Secure Cell Redirection via MME Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current LTE networks lack a mechanism to verify the authenticity of eNodeBs and user equipment during cell redirection, making them vulnerable to attacks, such as redirection to fake GSM networks.
Innovation Solution
Implementing an authentication procedure and generating a cell redirection command with integrity protection to ensure the authenticity of the eNodeB and user equipment, using an integrity key for secure communication and verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cell redirection is implemented without authentication, then the redirection process is simple and fast, but the system becomes vulnerable to attacks by fake eNodeBs
Solution Approach 1:
The patent applies preliminary action by performing authentication between the UE and eNodeB before the cell redirection command is issued. The authentication procedure establishes security credentials and integrity protection mechanisms in advance, so that when redirection occurs, the UE can verify the legitimacy of the eNodeB. This prevents fake eNodeB attacks while maintaining a relatively simple redirection process.
2Reliability
If integrity protection is added to cell redirection commands, then authentication security is improved, but the signaling overhead and processing complexity increase
Solution Approach 1:
The patent changes the parameter of security protection from none to integrity protection with authentication. By introducing integrity protection parameters (such as authentication tokens or cryptographic verification data) in the cell redirection command, the system ensures that the UE can verify the command's legitimacy. This prevents man-in-the-middle attacks and fake eNodeB redirection, accepting the necessary increase in signaling overhead as a trade-off for security.
Data Source
AI summary
A mobility management entity (MME) is configured to perform cell redirection or Circuit-Switched fallback with security protocols. The MME receives an initial connection message from user equipment (UE) in an idle mode with a service request for a voice call. The MME and UE first perform an authentication procedure with the UE prior to processing of the service request by the MME. The MME generate a cell redirection command with integrity protection using an integrity key established during the authentication procedure. The MME transmits the cell redirection command with integrity protection in the payload of a signaling message to the UE. The MME may also transmit the UE its policy of security protected cell redirection in an initial attach message to the network or with a tracking area update message.


