ProSe Authorization Mechanism for Direct Discovery Spoofing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authorization procedures for proximity services in mobile communication systems are insufficient to detect malicious applications attempting to use direct discovery, allowing potential spoofing of Application IDs and unauthorized access.

Innovation Solution

An enhanced authorization mechanism that includes a validation controller and rules engine to verify the authenticity of applications by sending a security challenge message and comparing the response to authorized security parameters, ensuring only authorized applications can perform direct discovery.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authorization procedures are used for ProSe discovery, then the system is simple and easy to operate, but malicious applications can spoof Application IDs and unauthorized access occurs

Engineering Contradiction:
ImprovesecurityVSAvoidauthorization mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by requiring the UE to obtain security parameters and generate authentication credentials before performing direct discovery. The validation controller sends a challenge message beforehand, and the UE prepares the security answer using stored security parameters. This advance preparation ensures that when discovery requests are made, the authentication is already in place, preventing malicious spoofing while maintaining a manageable authorization process.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If enhanced security verification is implemented, then malicious applications are detected and security is improved, but the authorization procedure becomes more complex and time-consuming

Engineering Contradiction:
Improvedetection of malicious applicationsVSAvoidauthorization procedure time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-storing security parameters in the UE and pre-generating authentication credentials before discovery operations. When a discovery request occurs, the UE can quickly retrieve and use these pre-prepared credentials to respond to validation challenges, significantly reducing the time required for security verification while maintaining strong detection capabilities against malicious applications.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If security challenge messages are sent to verify Application ID authenticity, then spoofing is prevented, but additional communication overhead and processing time are required

Engineering Contradiction:
ImproveApplication ID authenticityVSAvoidvalidation procedure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary approach by using a validation controller as a mediator between the UE and the discovery authorization process. The validation controller sends challenge messages to UEs and collects security answers, acting as an intermediary that verifies Application ID authenticity without requiring complex peer-to-peer verification between UEs. This intermediary role simplifies the overall validation procedure while maintaining strong security through centralized challenge-response verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3711323B1Authorization of applications for direct discovery
Publication Date: 2023.08.09 NOKIA TECHNOLOGIES OY
  • EP3711323B1 patent drawingFigure 1
  • EP3711323B1 patent drawingFigure 2~3
  • EP3711323B1 patent drawingFigure 4~5

AI summary

Systems, methods, and software for authorizing an application in User Equipment (UE) for direct discovery. In one embodiment, an authorization mechanism receives information (e.g., application ID) for a discovery request sent by an application in a UE. In response to the discovery request, the authorization mechanism challenges the UE for information regarding security parameters that are mapped to the application ID. Based on the information provided by the UE, the authorization mechanism determines whether the application is authorized for direct discovery.