V2X Sidelink Authentication via Network Identity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In vehicle-to-everything (V2X) wireless communication networks, the challenge lies in ensuring network security and reducing latency during authentication procedures, as conventional methods can introduce delays and may fail to prevent malicious devices from transmitting false information, leading to potential network congestion and reliability issues.

Innovation Solution

The proposed solution involves verifying the identity of a base station using messages such as authentication and key agreement (AKA), tracking area update (TAU), radio resource control (RRC), or non-access stratum (NAS) messages with valid integrity check values before utilizing communication resources, ensuring that only authenticated devices can transmit data via the sidelink communication resource pool.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional authentication procedures are used in V2X networks, then network security is maintained, but communication latency increases and network reliability decreases

Engineering Contradiction:
Improvenetwork reliabilityVSAvoidauthentication latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs authentication and identity verification procedures before allocating communication resources. The network device verifies the identity of the UE based on messages received during connection setup, and only after successful verification does it grant access to the sidelink communication resource pool. This preliminary action ensures security is established beforehand, preventing malicious devices from transmitting false information while enabling legitimate communications with reduced latency.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If identity verification is performed before resource allocation, then network security is enhanced, but communication setup time increases

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication procedure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network device acts as an intermediary that performs identity verification using messages already exchanged during the connection setup process (such as AKA, TAU, RRC, or NAS messages). By leveraging these existing communication protocols and messages, the system verifies UE identity without requiring separate dedicated authentication procedures, thus enhancing security while avoiding significant increases in procedural complexity or setup time.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If malicious devices are allowed to transmit, then network coverage is maintained, but false information spreads causing congestion

Engineering Contradiction:
Improvenetwork coverageVSAvoidfalse information transmission
Core Design Contradiction:
Adaptability or versatilityVSObject-generated harmful factors

Solution Approach 1:

The system applies preliminary anti-action by verifying the identity of each UE before allowing it to transmit on the sidelink. The network device checks whether the UE is legitimate based on authentication messages received during connection establishment. Only UEs with verified identities are granted access to the communication resource pool, thereby preventing malicious devices from transmitting false alarm messages while maintaining network coverage for legitimate users.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS11812411B2Systems and methods of vehicle-to-everything (V2X) security
Publication Date: 2023.11.07 QUALCOMM INC
  • US11812411B2 patent drawing
  • US11812411B2 patent drawing
  • US11812411B2 patent drawing

AI summary

A method of wireless communication includes receiving, by a user equipment (UE), a system information block of type 21 (SIB21) from a network device. The SIB21 indicates a communication resource pool associated with a sidelink. The method further includes receiving one or more messages from the network device based on receiving the SIB21 and prior to communicating using the communication resource pool. The method further includes communicating, based on verifying an identity of the network device based on the one or more messages, via the sidelink using the communication resource pool and based on a vehicle-to-everything (V2X) wireless communication protocol.