Pre-AKA Secure Signaling for Wireless Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless communication systems face security vulnerabilities as messages transmitted before authentication and key agreement (AKA) are not secured, making them susceptible to interception and denial-of-service attacks.

Innovation Solution

Establishing a secure connection between user equipment (UE) and network devices using security credentials or public key-based cryptography to secure signaling messages prior to AKA, preventing unauthorized responses and ensuring message integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If messages are transmitted before AKA without security measures, then the signaling process can proceed quickly and simply, but the messages become vulnerable to interception and denial-of-service attacks

Engineering Contradiction:
Improvemessage securityVSAvoidsignaling complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by establishing security credentials and cryptographic context before the actual authentication and key agreement process. The network device and UE exchange and store security parameters (such as authentication token, cryptographic context) in advance, so that when pre-AKA signaling occurs, these pre-established credentials can be used to secure the messages without adding complex real-time security mechanisms.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If security credentials are established before AKA, then pre-AKA messages can be secured against attacks, but the authentication process becomes more complex

Engineering Contradiction:
Improveattack vulnerabilityVSAvoidauthentication complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent uses an intermediary approach by introducing a standardized cryptographic context structure that mediates between the security requirements and the authentication process. This cryptographic context acts as an intermediary layer that encapsulates security credentials (authentication token, security parameters) in a structured format, allowing secure pre-AKA signaling without requiring complex custom security implementations for each message exchange.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If secure signaling is implemented before AKA using cryptographic methods, then message integrity and authenticity are ensured, but the processing overhead increases

Engineering Contradiction:
Improvemessage integrityVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent reduces processing overhead during actual communication by performing cryptographic setup in advance. Security credentials and cryptographic contexts are established and cached before AKA, allowing pre-AKA signaling to use these pre-computed credentials rather than performing full cryptographic operations for each message. This preliminary cryptographic setup minimizes real-time processing requirements.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3453149B1Secure signaling before performing an authentication and key agreement
Publication Date: 2023.03.29 QUALCOMM INC
  • EP3453149B1 patent drawingFigure 1
  • EP3453149B1 patent drawingFigure 2
  • EP3453149B1 patent drawingFigure 3

AI summary

Techniques are described for wireless communication. A method of wireless communication at a wireless communication device includes generating a secured query message based at least in part on a security credential of the wireless communication device, where the secured query message is generated prior to performing an authentication and key agreement (AKA) with a network; transmitting the secured query message to the network; receiving a response to the secured query message; and determining whether to perform the AKA with the network based at least in part on the received response.