Security Mode Integrity Verification in Wireless Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless communication networks, false base stations can authenticate user equipment, leading to security mode integrity verification challenges, particularly in scenarios where victim and malicious UEs are located in different PLMNs.

Innovation Solution

A method and apparatus for security mode integrity verification, involving transmitting a request message to network devices, authenticating with them, receiving a security mode command message, verifying its integrity, and performing a cell reselection procedure if the security key is invalid.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a false base station authenticates user equipment, then the user equipment can access the network, but security integrity is compromised

Engineering Contradiction:
Improvenetwork accessVSAvoidsecurity integrity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by performing integrity verification of the security mode command message before completing the authentication process. The remote unit verifies the integrity of the security mode command received from the base station using a derived verification key. If the verification fails, the remote unit rejects the authentication attempt before establishing a secure connection, thus preventing compromised access while allowing legitimate access to proceed.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If integrity verification of security mode command is performed, then security reliability is improved, but authentication process complexity increases

Engineering Contradiction:
Improvesecurity integrityVSAvoidauthentication process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies self-service by enabling the remote unit to autonomously perform integrity verification using keys derived from authentication parameters already exchanged during the authentication process. The remote unit derives a verification key from the authentication root key and other parameters, then uses this key to verify the security mode command's integrity without requiring additional external verification infrastructure or complex multi-party protocols.

Inventive Principle:
Principle #25Self-service

3Reliability

If security key validation is implemented, then unauthorized access is prevented, but authentication time increases

Engineering Contradiction:
Improveaccess controlVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-derived verification keys during the authentication phase, which are then used for efficient integrity verification of the security mode command. The verification key is derived from the authentication root key and other parameters exchanged during authentication, enabling fast cryptographic verification without requiring additional key exchange rounds or time-consuming validation protocols.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3935810B1Security mode integrity verification
Publication Date: 2025.05.14 LENOVO (SINGAPORE) PTE LTD
  • EP3935810B1 patent drawingFigure 1
  • EP3935810B1 patent drawingFigure 2
  • EP3935810B1 patent drawingFigure 3

AI summary

Apparatuses, methods, and systems are disclosed for security mode integrity verification. One method (600) includes transmitting (602) a request message to one or more network devices. The method (600) includes, in response to transmitting the request message, authenticating (604) with the one or more network devices. The method (600) includes, in response to successfully authenticating with the one or more network devices, receiving (606) a security mode command message. The method (600) includes verifying (608) the integrity of the security mode command message. The method (600) includes, in response to the verification of the integrity of the security mode command message indicating that a security key is invalid, performing (610) a cell reselection procedure.