Security Mode Integrity Verification in Wireless Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In wireless communication networks, false base stations can authenticate user equipment, leading to security mode integrity verification challenges, particularly in scenarios where victim and malicious UEs are located in different PLMNs.
Innovation Solution
A method and apparatus for security mode integrity verification, involving transmitting a request message to network devices, authenticating with them, receiving a security mode command message, verifying its integrity, and performing a cell reselection procedure if the security key is invalid.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a false base station authenticates user equipment, then the user equipment can access the network, but security integrity is compromised
Solution Approach 1:
The patent applies preliminary action by performing integrity verification of the security mode command message before completing the authentication process. The remote unit verifies the integrity of the security mode command received from the base station using a derived verification key. If the verification fails, the remote unit rejects the authentication attempt before establishing a secure connection, thus preventing compromised access while allowing legitimate access to proceed.
2Reliability
If integrity verification of security mode command is performed, then security reliability is improved, but authentication process complexity increases
Solution Approach 1:
The patent applies self-service by enabling the remote unit to autonomously perform integrity verification using keys derived from authentication parameters already exchanged during the authentication process. The remote unit derives a verification key from the authentication root key and other parameters, then uses this key to verify the security mode command's integrity without requiring additional external verification infrastructure or complex multi-party protocols.
3Reliability
If security key validation is implemented, then unauthorized access is prevented, but authentication time increases
Solution Approach 1:
The patent applies preliminary action by pre-derived verification keys during the authentication phase, which are then used for efficient integrity verification of the security mode command. The verification key is derived from the authentication root key and other parameters exchanged during authentication, enabling fast cryptographic verification without requiring additional key exchange rounds or time-consuming validation protocols.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Apparatuses, methods, and systems are disclosed for security mode integrity verification. One method (600) includes transmitting (602) a request message to one or more network devices. The method (600) includes, in response to transmitting the request message, authenticating (604) with the one or more network devices. The method (600) includes, in response to successfully authenticating with the one or more network devices, receiving (606) a security mode command message. The method (600) includes verifying (608) the integrity of the security mode command message. The method (600) includes, in response to the verification of the integrity of the security mode command message indicating that a security key is invalid, performing (610) a cell reselection procedure.