M2M Request Message Integrity Verification via Pre-Registered Credentials
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In machine-to-machine (M2M) communication systems, there is a risk of impersonation attacks where a malicious entity can manipulate request messages, leading to unauthorized access and control of resources, as existing security measures are inadequate in multi-hop environments.
Innovation Solution
A method and apparatus for processing request messages in a wireless communication system that involves determining whether the transmitting entity has the required resource, checking for an integrity code, verifying registration relationships, and ensuring the originator's ID matches the associated credential, thereby preventing impersonation attacks by ensuring accurate access control and message integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing security measures are used in M2M communication, then basic message transmission is enabled, but the system is vulnerable to impersonation attacks and message manipulation
Solution Approach 1:
The patent applies preliminary action by pre-establishing registration relationships between entities and resources before actual message transmission. The receiving entity stores originator information (such as entity IDs, credentials, or cryptographic keys) in advance during a registration phase. This allows the system to quickly verify message authenticity during operation without adding complex real-time authentication protocols, thus maintaining message integrity while preventing impersonation attacks.
2Reliability
If strict access control verification is implemented, then security against malicious attacks is improved, but message processing complexity and time increase
Solution Approach 1:
The patent reduces message processing time by performing access control verification based on pre-stored originator information. Instead of implementing complex real-time authentication protocols, the receiving entity simply checks whether the originator's information in the message matches the pre-registered information. This preliminary action during registration phase enables fast, efficient verification during message processing while maintaining strict security controls.
3Object-affected harmful factors
If originator verification is performed for every message, then impersonation attacks are prevented, but the complexity of message processing increases
Solution Approach 1:
The patent simplifies message processing complexity by performing originator verification based on pre-stored information from the registration phase. The receiving entity maintains a database of registered originators and their credentials in advance. During message processing, the system only needs to compare the originator information in the message against this pre-established database, rather than implementing complex real-time authentication protocols. This approach effectively prevents impersonation attacks while keeping the processing logic simple and efficient.
Data Source
AI summary
Suggested is a method for processing a request message in a wireless communication system according to one example of the present invention. The method comprises the steps of: receiving, by a first M2M entity, a request message relating to an operation for a specific resource from a second M2M entity; determining whether or not the first M2M entity has the specific resource; and if the first M2M entity does not have the specific resource, determining whether or not an integrity code is included in the request message, and if the integrity code is included in the request message, delivering the request message to a third M2M entity, or the method may comprise the steps of: if the first M2M entity has the specific resource, determining whether or not the first M2M entity has a registration relation with the second M2M entity; and if the first M2M entity has no registration relation with the second M2M entity, performing verification on the integrity code included in the request message.


