M2M Request Message Integrity Verification via Pre-Registered Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In machine-to-machine (M2M) communication systems, there is a risk of impersonation attacks where a malicious entity can manipulate request messages, leading to unauthorized access and control of resources, as existing security measures are inadequate in multi-hop environments.

Innovation Solution

A method and apparatus for processing request messages in a wireless communication system that involves determining whether the transmitting entity has the required resource, checking for an integrity code, verifying registration relationships, and ensuring the originator's ID matches the associated credential, thereby preventing impersonation attacks by ensuring accurate access control and message integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing security measures are used in M2M communication, then basic message transmission is enabled, but the system is vulnerable to impersonation attacks and message manipulation

Engineering Contradiction:
Improvemessage integrityVSAvoidimpersonation attack risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by pre-establishing registration relationships between entities and resources before actual message transmission. The receiving entity stores originator information (such as entity IDs, credentials, or cryptographic keys) in advance during a registration phase. This allows the system to quickly verify message authenticity during operation without adding complex real-time authentication protocols, thus maintaining message integrity while preventing impersonation attacks.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If strict access control verification is implemented, then security against malicious attacks is improved, but message processing complexity and time increase

Engineering Contradiction:
Improveaccess control securityVSAvoidmessage processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent reduces message processing time by performing access control verification based on pre-stored originator information. Instead of implementing complex real-time authentication protocols, the receiving entity simply checks whether the originator's information in the message matches the pre-registered information. This preliminary action during registration phase enables fast, efficient verification during message processing while maintaining strict security controls.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If originator verification is performed for every message, then impersonation attacks are prevented, but the complexity of message processing increases

Engineering Contradiction:
Improveimpersonation attack preventionVSAvoidmessage processing complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent simplifies message processing complexity by performing originator verification based on pre-stored information from the registration phase. The receiving entity maintains a database of registered originators and their credentials in advance. During message processing, the system only needs to compare the originator information in the message against this pre-established database, rather than implementing complex real-time authentication protocols. This approach effectively prevents impersonation attacks while keeping the processing logic simple and efficient.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9883320B2Method for processing request message in wireless communication system and apparatus therefor
Publication Date: 2018.01.30 LG ELECTRONICS INC
  • US9883320B2 patent drawing
  • US9883320B2 patent drawing
  • US9883320B2 patent drawing

AI summary

Suggested is a method for processing a request message in a wireless communication system according to one example of the present invention. The method comprises the steps of: receiving, by a first M2M entity, a request message relating to an operation for a specific resource from a second M2M entity; determining whether or not the first M2M entity has the specific resource; and if the first M2M entity does not have the specific resource, determining whether or not an integrity code is included in the request message, and if the integrity code is included in the request message, delivering the request message to a third M2M entity, or the method may comprise the steps of: if the first M2M entity has the specific resource, determining whether or not the first M2M entity has a registration relation with the second M2M entity; and if the first M2M entity has no registration relation with the second M2M entity, performing verification on the integrity code included in the request message.