UE Security Capability Verification for Bidding Down Attack Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile communication systems do not effectively prevent bidding down attacks during UE motion, where an attacker modifies the UE's security capabilities, leading to vulnerable security negotiations between the UE and the network.
Innovation Solution
A method and system where the UE sends a TAU Request message to the MME, receives and checks the MME's security capabilities, determining if a bidding down attack has occurred by comparing them to stored capabilities, ensuring consistent security settings and preventing attacks through reinitiation of the negotiation process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the UE sends TAU Request to the new MME without verifying security capabilities, then the mobility management process is completed efficiently, but the system becomes vulnerable to bidding down attacks where security algorithms are downgraded
Solution Approach 1:
The patent applies preliminary action by having the UE obtain and store its security capabilities before the TAU process, and then verify these capabilities against the MME's selection. This pre-prepared verification mechanism allows the UE to detect and reject bidding down attacks before they compromise security, while not disrupting the overall efficiency of the mobility management process.
Solution Approach 2:
The patent implements feedback by creating a verification loop where the UE checks the MME's selected security algorithm against its stored capabilities and the original security capabilities sent in the TAU request. If a discrepancy is detected indicating a bidding down attack, the UE can trigger re-verification or reject the connection, providing a feedback mechanism that maintains security without permanently blocking efficient mobility management.
2Reliability
If the UE verifies security capabilities by comparing with stored capabilities, then bidding down attacks are prevented, but additional processing time and complexity are introduced
Solution Approach 1:
The patent applies copying by having the UE store a copy of its security capabilities locally before the TAU process. This stored copy serves as a reference for verification without requiring complex real-time queries or additional hardware components. The verification process simply compares the MME's selection against this pre-stored copy, maintaining low complexity while ensuring reliable security verification.
3Reliability
If the UE reinitiates security negotiation upon detecting bidding down attack, then security is restored, but the mobility process is delayed
Solution Approach 1:
The patent applies preliminary anti-action by preparing the UE with stored security capabilities and verification logic before the TAU process begins. When a bidding down attack is detected, the UE can immediately reinitiate security negotiation using these pre-prepared capabilities, rather than needing to perform complex capability discovery or query procedures. This reduces the time penalty for security restoration while ensuring reliable security maintenance.
Data Source
Figure 1~2
Figure 3~4
AI summary
A method for preventing bidding down attacks during motion of a UE is disclosed herein. The method includes: The UE sends a TAU Request message to a new MME; the UE receives UE's security capabilities sent by the MME; and the UE checks whether the received UE's security capabilities are consistent with the stored security capabilities. A system, an MME, and a UE for preventing bidding down attacks during motion of the UE are disclosed herein. When the UE performs security capability negotiation with the MME, the UE can check whether the received security capabilities are consistent with the stored security capabilities, and determine whether a bidding down attack exists, thus preventing bidding down attacks.