RRC Frame Consistency Checks for Man-in-the-Middle Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods fail to detect man-in-the-middle attacks in wireless communication systems, particularly when the attacker imitates the master information block/system information block of a real base station, making it difficult to identify and prevent such attacks.
Innovation Solution
A method involving the exchange of radio resource control messages with frame information, such as frame and subframe numbers, between user equipment and a base station, using established access stratum security contexts to verify the matching of physical frames, thereby detecting potential man-in-the-middle attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If hash value comparison of MIB/SIB is used for man-in-the-middle detection, then detection capability is improved, but the method fails when attacker completely imitates the MIB/SIB of real base station
Solution Approach 1:
The patent segments the detection process into multiple independent verification stages: first verifying MIB/SIB hash values, then verifying RRC message integrity with security protection, and finally verifying frame number consistency. This multi-stage segmentation ensures that even if one verification method is bypassed (like MIB/SIB imitation), other verification layers remain effective.
Solution Approach 2:
The patent establishes security protection mechanisms and frame number verification procedures in advance before actual communication occurs. The AS security context is set up beforehand, and frame number tracking is initialized, enabling proactive detection rather than reactive response to man-in-the-middle attacks.
2Reliability
If frame information exchange with security protection is implemented, then man-in-the-middle detection rate is improved, but communication protocol complexity increases
Solution Approach 1:
The patent integrates frame number verification into the existing RRC message exchange framework, making the communication protocol serve multiple functions: normal data transmission, security protection verification, and man-in-the-middle detection. This multi-functionality reduces the need for separate dedicated verification protocols, thereby limiting the increase in overall system complexity.
Solution Approach 2:
The patent implements feedback mechanisms where the base station and UE continuously exchange frame number information and verification results through RRC messages. This feedback loop enables real-time detection of frame mismatches that would indicate man-in-the-middle attacks, maintaining high detection rates through systematic verification rather than complex ad-hoc checks.
3Measurement precision
If continuous frame number verification is performed, then detection accuracy is improved, but processing overhead increases
Solution Approach 1:
The patent employs periodic verification of frame numbers at specific intervals during RRC message exchanges rather than continuous verification of every single bit. This periodic approach maintains detection accuracy by checking at critical verification points while significantly reducing the processing overhead compared to exhaustive continuous verification.
Solution Approach 2:
The patent performs verification on critical frame number fields and security protection parameters rather than analyzing every aspect of the communication stream. This partial verification approach focuses computational resources on the most indicative elements for detecting man-in-the-middle attacks, achieving sufficient detection accuracy without the excessive processing burden of complete analysis.
Data Source
AI summary
A man-in-the-middle detection method and apparatus. The method includes: A base station receives, in a first physical frame, a RRC message from user equipment UE; the base station receives from the UE a second RRC message including frame information of a second physical frame, and security protection is performed on the first RRC message and the second RRC message by using an access stratum AS security context established by the UE and the base station; and the base station determines whether the first physical frame matches the second physical frame. Thereby, whether a man-in-the-middle exists in air interface communication is determined by determining whether a physical frame in which the UE sends an uplink message matches a physical frame in which the base station receives the uplink message, to prevent the man-in-the-middle from bypassing detection through a mechanism of the man-in-the-middle and improve a man-in-the-middle detection rate.


