On-Demand System Information Authentication for 5G DoS Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In communication systems, particularly in 5G networks, the transmission of system information (SI) can be overwhelmed by malicious UEs requesting large volumes of on-demand SI, leading to potential denial-of-service (DoS) attacks due to the lack of authentication for UEs in idle mode, as the base station lacks the necessary security context to verify the genuineness of the requesting UE.

Innovation Solution

Implementing an authentication process using challenge vectors and response vectors, where the UE or a network node generates a challenge vector, and the UE responds with a corresponding vector, which is verified by a core network node to ensure only genuine UEs receive the requested on-demand SI, thereby mitigating DoS attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If on-demand system information is transmitted without authentication, then UEs can access system information quickly, but malicious UEs can launch denial-of-service attacks by sending voluminous requests

Engineering Contradiction:
ImproveSystem information access speedVSAvoidDenial-of-service attacks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an authentication intermediary mechanism where the base station acts as a mediator between UEs and system information transmission. The base station verifies UE legitimacy through authentication procedures (checking UE identity, authentication status, and subscription data) before allowing on-demand SI requests, thereby blocking malicious UEs while permitting legitimate ones to access information efficiently

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary authentication actions before system information transmission. The base station performs authentication checks (verifying UE identity against stored data, checking authentication status flags, and validating subscription permissions) in advance of SI transmission, ensuring that only authenticated UEs can proceed with on-demand requests, thus preventing DoS attacks before they occur

Inventive Principle:
Principle #10Preliminary action

2Reliability

If authentication is implemented for on-demand system information requests, then malicious requests are filtered, but the complexity of the system increases due to additional authentication procedures

Engineering Contradiction:
ImproveRequest filtering capabilityVSAvoidAuthentication procedure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service authentication where the base station uses its own stored UE data (identity, authentication status, subscription information) to perform verification autonomously without requiring external authentication servers. This self-contained approach filters malicious requests effectively while minimizing additional system complexity by leveraging existing base station capabilities

Inventive Principle:
Principle #25Self-service

3Speed

If the base station stores security context for all UEs, then authentication can be performed efficiently, but the memory requirements and processing overhead increase

Engineering Contradiction:
ImproveAuthentication verification speedVSAvoidStored security context data
Core Design Contradiction:
SpeedVSQuantity of substance

Solution Approach 1:

The patent applies local quality by storing complete security context data (identity, authentication status, subscription information) specifically for UEs that are currently connected or have recently accessed the cell. This localized storage approach enables fast authentication verification for active UEs while avoiding the memory overhead of storing data for all possible UEs in the network, thus balancing speed requirements with resource constraints

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3319372B1Authentication based delivery of on-demand system information
Publication Date: 2020.12.02 BLACKBERRY LTD
  • EP3319372B1 patent drawingFigure 1~2
  • EP3319372B1 patent drawingFigure 3~4
  • EP3319372B1 patent drawingFigure 5~6

AI summary

Systems and methods to request system information are provided. In some aspect, a user equipment (UE) transmits a request for on-demand system information. The UE transmits a challenge response for authentication of the request for the on-demand system information. The UE receives the on-demand system information after the request for the on-demand system information is authenticated based on the challenge response.