Integrity-Protected Control Signaling for 5G Wait Time Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

5th Generation (5G) cellular networks face challenges in resisting sophisticated Denial of Service (DoS) attacks, particularly those exploiting vulnerabilities in control signaling protocols, where attackers can intercept and inject crafted messages to cause persistent disruptions, making it harder to detect and mitigate these attacks compared to traditional jamming methods.

Innovation Solution

Implementing integrity protection for control signaling that indicates wait times exceeding a defined threshold, ensuring that only integrity-protected messages can specify longer wait times, thereby preventing attackers from misusing these times for DoS attacks, while allowing non-integrity protected messages to indicate shorter wait times for legitimate control message timing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If control signaling allows flexible wait time indication for legitimate timing control, then network control capability is improved, but vulnerability to DoS attacks increases

Engineering Contradiction:
Improvenetwork control capabilityVSAvoidvulnerability to DoS attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by differentiating integrity protection requirements based on the specific wait time value. Control signaling with wait times above the threshold requires integrity protection, while those below the threshold do not. This localized application of security measures maintains network control capability for legitimate timing while preventing DoS attacks that exploit unprotected signaling.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the parameter of integrity protection status based on the wait time parameter. By establishing a threshold and requiring integrity protection only for wait times exceeding this threshold, the system dynamically adjusts security parameters to balance control flexibility with attack resistance.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If integrity protection is applied to all control signaling, then security against DoS attacks is improved, but signaling overhead and processing complexity increase

Engineering Contradiction:
Improvesecurity against DoS attacksVSAvoidsignaling processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the control signaling space into two categories: those requiring integrity protection (wait times above threshold) and those that do not (wait times at or below threshold). This segmentation allows the system to apply security measures only where necessary, reducing overall processing complexity while maintaining security for critical signaling.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial action by implementing integrity protection only for a subset of control signaling messages - specifically those indicating wait times above the threshold. This partial application of security measures provides sufficient protection against DoS attacks without the excessive overhead of protecting all control signaling.

Inventive Principle:
Principle #16Partial or excessive action

3Object-affected harmful factors

If wait time range for non-integrity protected messages is limited, then DoS attack mitigation is improved, but flexibility in timing control is reduced

Engineering Contradiction:
ImproveDoS attack mitigationVSAvoidtiming control flexibility
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent implements preliminary anti-action by preemptively requiring integrity protection for control signaling that could enable DoS attacks (those with wait times above the threshold). This preliminary security measure prevents attackers from exploiting timing control flexibility for malicious purposes while preserving legitimate timing control capabilities.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS11218880B2Control signaling in a wireless communication system
Publication Date: 2022.01.04 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US11218880B2 patent drawing
  • US11218880B2 patent drawing
  • US11218880B2 patent drawing

AI summary

A wireless communication device (16) is configured for use in a wireless communication system (10). The wireless communication device (16) is configured to receive control signaling (22) that indicates a certain wait time (24) for which the wireless communication device (16) is required to wait before sending a certain control message (20) to network equipment (18). A subset of possible wait times must be indicated by integrity-protected control signaling. The wireless communication device (16) may therefore also be configured to accept or reject the certain wait time (24) as being required before sending the certain control message (20), based on whether the received control signaling (22) was integrity protected and on whether the certain wait time (24) is included in the subset of possible wait times which must be indicated by integrity-protected control signaling.