5G RRC Message MAC-I Verification Before AS Security Activation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 5G wireless communication systems are vulnerable to security attacks from false base stations (FBS), particularly due to the lack of integrity protection for certain RRC messages before AS security activation, which can lead to Denial-of-Service attacks and unauthorized service delivery.
Innovation Solution
Introduce a new Message Authentication Code for Integrity (MAC-I) to perform integrity checks on RRC messages in the access stratum layer, using symmetric or asymmetric keys to verify the authenticity of RRC messages, ensuring secure RRC connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If integrity protection is not applied to RRC messages before AS security activation, then the system maintains simplicity and fast connection establishment, but the system becomes vulnerable to false base station attacks and unauthorized service delivery
Solution Approach 1:
The patent applies preliminary action by introducing MAC-I verification before AS security activation. The UE performs integrity checks on RRC messages using MAC-I codes received in system information or previous RRC messages, even before the full AS security mechanism is activated. This preliminary security measure prevents false base station attacks during the vulnerable initial connection phase without requiring the complete AS security infrastructure to be in place first.
2Reliability
If MAC-I verification is performed on all RRC messages, then security is enhanced, but the processing time and complexity increase
Solution Approach 1:
The patent applies local quality by selectively applying MAC-I verification to specific RRC messages rather than all messages. The verification is performed on critical messages such as RRCSetup, RRCResume, and other messages received before AS security activation. This targeted approach ensures that the most vulnerable and important messages are protected while avoiding the overhead of verifying every single RRC message, thus balancing security enhancement with processing efficiency.
Data Source
AI summary
The present disclosure provides a method performed by means of a terminal in a wireless communication system. The method may comprise the steps of: acquiring information including a Message Authentication Code for Integrity (MAC-I) in an RRC idle state; verifying the MAC-I; and performing a procedure for an RRC connection with a base station if the MAC-I is valid on the basis of the verification.


