Wireless Security Validation via Preliminary Capability Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication systems, particularly in the Evolved Packet System (EPS) under 3GPP, lack effective mechanisms for validating User Equipment (UE) security capability, making them vulnerable to Man-In-The-Middle (MITM) attacks, and do not specify procedures for securing Non Access Stratum (NAS) protocol messages.

Innovation Solution

A security processing method and system that involves transmitting UE security capability messages between User Equipment (UE), Mobility Management Entity (MME), and evolved Node B (eNB), using Layer 3 messages, Access Stratum Security Mode Commands (AS SMC), and Message Authentication Codes (MAC) to verify and authenticate security algorithms, ensuring integrity and protecting against MITM attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If UE security capability information is derived from NAS protocol without validation mechanism, then security management is simplified, but the system becomes vulnerable to MITM attacks

Engineering Contradiction:
Improvesecurity management complexityVSAvoidsecurity capability validation
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent applies preliminary action by having the UE send its security capability information to the eNB before the actual security mode command exchange. The eNB then validates this capability against the SMC message contents in advance, detecting potential MITM attacks before they can compromise the security setup. This preliminary validation prevents vulnerable operation states.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback by having the eNB compare the UE-provided security capability information with the security capability information contained in the SMC message from the MME. This feedback mechanism allows the eNB to detect inconsistencies that indicate MITM attacks, and to take corrective action by not proceeding with security mode setup when validation fails.

Inventive Principle:
Principle #23Feedback

2Reliability

If detailed procedures for validating NAS information are specified, then security is reinforced, but the protocol complexity increases

Engineering Contradiction:
Improvesecurity validationVSAvoidprotocol procedures
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses the eNB as an intermediary that performs the validation function. Instead of requiring complex validation procedures in the NAS layer between UE and MME, the eNB acts as a mediator that receives security capability information from the UE, compares it with the SMC message, and makes the validation decision. This simplifies the overall protocol by offloading validation to an intermediate entity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the security validation function into separate steps: (1) UE sends security capability information to eNB in L3 message, (2) eNB validates against SMC message, (3) eNB proceeds or rejects based on validation result. This segmentation makes the validation process more manageable and easier to implement than a monolithic complex validation procedure.

Inventive Principle:
Principle #1Segmentation

3Productivity

If AS security algorithm is selected without verifying UE security capability, then the security mode command processing is faster, but the system is exposed to MITM attacks

Engineering Contradiction:
Improvesecurity mode command processing speedVSAvoidsecurity capability authentication
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by having the UE send its security capability information to the eNB before the AS SMC is sent. The eNB performs validation of this capability against the SMC message contents in advance, detecting potential MITM attacks before they can compromise the security setup. This preliminary validation prevents vulnerable operation states while maintaining efficient processing.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8555064B2Security system and method for wireless communication system
Publication Date: 2013.10.08 SAMSUNG ELECTRONICS CO LTD
  • US8555064B2 patent drawing
  • US8555064B2 patent drawing
  • US8555064B2 patent drawing

AI summary

A security system processing method of a User Equipment (UE) and a security system for a wireless communication system are provided. The security processing method of the UE includes transmitting a Layer 3 message including a UE security capability to a Mobility Management Entity (MME) and the eNB, receiving a Access Stratum Security Mode Command (AS SMC) including a AS security algorithm selected by the eNB, as a result of verification of the UE security capability and information received from the MME, and a AS Message Authentication Code (MAC), transmitting a AS security mode complete message including the AS SMC to the eNB after verification of integrity of the AS SMC using the AS MAC, and transmitting, when receiving a Non Access Stratum (NAS) SMC including the UE security capability, a NAS security mode complete message to the MME after verification of integrity of the NAS SMC.