitted in an unencrypted format, allowing fake base stations to intercept and manipulate information.

Innovation Solution

Implementing identity-based message integrity protection and verification using signatures derived from identity-based keys, where a wireless device verifies messages using a public key generated from an identity value and a private key generator server's public key, ensuring message integrity before security context activation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If messages are transmitted in unencrypted format before security context activation, then communication simplicity is maintained, but security vulnerability increases allowing eavesdropping and rogue entity attacks

Engineering Contradiction:
Improvecommunication simplicityVSAvoidmessage integrity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by implementing message integrity protection mechanisms before the security context is fully activated. The network entity generates and transmits integrity protection information (such as MAC values or signatures) along with messages during the initial phase, allowing the wireless device to verify message integrity before establishing secure encryption channels. This prevents rogue entities from injecting or modifying messages during the vulnerable pre-authentication period.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If identity-based verification is implemented before security context establishment, then protection against rogue network entities is improved, but computational complexity increases due to signature generation and verification

Engineering Contradiction:
Improveprotection against rogue entitiesVSAvoidcomputational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by implementing identity-based verification selectively for critical messages during the pre-security context phase, rather than applying full cryptographic verification to all messages. The network entity generates integrity protection information using its identity-based private key for specific control messages (such as system information blocks, random access responses), and the wireless device verifies only these targeted messages. This approach provides focused protection where most needed while minimizing overall computational overhead.

Inventive Principle:
Principle #3Local quality

3Reliability

If message integrity protection is provided during pre-security communication, then security is improved, but message transmission overhead increases due to additional protection information

Engineering Contradiction:
Improvemessage integrityVSAvoidmessage size
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent applies partial action by providing integrity protection for only the most critical messages during the pre-security context establishment phase, rather than protecting all messages equally. Specifically, the network entity generates integrity protection information (such as MAC values or digital signatures) for essential control messages like system information blocks, random access responses, and authentication requests. For less critical messages, the patent may omit integrity protection or use lighter-weight verification mechanisms, thereby balancing security requirements with transmission efficiency.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11856402B2Identity-based message integrity protection and verification for wireless communication
Publication Date: 2023.12.26 APPLE INC
  • US11856402B2 patent drawing
  • US11856402B2 patent drawing
  • US11856402B2 patent drawing

AI summary

Techniques for identity-based message integrity protection and verification between a user equipment (UE) and a wireless network entity, include use of signatures derived from identity-based keys. To protect against attacks from rogue network entities before activation of a security context with a network entity, the UE verifies integrity of messages by checking a signature using an identity-based public key PKID derived by the UE based on (i) an identity value (ID) of the network entity and (ii) a separate public key PKPKG of a private key generator (PKG) server. The network entity generates signatures for messages using an identity-based private key SKID obtained from the PKG server, which generates the identity-based private key SKID using (i) the ID value of the network entity and (ii) a private key SKPKG that is known only by the PKG server and corresponds to the public key PKPKG.