Communication Network Joining With Challenge-Response MitM Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cellular networks are susceptible to Man-in-the-Middle (MitM) attacks that modify security capabilities and identifiers, leading to privacy risks and unauthorized access, especially in roaming scenarios and with new network components like network-controlled repeaters, without adequate protection in current solutions.
Innovation Solution
Incorporating security capabilities into the authentication and key agreement phase, using challenge-response mechanisms and key derivation to verify sensitive fields, and ensuring secure communication protocols, including protection of identifiers over wireless interfaces.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network access protocols are used without additional security verification, then network access is fast and simple, but the system becomes vulnerable to Man-in-the-Middle attacks and identifier modification
Solution Approach 1:
The patent applies preliminary action by performing authentication and verification of security capabilities during the initial network access phase, before any sensitive communication occurs. The UE verifies the network's security capabilities and authenticates network components (gNBs, repeaters) before establishing secure communication channels, preventing MitM attacks from the outset rather than adding complex ongoing verification mechanisms
Solution Approach 2:
The patent introduces an intermediary verification mechanism where the UE actively verifies security capabilities and authentication information exchanged between network components. This intermediary verification layer checks whether gNBs and repeaters are properly authenticated and whether security capabilities match expected values, adding security without requiring complete protocol redesign
2Reliability
If security capabilities are verified during authentication phase, then protection against MitM attacks is improved, but the authentication process time increases
Solution Approach 1:
The patent merges the security capabilities verification process with the existing authentication phase. Instead of adding a separate verification step, the UE performs security capability checks, network component authentication, and identifier verification all within the standard authentication procedure flow. This combines multiple security functions into one unified process, avoiding time penalties from sequential operations
Solution Approach 2:
The patent ensures continuity by making security verification an integrated part of the authentication flow rather than an interrupting step. The UE continuously verifies security capabilities and authentication information throughout the authentication process, maintaining the natural progression of the protocol while embedding security checks that prevent MitM attacks without causing delays
3Productivity
If identifiers are transmitted over wireless interface without protection, then communication efficiency is maintained, but user privacy is compromised
Solution Approach 1:
The patent applies parameter changes by dynamically adjusting the protection level of identifier transmission based on verification results. After verifying network security capabilities and authentication status, the UE determines whether to transmit identifiers in protected or unprotected form. This conditional approach allows efficient unprotected transmission when security is verified, while providing protection when verification fails or is not yet complete
Data Source
AI summary
The invention relates to an apparatus for verifying the information sent to a second device, the apparatus comprising a memory adapted to store information and a transceiver adapted to send and receive messages, wherein the apparatus is configured to send a first message with the information to the second device, wherein the apparatus is configured to receive a verification challenge from the second device, wherein the apparatus is adapted to compute and send to the second device a response based on the verification challenge, keying material shared between the first and second device, and the information exchanged in the first message.


