Method and Apparatus for Detecting Man-In-The-Middle Attack
Abstract
A system and method for detecting a man-in-the-middle attack, where the includes sending, by a secondary base station, a first check request message to a master base station, wherein the first check request message comprises first identifier information of an evolved random access bearer (ERAB) and a first data packet count value corresponding to the first identifier information; receiving, by the master base station, the first check request message; obtaining second identifier information that matches the first identifier information, wherein the second identifier information is an identifier of a data radio bearer (DRB) corresponding to the ERAB; sending a second check request message to a user terminal, wherein the second check request message comprises the first data packet count value and the second identifier information; and receiving, by the master base station, a check response message from the user terminal.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for detecting a man-in-the-middle attack, the method comprising:
sending, by a secondary base station, a first check request message to a master base station, wherein the first check request message comprises first identifier information of an evolved random access bearer (ERAB) and a first data packet count value corresponding to the first identifier information; receiving, by the master base station, the first check request message; obtaining, by the master base station, second identifier information that matches the first identifier information, wherein the second identifier information is an identifier of a data radio bearer (DRB) corresponding to the ERAB; sending, by the master base station, a second check request message to a user terminal, wherein the second check request message comprises the first data packet count value and the second identifier information; and receiving, by the master base station, a check response message from the user terminal.
2 . The method according to claim 1 , further comprising:
receiving, by the user terminal, the second check request message; determining, by the user terminal, whether a second data packet count value is equal to the first data packet count value, wherein the second data packet count value corresponds to the second identifier information; and sending, by the user terminal, the check response message to the master base station.
3 . The method according to claim 2 , further comprising generating, by the user terminal, the check response message based on determining whether the second data packet count value is equal to the first data packet count value.
4 . The method according to claim 2 , further comprising sending, by the master base station, an exception report to a mobility management entity or an operation and maintenance server when the check response message comprises the second data packet count value.
5 . The method according to claim 2 , wherein the first data packet count value reflects a count, obtained by the secondary base station, of sent and received data packets of a bearer between the secondary base station and the user terminal.
6 . The method according to claim 2 , wherein the second data packet count value reflects a count, obtained by the user terminal, of sent and received data packets of a bearer between the secondary base station and the user terminal.
7 . A system for detecting a man-in-the-middle attack, wherein the system comprises:
a master base station; and a secondary base station configured to send a first check request message, wherein the first check request message comprises first identifier information of an evolved random access bearer (ERAB) and a first data packet count value corresponding to the first identifier information, wherein the master base station is configured to:
receive the first check request message;
obtain second identifier information that matches the first identifier information, wherein the second identifier information is an identifier of a data radio bearer (DRB) corresponding to the ERAB;
send a second check request message to a user terminal, wherein the second check request message comprises the first data packet count value and the second identifier information; and
receive a check response message from the user terminal.
8 . The system according to claim 7 , wherein the user terminal is configured to:
receive the second check request message; determine whether a second data packet count value is equal to the first data packet count value, wherein the second data packet count value corresponds to the second identifier information; and send the check response message to the master base station.
9 . The system according to claim 8 , wherein the user terminal is further configured to generate the check response message based on determining whether the second data packet count value is equal to the first data packet count value.
10 . The system according to claim 8 , wherein the master base station is further configured to send an exception report to a mobility management entity or an operation and maintenance server when the check response message comprises the second data packet count value.
11 . The system according to claim 8 , wherein the first data packet count value reflects a count, obtained by the secondary base station, of sent and received data packets of a bearer between the secondary base station and the user terminal.
12 . The system according to claim 8 , wherein the second data packet count value reflects a count, obtained by the user terminal, of sent and received data packets of a bearer between the secondary base station and the user terminal.
13 . A method for detecting a man-in-the-middle attack, the method comprising:
receiving, by a master base station, a first check request message from a secondary base station, wherein the first check request message comprises first identifier information of an evolved random access bearer (ERAB) and a first data packet count value corresponding to the first identifier information; obtaining, by the master base station, second identifier information that matches the first identifier information, wherein the second identifier information is an identifier of a data radio bearer (DRB) corresponding to the ERAB; sending, by the master base station, a second check request message to a user terminal, wherein the second check request message comprises the first data packet count value and the second identifier information that matches the first identifier information; and receiving, by the master base station, a check response message from the user terminal.
14 . The method according to claim 13 wherein the check response message comprises a second data packet count value.
15 . The method according to claim 13 , further comprising sending, by the master base station, an exception report to a mobility management entity or an operation and maintenance server.
16 . The method according to claim 13 , wherein the first data packet count value reflects a count, obtained by the secondary base station, of sent and received data packets of a bearer between the secondary base station and the user terminal.
17 . The method according to claim 14 , wherein the second data packet count value reflects a count, obtained by the user terminal, of sent and received data packets of a bearer between the secondary base station and the user terminal.
18 . An apparatus comprising:
a network interface; and a processor coupled to the network interface, wherein the processor is configured to:
receive a first check request message from a secondary base station through the network interface, wherein the first check request message comprises first identifier information of an evolved random access bearer (ERAB) and a first data packet count value corresponding to the first identifier information;
obtain second identifier information that matches the first identifier information, wherein the second identifier information is an identifier of a data radio bearer (DRB) corresponding to the ERAB;
send a second check request message to a user terminal through the network interface, wherein the second check request message comprises the first data packet count value and the second identifier information that matches the first identifier information; and
receive a check response message from the user terminal through the network interface.
19 . The apparatus according to claim 18 , wherein the check response message comprises a second data packet count value.
20 . The apparatus according to claim 18 , wherein the processor is further configured to send an exception report to a mobility management entity or an operation and maintenance server.Join the waitlist — get patent alerts
Track US2019281070A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.