US2019281070A1PendingUtilityA1

Method and Apparatus for Detecting Man-In-The-Middle Attack

Assignee: HUAWEI TECH CO LTDPriority: Mar 21, 2014Filed: May 24, 2019Published: Sep 12, 2019
Est. expiryMar 21, 2034(~7.6 yrs left)· nominal 20-yr term from priority
H04L 63/12H04L 63/1441H04W 12/12H04L 63/14H04W 12/122
54
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A system and method for detecting a man-in-the-middle attack, where the includes sending, by a secondary base station, a first check request message to a master base station, wherein the first check request message comprises first identifier information of an evolved random access bearer (ERAB) and a first data packet count value corresponding to the first identifier information; receiving, by the master base station, the first check request message; obtaining second identifier information that matches the first identifier information, wherein the second identifier information is an identifier of a data radio bearer (DRB) corresponding to the ERAB; sending a second check request message to a user terminal, wherein the second check request message comprises the first data packet count value and the second identifier information; and receiving, by the master base station, a check response message from the user terminal.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for detecting a man-in-the-middle attack, the method comprising:
 sending, by a secondary base station, a first check request message to a master base station, wherein the first check request message comprises first identifier information of an evolved random access bearer (ERAB) and a first data packet count value corresponding to the first identifier information;   receiving, by the master base station, the first check request message;   obtaining, by the master base station, second identifier information that matches the first identifier information, wherein the second identifier information is an identifier of a data radio bearer (DRB) corresponding to the ERAB;   sending, by the master base station, a second check request message to a user terminal, wherein the second check request message comprises the first data packet count value and the second identifier information; and   receiving, by the master base station, a check response message from the user terminal.   
     
     
         2 . The method according to  claim 1 , further comprising:
 receiving, by the user terminal, the second check request message;   determining, by the user terminal, whether a second data packet count value is equal to the first data packet count value, wherein the second data packet count value corresponds to the second identifier information; and   sending, by the user terminal, the check response message to the master base station.   
     
     
         3 . The method according to  claim 2 , further comprising generating, by the user terminal, the check response message based on determining whether the second data packet count value is equal to the first data packet count value. 
     
     
         4 . The method according to  claim 2 , further comprising sending, by the master base station, an exception report to a mobility management entity or an operation and maintenance server when the check response message comprises the second data packet count value. 
     
     
         5 . The method according to  claim 2 , wherein the first data packet count value reflects a count, obtained by the secondary base station, of sent and received data packets of a bearer between the secondary base station and the user terminal. 
     
     
         6 . The method according to  claim 2 , wherein the second data packet count value reflects a count, obtained by the user terminal, of sent and received data packets of a bearer between the secondary base station and the user terminal. 
     
     
         7 . A system for detecting a man-in-the-middle attack, wherein the system comprises:
 a master base station; and   a secondary base station configured to send a first check request message, wherein the first check request message comprises first identifier information of an evolved random access bearer (ERAB) and a first data packet count value corresponding to the first identifier information,   wherein the master base station is configured to:
 receive the first check request message; 
 obtain second identifier information that matches the first identifier information, wherein the second identifier information is an identifier of a data radio bearer (DRB) corresponding to the ERAB; 
 send a second check request message to a user terminal, wherein the second check request message comprises the first data packet count value and the second identifier information; and 
 receive a check response message from the user terminal. 
   
     
     
         8 . The system according to  claim 7 , wherein the user terminal is configured to:
 receive the second check request message;   determine whether a second data packet count value is equal to the first data packet count value, wherein the second data packet count value corresponds to the second identifier information; and   send the check response message to the master base station.   
     
     
         9 . The system according to  claim 8 , wherein the user terminal is further configured to generate the check response message based on determining whether the second data packet count value is equal to the first data packet count value. 
     
     
         10 . The system according to  claim 8 , wherein the master base station is further configured to send an exception report to a mobility management entity or an operation and maintenance server when the check response message comprises the second data packet count value. 
     
     
         11 . The system according to  claim 8 , wherein the first data packet count value reflects a count, obtained by the secondary base station, of sent and received data packets of a bearer between the secondary base station and the user terminal. 
     
     
         12 . The system according to  claim 8 , wherein the second data packet count value reflects a count, obtained by the user terminal, of sent and received data packets of a bearer between the secondary base station and the user terminal. 
     
     
         13 . A method for detecting a man-in-the-middle attack, the method comprising:
 receiving, by a master base station, a first check request message from a secondary base station, wherein the first check request message comprises first identifier information of an evolved random access bearer (ERAB) and a first data packet count value corresponding to the first identifier information;   obtaining, by the master base station, second identifier information that matches the first identifier information, wherein the second identifier information is an identifier of a data radio bearer (DRB) corresponding to the ERAB;   sending, by the master base station, a second check request message to a user terminal, wherein the second check request message comprises the first data packet count value and the second identifier information that matches the first identifier information; and   receiving, by the master base station, a check response message from the user terminal.   
     
     
         14 . The method according to  claim 13  wherein the check response message comprises a second data packet count value. 
     
     
         15 . The method according to  claim 13 , further comprising sending, by the master base station, an exception report to a mobility management entity or an operation and maintenance server. 
     
     
         16 . The method according to  claim 13 , wherein the first data packet count value reflects a count, obtained by the secondary base station, of sent and received data packets of a bearer between the secondary base station and the user terminal. 
     
     
         17 . The method according to  claim 14 , wherein the second data packet count value reflects a count, obtained by the user terminal, of sent and received data packets of a bearer between the secondary base station and the user terminal. 
     
     
         18 . An apparatus comprising:
 a network interface; and   a processor coupled to the network interface, wherein the processor is configured to:
 receive a first check request message from a secondary base station through the network interface, wherein the first check request message comprises first identifier information of an evolved random access bearer (ERAB) and a first data packet count value corresponding to the first identifier information; 
 obtain second identifier information that matches the first identifier information, wherein the second identifier information is an identifier of a data radio bearer (DRB) corresponding to the ERAB; 
 send a second check request message to a user terminal through the network interface, wherein the second check request message comprises the first data packet count value and the second identifier information that matches the first identifier information; and 
 receive a check response message from the user terminal through the network interface. 
   
     
     
         19 . The apparatus according to  claim 18 , wherein the check response message comprises a second data packet count value. 
     
     
         20 . The apparatus according to  claim 18 , wherein the processor is further configured to send an exception report to a mobility management entity or an operation and maintenance server.

Join the waitlist — get patent alerts

Track US2019281070A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.