Identity-Based Message Integrity for Wireless Communication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wireless communication systems are vulnerable to eavesdropping and attacks from rogue network entities before the establishment of a security context, as messages are transmitted in an unencrypted format, allowing fake base stations to intercept and manipulate information.
Innovation Solution
Implementing identity-based message integrity protection and verification using signatures derived from identity-based keys, where a wireless device verifies messages using a public key generated from an identity value and a private key generator server's public key, ensuring message integrity before security context activation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If messages are transmitted in unencrypted format before security context activation, then communication simplicity is maintained, but security vulnerability increases allowing eavesdropping and rogue entity attacks
Solution Approach 1:
The patent applies preliminary action by implementing message integrity protection mechanisms before the security context is fully activated. The network entity generates and transmits integrity protection information (such as MAC values or signatures) along with messages during the initial phase, allowing the wireless device to verify message integrity before establishing secure encryption channels. This prevents rogue entities from injecting or modifying messages during the vulnerable pre-authentication period.
2Reliability
If identity-based verification is implemented before security context establishment, then protection against rogue network entities is improved, but computational complexity increases due to signature generation and verification
Solution Approach 1:
The patent applies local quality by implementing identity-based verification selectively for critical messages during the pre-security context phase, rather than applying full cryptographic verification to all messages. The network entity generates integrity protection information using its identity-based private key for specific control messages (such as system information blocks, random access responses), and the wireless device verifies only these targeted messages. This approach provides focused protection where most needed while minimizing overall computational overhead.
3Reliability
If message integrity protection is provided during pre-security communication, then security is improved, but message transmission overhead increases due to additional protection information
Solution Approach 1:
The patent applies partial action by providing integrity protection for only the most critical messages during the pre-security context establishment phase, rather than protecting all messages equally. Specifically, the network entity generates integrity protection information (such as MAC values or digital signatures) for essential control messages like system information blocks, random access responses, and authentication requests. For less critical messages, the patent may omit integrity protection or use lighter-weight verification mechanisms, thereby balancing security requirements with transmission efficiency.
Data Source
AI summary
Techniques for identity-based message integrity protection and verification between a user equipment (UE) and a wireless network entity, include use of signatures derived from identity-based keys. To protect against attacks from rogue network entities before activation of a security context with a network entity, the UE verifies integrity of messages by checking a signature using an identity-based public key PKID derived by the UE based on (i) an identity value (ID) of the network entity and (ii) a separate public key PKPKG of a private key generator (PKG) server. The network entity generates signatures for messages using an identity-based private key SKID obtained from the PKG server, which generates the identity-based private key SKID using (i) the ID value of the network entity and (ii) a private key SKPKG that is known only by the PKG server and corresponds to the public key PKPKG.


