Network Device Context Integrity Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Communication networks, such as cellular networks, are vulnerable to denial-of-service (DoS) attacks where malicious actors send spurious messages to delete user equipment contexts, compromising network integrity and authenticity.
Innovation Solution
An apparatus and method that establish and manage user equipment contexts, determining failed network message integrity by triggering paging or authentication processes to differentiate between legitimate and malicious messages, thereby maintaining network security and integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If full authentication process is performed for every suspicious message, then network security is improved, but network efficiency and signaling overhead deteriorate
Solution Approach 1:
The patent applies partial authentication by performing integrity checks on a subset of messages rather than all messages. When integrity failures occur, full authentication is triggered only for specific suspicious messages or contexts, not universally. This selective approach maintains security for critical cases while avoiding the overhead of authenticating every message, thus resolving the contradiction between security and efficiency.
Solution Approach 2:
The system employs self-service mechanisms where the network automatically detects integrity failures and triggers appropriate responses without requiring manual intervention or full authentication for every case. The apparatus autonomously manages security by monitoring message integrity and selectively initiating authentication only when necessary, reducing overall signaling overhead while maintaining security posture.
2Measurement precision
If integrity checking is performed on all network messages, then detection of malicious messages is improved, but processing time and computational resources worsen
Solution Approach 1:
The patent implements partial integrity checking by selectively applying integrity verification to specific message types or contexts rather than universally checking all messages. Full integrity validation is performed only when suspicious patterns are detected or for critical messages, while routine messages receive reduced or no integrity checking. This approach maintains high detection accuracy for malicious messages while significantly reducing overall processing time and computational resource consumption.
3Reliability
If user equipment context is deleted upon integrity failure, then network security is improved, but legitimate user service continuity deteriorates
Solution Approach 1:
The patent applies preliminary action by establishing integrity verification mechanisms before critical service operations. When integrity failures are detected, the system has pre-configured response protocols that allow for graceful degradation or alternative service paths rather than immediate context deletion. This enables the network to maintain service continuity for legitimate users while still responding to security threats, as the preliminary integrity checks allow for differentiated responses based on the nature and severity of the failure.
Solution Approach 2:
The system employs feedback mechanisms where integrity check results are continuously monitored and used to adjust security responses. When integrity failures occur, the feedback loop allows the network to distinguish between legitimate messages experiencing transient errors and genuinely malicious messages. This feedback-driven approach enables selective context management where legitimate user contexts are preserved despite isolated integrity failures, while malicious contexts are appropriately deleted, thus maintaining both security and service continuity.
Data Source
AI summary
According to an example aspect of the present invention, there is provided an apparatus comprising at least one processing core, at least one memory including computer program code, the at least one memory and the computer program code being configured to, with the at least one processing core, cause the apparatus at least to establish a user equipment context for a user equipment registered with the apparatus, the user equipment context being associated with an identity of the user equipment, determine that a plurality of network messages comprising the identity of the user equipment as sender fail a network message integrity process, and trigger, responsive to the determination, at least one of: 1) sending a paging message to the user equipment, and 2) initiating an authentication process with a sender of the network messages, and deletion the user equipment context as a response to successful completion of the authentication process.


