Securing 5G RRC Resume Cause Messages via Authentication Code Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In 5G wireless networks, there is a lack of mechanisms to ensure the authenticity of RRC resume cause messages, making them vulnerable to manipulation by attackers, which can lead to denial-of-service attacks and network performance degradation.
Innovation Solution
A method is introduced to secure unicast message communication by having the UE send a request for resuming RRC connection, with the base station computing a message authentication code and mapping it with a UE-generated code, ensuring the authenticity of RRC reject messages and resume causes, and acknowledging successful mappings to prevent unauthorized changes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If message authentication codes are implemented to secure RRC resume cause messages, then network security and message integrity are improved, but device complexity and signaling overhead increase
Solution Approach 1:
The network pre-generates and stores multiple authentication codes (first authentication code, second authentication code, third authentication code) before the RRC resume procedure. When the UE sends a resume request, the network selects the appropriate pre-generated authentication code from its stored set, avoiding real-time computation and reducing signaling overhead.
Solution Approach 2:
The UE stores multiple copies of authentication codes locally (first authentication code, second authentication code, third authentication code) corresponding to different resume causes. The UE selects and sends the appropriate authentication code copy based on the resume cause, enabling verification without increasing computational complexity at the network side.
2Reliability
If multiple authentication codes are stored and managed, then message authenticity verification is improved, but memory requirements and processing overhead increase
Solution Approach 1:
Different authentication codes are stored and used for different resume causes (first authentication code for first resume cause, second authentication code for second resume cause, third authentication code for third resume cause). This localized approach ensures that each authentication code is used in its appropriate context, improving verification accuracy while managing memory efficiently through purpose-specific storage.
Data Source
AI summary
The present disclosure relates to a pre-5th-Generation (5G) or 5G communication system to be provided for supporting higher data rates Beyond 4th-Generation (4G) communication system such as Long Term Evolution (LTE). A method for securing unicast message communication is provided. The method includes sending, by a user equipment (UE), a request-message for resuming radio resource control (RRC) connection to a base station, wherein the request message comprises a first-parameter defining “resume cause”. A response pertaining to at least one of network-release or network-resumption is received by the UE, wherein the response comprises a second parameter defining “resume cause”. Based on a successful-mapping between the first parameter and the second parameter, the response is acknowledged by the UE. However, for example, in case of network-rejection of the request due to network congestion, an RRC reject message comprising a first message authentication code is computed by the base station based on a stored network security context and communicated to the UE. Thereafter, a second message authentication code is mapped by the UE with the first message authentication code.


