On-Demand System Information Authentication for 5G DoS Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In communication systems, particularly in 5G networks, the transmission of system information (SI) can be overwhelmed by malicious UEs requesting large volumes of on-demand SI, leading to potential denial-of-service (DoS) attacks due to the lack of authentication for UEs in idle mode, as the base station lacks the necessary security context to verify the genuineness of the requesting UE.
Innovation Solution
Implementing an authentication process using challenge vectors and response vectors, where the UE or a network node generates a challenge vector, and the UE responds with a corresponding vector, which is verified by a core network node to ensure only genuine UEs receive the requested on-demand SI, thereby mitigating DoS attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If on-demand system information is transmitted without authentication, then UEs can access system information quickly, but malicious UEs can launch denial-of-service attacks by sending voluminous requests
Solution Approach 1:
The patent introduces an authentication intermediary mechanism where the base station acts as a mediator between UEs and system information transmission. The base station verifies UE legitimacy through authentication procedures (checking UE identity, authentication status, and subscription data) before allowing on-demand SI requests, thereby blocking malicious UEs while permitting legitimate ones to access information efficiently
Solution Approach 2:
The patent implements preliminary authentication actions before system information transmission. The base station performs authentication checks (verifying UE identity against stored data, checking authentication status flags, and validating subscription permissions) in advance of SI transmission, ensuring that only authenticated UEs can proceed with on-demand requests, thus preventing DoS attacks before they occur
2Reliability
If authentication is implemented for on-demand system information requests, then malicious requests are filtered, but the complexity of the system increases due to additional authentication procedures
Solution Approach 1:
The patent implements self-service authentication where the base station uses its own stored UE data (identity, authentication status, subscription information) to perform verification autonomously without requiring external authentication servers. This self-contained approach filters malicious requests effectively while minimizing additional system complexity by leveraging existing base station capabilities
3Speed
If the base station stores security context for all UEs, then authentication can be performed efficiently, but the memory requirements and processing overhead increase
Solution Approach 1:
The patent applies local quality by storing complete security context data (identity, authentication status, subscription information) specifically for UEs that are currently connected or have recently accessed the cell. This localized storage approach enables fast authentication verification for active UEs while avoiding the memory overhead of storing data for all possible UEs in the network, thus balancing speed requirements with resource constraints
Data Source
Figure 1~2
Figure 3~4
Figure 5~6
AI summary
Systems and methods to request system information are provided. In some aspect, a user equipment (UE) transmits a request for on-demand system information. The UE transmits a challenge response for authentication of the request for the on-demand system information. The UE receives the on-demand system information after the request for the on-demand system information is authenticated based on the challenge response.