Network Device Context Integrity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Communication networks, such as cellular networks, are vulnerable to denial-of-service (DoS) attacks where malicious actors send spurious messages to delete user equipment contexts, compromising network integrity and authenticity.

Innovation Solution

An apparatus and method that establish and manage user equipment contexts, determining failed network message integrity by triggering paging or authentication processes to differentiate between legitimate and malicious messages, thereby maintaining network security and integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If full authentication process is performed for every suspicious message, then network security is improved, but network efficiency and signaling overhead deteriorate

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies partial authentication by performing integrity checks on a subset of messages rather than all messages. When integrity failures occur, full authentication is triggered only for specific suspicious messages or contexts, not universally. This selective approach maintains security for critical cases while avoiding the overhead of authenticating every message, thus resolving the contradiction between security and efficiency.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system employs self-service mechanisms where the network automatically detects integrity failures and triggers appropriate responses without requiring manual intervention or full authentication for every case. The apparatus autonomously manages security by monitoring message integrity and selectively initiating authentication only when necessary, reducing overall signaling overhead while maintaining security posture.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If integrity checking is performed on all network messages, then detection of malicious messages is improved, but processing time and computational resources worsen

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements partial integrity checking by selectively applying integrity verification to specific message types or contexts rather than universally checking all messages. Full integrity validation is performed only when suspicious patterns are detected or for critical messages, while routine messages receive reduced or no integrity checking. This approach maintains high detection accuracy for malicious messages while significantly reducing overall processing time and computational resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If user equipment context is deleted upon integrity failure, then network security is improved, but legitimate user service continuity deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidservice continuity
Core Design Contradiction:
ReliabilityVSDuration of action of stationary object

Solution Approach 1:

The patent applies preliminary action by establishing integrity verification mechanisms before critical service operations. When integrity failures are detected, the system has pre-configured response protocols that allow for graceful degradation or alternative service paths rather than immediate context deletion. This enables the network to maintain service continuity for legitimate users while still responding to security threats, as the preliminary integrity checks allow for differentiated responses based on the nature and severity of the failure.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system employs feedback mechanisms where integrity check results are continuously monitored and used to adjust security responses. When integrity failures occur, the feedback loop allows the network to distinguish between legitimate messages experiencing transient errors and genuinely malicious messages. This feedback-driven approach enables selective context management where legitimate user contexts are preserved despite isolated integrity failures, while malicious contexts are appropriately deleted, thus maintaining both security and service continuity.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11991190B2Counteractions against suspected identity imposture
Publication Date: 2024.05.21 NOKIA TECHNOLOGIES OY
  • US11991190B2 patent drawing
  • US11991190B2 patent drawing
  • US11991190B2 patent drawing

AI summary

According to an example aspect of the present invention, there is provided an apparatus comprising at least one processing core, at least one memory including computer program code, the at least one memory and the computer program code being configured to, with the at least one processing core, cause the apparatus at least to establish a user equipment context for a user equipment registered with the apparatus, the user equipment context being associated with an identity of the user equipment, determine that a plurality of network messages comprising the identity of the user equipment as sender fail a network message integrity process, and trigger, responsive to the determination, at least one of: 1) sending a paging message to the user equipment, and 2) initiating an authentication process with a sender of the network messages, and deletion the user equipment context as a response to successful completion of the authentication process.