Wireless Communication Security via Location-Based Channel Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless communication systems face security vulnerabilities due to the independence of data security from communication channels, particularly in NFC, Bluetooth, or WiFi channels, where data transmission is susceptible to attacks from malicious third parties without valid verification of both communication endpoints.
Innovation Solution
A device and method in a wireless communication system that establishes a secure communication channel using a location-based service, such as Proximity-based Service (ProSe), to generate a data security key based on a channel key extracted from the secure communication channel, ensuring bi-directional authentication and protecting service data with a two-stage protection mechanism.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data security is made independent from communication channels using NFC, Bluetooth or WiFi, then security can be guaranteed by communication protocols and applications, but the physical channel becomes an attack point that attackers can exploit
Solution Approach 1:
The patent merges data security with the communication channel by establishing that security parameters are initialized and verified through the same physical channel (NFC, Bluetooth, or WiFi) that carries the data. This integration ensures that both data and channel are authenticated together, eliminating the vulnerability where independent security could be attacked through the physical channel.
Solution Approach 2:
The patent introduces a third-party server as an intermediary that verifies security parameters and authenticates both communication endpoints. This mediator prevents direct attacks on the physical channel by adding a verification layer that confirms the legitimacy of both devices before allowing data transmission.
2Device complexity
If only one apparatus is verified in current wireless communication systems, then verification complexity is reduced, but the unverified apparatus faces risk of being attacked by malicious third parties
Solution Approach 1:
The patent performs preliminary verification of both communication endpoints before data transmission begins. Security parameters are initialized and verified in advance through the third-party server, ensuring that both apparatuses are authenticated before any sensitive data exchange occurs, thereby preventing attacks from malicious third parties.
3Reliability
If additional third party secure channel is used for initializing security parameters, then security parameter initialization is more secure, but system complexity increases
Solution Approach 1:
The patent makes the third-party server serve multiple functions: it initializes security parameters, verifies security parameters, and authenticates both communication endpoints. This multi-functionality reduces the need for separate dedicated components for each security function, thereby managing system complexity while maintaining high security standards.
Data Source
AI summary
There is disclosed a device and method in a wireless communication system and a wireless communication system, the device including: a secure channel establishing unit configured to establish a secure communication channel between a first apparatus and a second apparatus using a location-based service; a data security key generating unit configured to generate a data security key for protecting service data based on at least a channel key extracted from the secure communication channel; and a controlling unit configured to control the service data protected using the data security key to be transmitted on the secure communication channel. According to the embodiments of the disclosure, it is possible to improve security of data transmission.


