Secure Cell Redirection via MME Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current LTE networks lack a mechanism to verify the authenticity of eNodeBs and user equipment during cell redirection, making them vulnerable to attacks, such as redirection to fake GSM networks.

Innovation Solution

Implementing an authentication procedure and generating a cell redirection command with integrity protection to ensure the authenticity of the eNodeB and user equipment, using an integrity key for secure communication and verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cell redirection is implemented without authentication, then the redirection process is simple and fast, but the system becomes vulnerable to attacks by fake eNodeBs

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by performing authentication between the UE and eNodeB before the cell redirection command is issued. The authentication procedure establishes security credentials and integrity protection mechanisms in advance, so that when redirection occurs, the UE can verify the legitimacy of the eNodeB. This prevents fake eNodeB attacks while maintaining a relatively simple redirection process.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If integrity protection is added to cell redirection commands, then authentication security is improved, but the signaling overhead and processing complexity increase

Engineering Contradiction:
Improveintegrity verificationVSAvoidsignaling overhead
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent changes the parameter of security protection from none to integrity protection with authentication. By introducing integrity protection parameters (such as authentication tokens or cryptographic verification data) in the cell redirection command, the system ensures that the UE can verify the command's legitimacy. This prevents man-in-the-middle attacks and fake eNodeB redirection, accepting the necessary increase in signaling overhead as a trade-off for security.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10542463B2System and method for secure cell redirection in wireless networks
Publication Date: 2020.01.21 NOKIA OF AMERICA CORP
  • US10542463B2 patent drawing
  • US10542463B2 patent drawing
  • US10542463B2 patent drawing

AI summary

A mobility management entity (MME) is configured to perform cell redirection or Circuit-Switched fallback with security protocols. The MME receives an initial connection message from user equipment (UE) in an idle mode with a service request for a voice call. The MME and UE first perform an authentication procedure with the UE prior to processing of the service request by the MME. The MME generate a cell redirection command with integrity protection using an integrity key established during the authentication procedure. The MME transmits the cell redirection command with integrity protection in the payload of a signaling message to the UE. The MME may also transmit the UE its policy of security protected cell redirection in an initial attach message to the network or with a tracking area update message.