Identifying and reporting rogue base stations
By using a system of at least two radio devices and an analyzer device in a cellular telecommunication system, fraudulent base stations are identified by utilizing identification request message reports received from the same base station within a threshold duration, thereby solving the problems of cumbersome detection and high computational requirements in the prior art and achieving efficient, immediate and accurate fraudulent base station detection.
Patent Information
- Application Number
- CN201980100585.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-09-24
- Filing Date
- 2019-10-25
- Publication Date
- 2025-09-16
- Estimated Expiration
- 2039-10-25
AI Technical Summary
Existing technologies have difficulty in efficiently identifying and detecting fraudulent base stations, especially in cellular telecommunication systems, due to the problems of cumbersome detection and high computational requirements.
Reports of identification request messages received from the same base station within a threshold duration are used to identify rogue base stations by configuring a system of at least two radio devices and an analyzer device, the analyzer device identifying base stations for which reports are received within the threshold time as rogue.
The proposed method achieves efficient, instant, and low-computational detection of deceptive base stations, reduces false alarms, improves detection accuracy, and does not require private information at the network level or end users, thus avoiding privacy issues.
Smart Images

Figure CN114424606B_ABST
Abstract
Description
Technical Field
[0001] The embodiments presented herein relate to methods, systems, analyzer devices, computer programs, and computer program products for identifying rogue base stations. The embodiments presented herein also relate to methods, radio devices, computer programs, and computer program products for reporting rogue base stations. Background Art
[0002] Cellular telecommunication systems (2G, 3G, 4G, and 5G systems) are inherently composed of a structure of interconnected cells, where a cell in this context represents a coverage area served by a base station that transmits wireless radio signals. Typically, a base station is equipped with a powerful RF (radio frequency) transceiver and antenna to serve its coverage area. Cellular telecommunication systems are sometimes also referred to as mobile communication systems (or networks), cellular (or wireless) communication networks, cellular radio systems, or cellular networks. In these systems, several services can be provided, such as wireless Internet access, voice call services, short messaging services, and data sharing between users. Here, each user is represented by a user equipment (UE) that accesses the cellular telecommunication system.
[0003] In different generations of cellular telecommunication systems, base stations are referred to by different terms. For example, they are called base transceiver stations (BTS) in 2G systems, NodeB in 3G systems, eNodeB in 4G systems, and gNodeB in 5G systems. The base station transmits radio signals constructed according to relevant international standards. These signals include, for example, information about the base station itself, such as physical cell ID, signal frequency, and synchronization information. Each UE extracts this information from the received signal and calculates various parameter values, such as RSRP (reference signal received power). RSRP depends on several factors, such as the radiated power of the base station, the receiver sensitivity at the UE, and the location where the measurement is performed. The UE can simultaneously sense RF signals belonging to different base stations and select the RF signal that is considered to best serve the UE based on some standard specifications. One criterion in this regard is RSRP, because the UE tends to attach to the base station that causes the highest possible RSSP. This base station is typically the base station that is physically closest to the UE.
[0004] Each UE is associated with a subscriber, which is required for the UE to access the cellular telecommunication system via a base station. Subscribers in a cellular telecommunication system have a long-term identifier called an International Mobile Subscriber Identifier (IMSI), which can be embedded in a Universal Subscriber Identity Module (USIM), for example. This is a unique identifier assigned to the subscriber, so for security and privacy reasons, it should be handled carefully in network protocols and applications. When a subscriber attempts to join the network by connecting to a base station via a UE, an attach procedure is performed. This attach procedure requires the UE's identity to be disclosed over the radio link. At this step, a short-term identifier called a Temporary Mobile Subscriber Identity (TMSI) is used instead of the IMSI to ensure the user's privacy. The TMSI is generated by the core network and stored in a database (the Visitor Location Register (VLR)), which associates the TMSI with the corresponding IMSI. The TMSI is updated regularly based on the physical location of the UE.
[0005] During the attach procedure in 4G systems (and earlier generation systems), a Mobility Management Entity (MME) or similar entity requests the UE to identify itself through the base station to which the UE is attempting to connect. The UE typically responds to this request by declaring its TMSI. However, the relevant standards allow the base station to request the long-term identifier IMSI instead of the TMSI by sending a special IDENTITY REQUEST message as a mechanism to address situations where the TMSI is lost or unavailable in the network. This mechanism can be exploited by a malicious unauthorized base station (hereinafter referred to as a spoofed base station) to capture the IMSI of the UE by sending an IDENTITY REQUEST message. To this end, the spoofed base station can announce itself as the preferred serving point for the UE by radiating a stronger signal than other base stations.
[0006] The deceptive base stations mentioned in this disclosure are sometimes referred to by different terms, such as fake base stations, IMSI catchers, base station simulators (stingrays), rogue base stations, fake base stations, etc. In this disclosure, the term "spoofed base station" is used to refer to a base station established for the purpose of capturing a long-term identifier (e.g., IMSI) of a subscriber of a UE in a cellular telecommunication system.
[0007] In some cases, a rogue base station can achieve its goals by exploiting the Tracking Area Update (TAU) process (as used in 4G systems) and the Location Area Update (LAU) process (as used in 3G systems) in the following manner: the rogue base station advertises itself with a different tracking area identifier or location area identifier from the legitimate base station, thereby convincing the UE to receive a signal from the rogue base station to initiate the TAU or LAU process involving the attach procedure. Because there is no security mechanism designed for mutual authentication between the UE and the base station during the initial stages of the attach procedure, the rogue base station can obtain the UE's IMSI. Legal measures may not be sufficient to prevent such base station abuse. Therefore, some technical countermeasures are also needed.
[0008] Earlier proposed methods for detecting rogue base stations can be categorized into two groups: (i) device-assisted mechanisms; and (ii) network-assisted mechanisms. As an example of the first category, a technician may manually observe the radio signals received at a specific location by using radio equipment or a spectrum analyzer to see if there are any suspicious signals that may be signs of a possible rogue base station. As another example of the first category, a special type of terminal is configured to send a location area update request message to a target base station, and then identify it as a rogue base station if a REJECT message is received from the base station as a reply. As an example of the second category, the base station first collects periodic measurement reports of all UEs in the area of interest and forwards them to a central unit for further processing. Anomaly detection is then performed at the central unit by analyzing the collected measurement reports and comparing them with the network topology of all legitimate base stations.
[0009] The first type of early methods described above are cumbersome to implement, while the second type of early methods described above have high computational requirements. Therefore, there remains a need for improved detection of deceptive base stations. Summary of the Invention
[0010] It is an object of embodiments herein to provide efficient identification and reporting of rogue base stations so that the above-mentioned problems do not suffer or are at least mitigated or alleviated.
[0011] According to a first aspect, a system for identifying a fraudulent base station is provided. The system includes an analyzer device and at least two radio devices. The system is configured to, when any one of the at least two radio devices has received an identification request message for a long-term identifier of the at least two radio devices from a base station, provide a report of the identification request message from the at least two radio devices to the analyzer device. The system is configured to, when reports of the same base station received from at least two different ones of the at least two radio devices are received within a threshold duration relative to each other, identify the base station as fraudulent by the analyzer device.
[0012] According to a second aspect, a method for identifying a fraudulent base station is provided. The method is performed by an analyzer device. The method comprises: when any one of at least two radio devices has received an identification request message for a long-term identifier of the at least two radio devices from a base station, receiving a report of the identification request message from the at least two radio devices. The method comprises: when reports of the same base station received from two different ones of the at least two radio devices are received within a threshold duration relative to each other, identifying the base station as fraudulent.
[0013] According to a third aspect, an analyzer device for identifying a spoofed base station is provided. The analyzer device includes processing circuitry. The processing circuitry is configured to cause the analyzer device to perform the following operations: when any one of at least two radio devices has received an identification request message for a long-term identifier of the at least two radio devices from a base station, receive a report of the identification request message from the at least two radio devices. The processing circuitry is configured to cause the analyzer device to perform the following operations: when reports of the same base station received from two different ones of the at least two radio devices are received within a threshold duration relative to each other, identify the base station as spoofed.
[0014] According to a fourth aspect, an analyzer device for identifying a fraudulent base station is provided. The analyzer device includes a receiving module configured to, when any one of at least two radio devices has received an identification request message for a long-term identifier of the at least two radio devices from a base station, receive a report of the identification request message from the at least two radio devices. The analyzer device includes an identifying module configured to, when reports of the same base station received from two different ones of the at least two radio devices are received within a threshold duration relative to each other, identify the base station as fraudulent.
[0015] According to a fifth aspect, a computer program for identifying a fraudulent base station is proposed. The computer program comprises computer program code which, when run on processing circuitry of an analyzer device, causes the analyzer device to perform the method according to the second aspect.
[0016] According to a sixth aspect, a method for reporting a fraudulent base station is provided. The method is performed by a radio device. The method includes receiving an identification request message for a long-term identifier of the radio device from a base station. The method also includes providing a report of the identification request message to an analyzer device when the radio device has received the identification request message.
[0017] According to a seventh aspect, a radio device for reporting a fraudulent base station is proposed.
[0018] The radio device includes a processing circuit configured to cause the radio device to receive an identification request message for a long-term identifier of the radio device from a base station. The processing circuit is configured to cause the radio device to provide a report of the identification request message to an analyzer device when the radio device has received the identification request message.
[0019] According to an eighth aspect, a radio device for reporting a fraudulent base station is proposed.
[0020] The radio device comprises a receiving module configured to receive an identification request message for a long-term identifier of the radio device from a base station and a providing module configured to provide a report of the identification request message to an analyzer device when the radio device has received the identification request message.
[0021] According to a ninth aspect, a computer program for reporting a fraudulent base station is provided. The computer program comprises computer program code which, when executed on processing circuitry of a radio device, causes the radio device to perform the method according to the sixth aspect.
[0022] According to a tenth aspect, a computer program product is provided, comprising a computer program according to at least one of the fifth and ninth aspects and a computer-readable storage medium on which the computer program is stored. The computer-readable storage medium may be a non-transitory computer-readable storage medium.
[0023] Advantageously, the methods, the systems, the analyzer devices, the radio devices, the computer programs, and the computer program products provide for efficient identification and reporting of rogue base stations.
[0024] Advantageously, the methods, the system, the analyzer devices, the radio devices, the computer programs and the computer program products do not suffer from the above-mentioned problems.
[0025] Advantageously, the methods, the system, the analyzer devices, the radio devices, the computer programs and the computer program product are simple to implement and do not have high computational requirements.
[0026] Advantageously, the methods, the systems, the analyzer devices, the radio devices, the computer programs and the computer program products enable instant detection of rogue base stations without requiring any prior preparation, such as data collection, related to legitimate networks or areas to be scanned.
[0027] Advantageously, the methods, the system, the analyzer devices, the radio devices, the computer programs and the computer program product do not require any changes at the network level or in the protocols used.
[0028] Advantageously, the methods, the systems, the analyzer devices, the radio devices, the computer programs and the computer program products enable reduction of false alarms and improvement of detection accuracy compared to training-based mechanisms for detecting rogue base stations.
[0029] Advantageously, the methods, the system, the analyzer devices, the radio devices, the computer programs and the computer program product do not require any private information about the network or about the end user, thereby eliminating the risk of privacy issues arising.
[0030] Other objectives, features and advantages of the accompanying embodiments will be apparent from the following detailed disclosure, the attached dependent claims as well as the accompanying drawings.
[0031] Generally, all terms used in the claims are to be interpreted according to their ordinary meaning in the technical field, unless explicitly defined otherwise herein. All references to "a / an / the element, device, component, means, module, step, etc." are to be interpreted openly as referring to at least one instance of the element, device, component, means, module, step, etc., unless explicitly stated otherwise. The steps of any method disclosed herein do not have to be performed in the exact order disclosed, unless explicitly stated otherwise. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] The present inventive concept will now be described by way of example with reference to the accompanying drawings, in which:
[0033] Figure 1 is a schematic diagram illustrating a cellular telecommunication system according to an embodiment;
[0034] Figure 2 and Figure 3 is a schematic diagram of a system according to an embodiment;
[0035] Figure 4 、 Figure 5 、 Figure 6 and Figure 7 is a flow chart of a method according to an embodiment;
[0036] Figure 8 is a signaling diagram according to an embodiment;
[0037] Figure 9 is a schematic diagram illustrating functional units of an analyzer device according to an embodiment;
[0038] Figure 10 is a schematic diagram illustrating functional modules of an analyzer device according to an embodiment;
[0039] Figure 11 is a schematic diagram showing functional units of a radio device according to an embodiment;
[0040] Figure 12 is a schematic diagram showing functional modules of a radio device according to an embodiment; and
[0041] Figure 13 One example of a computer program product comprising computer readable means according to an embodiment is shown. DETAILED DESCRIPTION
[0042] The present invention will now be described more fully below with reference to the accompanying drawings, in which certain embodiments of the present invention are shown. However, the present invention can be embodied in many different forms and should not be construed as limited to the embodiments set forth herein; rather, these embodiments are provided by way of example so that this disclosure will be thorough and complete and will fully convey the scope of the present invention to those skilled in the art. Throughout the specification, like reference numerals refer to like elements. Any steps or features shown by dashed lines should be considered optional.
[0043] Figure 1 1 is a schematic diagram illustrating a simplified version of a cellular telecommunication system 10 to which the embodiments presented herein may be applied. Cellular telecommunication system 10 includes a base station 20, which is assumed to be a fraudulent base station. The fraudulent base station 20 transmits a radio signal, as indicated by radiating arrows 30. The radio signal is assumed to be received by radio devices (RD) 300a, 300b. As will be disclosed in greater detail below, the radio devices 300a, 300b provide a report to an analyzer device (AD) 200, which is configured to identify the base station as fraudulent. The analyzer device 200 and at least two radio devices 300a, 300b together constitute system 100.
[0044] In particular, embodiments disclosed herein relate to mechanisms for identifying and reporting rogue base stations 20. To achieve such mechanisms, an analyzer device 200, a method performed by the analyzer device 200, and a computer program product including code, such as in the form of a computer program, that when executed on processing circuitry of the analyzer device 200 causes the analyzer device 200 to perform the method are provided. To achieve such mechanisms, a radio device 300a:300N, a method performed by the radio device 300a:300N, and a computer program product including code, such as in the form of a computer program, that when executed on processing circuitry of the radio device 300a:300N causes the radio device 300a:300N to perform the method are also provided. To achieve such mechanisms, a system including the analyzer device 200 and at least two radio devices 300a:300N is also provided.
[0045] There are different systems 100. Reference will now be made to Figure 2 and Figure 3 Two non-limiting examples thereof are disclosed.
[0046] Figure 2 A system 100 according to a first embodiment is shown. Figure 2In the embodiment of the present invention, each of the at least two radio devices 300a: 300N is operatively connected to the analyzer device 200 via a wired connection 40a. As known to those skilled in the art, there may be different types of wired connections, such as fiber optic connections, coaxial cable connections, twisted pair cable connections, etc. Figure 2 In an embodiment, the analyzer device 200 and the at least two radio devices 300 a : 300 N are integrated, collocated or provided within the same physical entity, wherein the physical entity defines the system 100 . Figure 2 The system 100 may be immovable and fixed to a strategic location to enable continuous monitoring of any rogue base stations at such a strategic location. Thus, according to one example, the system 100 is configured to be installed at a fixed location. Alternatively, Figure 2 The system 100 can be mounted on a vehicle (e.g., a car, an unmanned aerial vehicle (UAV), etc.) to enable intermittent monitoring of different locations. Thus, according to one example, the system 100 is configured to be mobile. In this sense, more than one such system 100 can be deployed to monitor different areas, and more than one such system 100 can be configured to issue a notification that a base station is identified as a rogue base station.
[0047] Figure 3 A system 100 according to a second embodiment is shown. Figure 3 In the embodiment of the present invention, each of the at least two radio devices 300a: 300N is operatively connected to the analyzer device 200 via a wireless connection 40b. Figure 3 , further, optional, at least two radio devices 300a': 300N' are shown, each of which is operatively connected to the analyzer device 200 via a respective wireless connection. As known to those skilled in the art, there may be different types of wireless connections, such as a wireless connection using radio signaling, a wireless connection using infrared signaling, etc. Figure 3 The analyzer device 200 of the system 100 in FIG. 1 may reside in a cloud computing environment. Since at least two radio devices 300a:300N are mobile, by definition, Figure 3 The system 100 is considered to be mobile.
[0048] In some embodiments, such as the first and second embodiments described above, it is assumed that at least two radio devices 300a: 300N are positioned relative to each other to receive signals from the same base station. Figure 2In the example, radios 300a:300N form a first group of radios positioned relative to each other to receive signals from the same base station, while optional radios 300a':300N' form a second group of radios positioned relative to each other to receive signals from the same base station.
[0049] Now refer to Figure 4 , Figure 4 A method for identifying a fraudulent base station 20 performed by an analyzer device 200 according to an embodiment is shown.
[0050] As will be disclosed further below, each of the radio devices 300a:300N is configured to report any received identification request messages to the analyzer device 200. Therefore, the analyzer device 200 is configured to perform S102:
[0051] S102: The analyzer device 200 receives a report. When any one of the at least two radio devices 300a and 300N has received an identification request message for the long-term identifier of the at least two radio devices 300a and 300N from the base station 20, the analyzer device 200 receives the report from the at least two radio devices 300a and 300N. The report is a report of the identification request message.
[0052] Based on the time difference between the reports, the base station 20 is identified as being fraudulent. Specifically, the analyzer device 200 is configured to perform S104:
[0053] S104: The analyzer device 200 identifies the base station 20 as being fraudulent when reports of the same base station 20 received from two different ones of the at least two radio devices 300a:300N are received within a threshold duration relative to each other.
[0054] In this regard, based on actual network statistics, it is highly unlikely that two or more radio devices 300a:300N in close proximity will receive an identification request message simultaneously or within a very short time period defined by a threshold duration. This is due to the fact that an identification request message is only sent by a legitimate base station in some special circumstances to request a long-term identifier from a UE, such as during initial registration with the network, when the long-term identifier is lost in the core network, or when authentication between the UE and the base station fails. The embodiments disclosed herein take advantage of this fact. Therefore, by using the radio device 300a:300N, the radio environment can be efficiently (continuously or intermittently) scanned for potential rogue base stations, thereby enabling real-time detection and identification of any rogue base stations.
[0055] Embodiments involving further details of the identification of rogue base stations 20 performed by the analyzer device 200 will now be disclosed.
[0056] In some aspects, the analyzer 200 issues a notification when the base station 20 has been identified as being fraudulent. Specifically, in some embodiments, the analyzer device 200 is configured to perform (optional) step S110:
[0057] S110 : The analyzer device 200 issues a notification of the fraudulent base station 20 thus identified.
[0058] In S110, analyzer device 200 may issue different types of notifications. For example, the notification may be an alert message. The recipient of the notification may be of different types. For example, analyzer device 200 may send the notification to a network management entity. Thus, if a fraudulent base station has been identified in S104, analyzer device 200 may send the notification in the form of an alert message to the network management entity for further processing of the fraudulent base station.
[0059] In some aspects, the analyzer device 200 issues a notification in S110 only when one or more conditions are met. Examples of such conditions will be disclosed next.
[0060] A first condition relates to how many radio devices 300a:300N have received reports from within a threshold duration. That is, in some embodiments, the analyzer device 200 issues a notification in S110 only when it has received reports from at least k radio devices 300a:300N for the same base station 20 that are at most separated by the threshold duration, where k is an integer greater than 1. The higher the value of k, the higher the confidence level that the base station 20 is indeed a rogue base station.
[0061] Thus, a level of certainty can be established based on how many radio devices 300a:300N report identification request messages for long-term identifiers simultaneously or within a time interval given by a threshold duration. Alternatively, assuming that there are a total of N radio devices configured to provide reports to the analyzer device 200, a notification can be issued when k of the N devices receive the same identification request message for a long-term identifier from the same cell at the same time.
[0062] A second condition relates to the level of certainty for positively identifying the base station 20 as a fraudulent base station. That is, in some embodiments, the analyzer device 200 is configured to perform (optional) step S106:
[0063] S106 : The analyzer device 200 determines the certainty level based on how many reports that are at most a threshold duration apart from each other have been received and how many at least two radio devices 300 a : 300N are operatively connected to the analyzer device 200 .
[0064] Then, in S110 , notification is issued only when the certainty level is higher than the certainty threshold.
[0065] A third condition relates to network statistics. Specifically, in some embodiments, the certainty level is also based on network statistics obtained by the analyzer device 200.
[0066] A fourth condition relates to the verification performed by the analyzer device 200. Generally speaking, a fraudulent base station will send identification request messages targeting the long-term identifier of the radio device 300a:300N much more often than a legitimate base station, regardless of whether the radio device 300a:300N has a valid long-term identifier. According to actual network statistics, for a legitimate base station, identification request messages targeting the long-term identifier may account for less than 15% of all identification request messages sent; for the remaining 85% or more, the identification request messages are for short-term identifiers. Specifically, in some embodiments, the analyzer device 200 is configured to perform (optional) step S108:
[0067] S108: The analyzer device 200 verifies that the base station 20 is not a registered base station by querying the database and before issuing a notification.
[0068] When S108 is executed, S108 is executed before S110 is executed.
[0069] Thus, the analyzer device 200 may be configured to perform analysis on reports received from the radio devices 300a:300N (if any) and thereby determine whether there are any base stations that should be considered rogue base stations based on the number of reports, the content of the reports and the timestamps of the reports.
[0070] The system 100 disclosed herein is flexible in the sense that parameters relating to any of the four conditions described above can be set with respect to the sensitivity of the detection, for example by changing the value of the threshold duration and also by adjusting how many radio devices 300a:300N need to receive reports from before a notification is issued.
[0071] Aspects of reports received from one or more of the radio devices 300a:300N will now be disclosed. In some examples, at least one of the radio devices 300a:300N reports a cell ID, i.e., an identifier that unambiguously identifies a cell within a public land mobile network (PLMN). That is, in some embodiments, the report includes the cell ID of the base station 20 that sent the identification request message.
[0072] There may be different examples of the long term identifier. According to some embodiments, the long term identifier is an IMSI.
[0073] In some aspects, one or more of the at least two radios 300a: 300N are configured to be served by two or more mobile network operators.
[0074] Specifically, in some embodiments, at least two radio devices 300a:300N are collectively configured to be served by at least two different mobile network operators. Thus, the same system 100 can be used to identify rogue base stations for two or more mobile network operators, which in turn can reduce the cost and overall power consumption of detecting rogue base stations for all mobile network operators in a specific area.
[0075] However, this does not necessarily mean that signals from base stations operated by two or more mobile network operators are collected and analyzed simultaneously.
[0076] The following will now describe how the identification request message is sent by the base station 200 and received by the at least two radio devices 300a:300N. According to a first example, the identification request message is received during an attach procedure, a TAU procedure, or a LAU procedure. According to a second example, the identification request message is received when either of the at least two radio devices 300a:300N has not yet undergone network lock. According to a third example, the identification request message is received when either of the at least two radio devices 300a:300N has performed initial registration since its radio modem was last turned on.
[0077] Now refer to Figure 5 , Figure 5 A method for reporting a fraudulent base station 20 performed by a radio device 300a : 300N according to an embodiment is shown.
[0078] The radio device 300a:300N is configured to receive a message from a base station. Specifically, the radio device 300a:300N is configured to execute S202:
[0079] S202 : The radio device 300 a : 300N receives an identification request message for the long-term identifier of the radio device 300 a : 300N from the base station 20 .
[0080] Then, the radio device 300a:300N reports the identification request message to the analyzer device. That is, the radio device 300a:300N is configured to perform S204:
[0081] S204 : When the radio device 300 a : 300N has received the identification request message, the radio device 300 a : 300N provides a report of the identification request message to the analyzer device 200 .
[0082] Embodiments will now be disclosed involving further details of the reporting of a rogue base station 20 performed by the radio devices 300a:300N.
[0083] Generally speaking, the radio devices 300a:300N register with the network as normal UEs.
[0084] As mentioned above, in some embodiments the report includes the cell ID of the base station 20 that has sent the identification request message.
[0085] As mentioned above, in some embodiments the long-term identifier is an IMSI.
[0086] As described above, according to the first example, the radio device 300a:300N receives the identification request message during an attach procedure, a TAU procedure, or a LAU procedure. As described above, according to the second example, the identification request message is received when the radio device 300a:300N has not yet undergone network lock. As described above, according to the third example, the identification request message is received when the radio device 300a:300N has performed initial registration since its radio modem was last turned on.
[0087] refer to Figure 6 , which illustrates a method performed by a radio device 300a: 300N for reporting a fraudulent base station 20 based on at least some of the above embodiments.
[0088] S301: The radio devices 300a: 300N listen to any message sent from the base station.
[0089] S302: The radio devices 300a:300N receive a message from one of the base stations.
[0090] S303: The radio devices 300a:300N check whether the message is an identification request message for a long-term identifier. If yes, the process proceeds to step S304; if not, the process proceeds to step S301.
[0091] S304 : The radio devices 300 a : 300N report the message to the analyzer device 200 .
[0092] refer to Figure 7 , Figure 7 A method for identifying a rogue base station 20 performed by an analyzer device 200 based on at least some of the above-described embodiments is shown.
[0093] S401 : The analyzer device 200 listens for any reports of identification request messages for long-term identifiers that have been received by any of the radio devices 300a : 300N.
[0094] S402: The analyzer device 200 receives a report from one of the radio devices 300a:300N of an identification request message for a long-term identifier that has been received by the one of the radio devices 300a:300N.
[0095] S403: The analyzer device 200 writes the received report and a timestamp indicating when the report was received into a list. Alternatively, the timestamp indicates when the relevant radio device 300a:300N received the identification request message.
[0096] S404: The analyzer device 200 removes from the list any report with a timestamp older than the threshold time value.The analyzer device 200 also removes from the list any previous report from the same base station of the same radio device 300a:300N, even if the previous report is not older than the threshold time value.
[0097] S405: The analyzer device 200 checks whether there are more than k reports in the list. If yes, it proceeds to step S406; if not, it proceeds to step S401.
[0098] S406: The analyzer device 200 issues a notification that a fraudulent base station has been identified.
[0099] refer to Figure 8 , Figure 8 A method for identifying and reporting a rogue base station 20 performed by the analyzer device 200 and the radio devices 300a: 300N is shown based on at least some of the above-described embodiments.
[0100] S501: The fraudulent base station 20 sends an identification request message for a long-term identifier. The identification request message is received by the radio device 300N.
[0101] S502: The radio device 300N provides a report of the identification request message to the analyzer device 200, and also appends its own ID and, optionally, a timestamp indicating when the identification request message was received to the report.
[0102] S503: The analyzer device 200 writes the received report and a timestamp indicating when the report was received (and / or when the identification request message was received by the relevant radio device 300a:300N) into a list. The analyzer device 200 removes from the list any previous reports received from the radio device 300N belonging to the same reported base station. Since no previous reports were received, the report is not removed. The analyzer device 200 checks whether there are k>1 reports in the list for the same base station and whether these k reports all have a timestamp that is no earlier than the threshold time value given by the time window W1. Since only one report was received, this condition is not met. Therefore, the base station 20 has not been identified as fraudulent.
[0103] S504: The fraudulent base station 20 sends another identification request message for the long-term identifier. The identification request message is received by the radio device 300b.
[0104] S505: The radio device 300b provides a report of the identification request message to the analyzer device 200, and also appends its own ID and, optionally, a timestamp indicating when the identification request message was received to the report.
[0105] S506: The analyzer device 200 writes the received report and a timestamp indicating when the report was received (and / or when the relevant radio device 300a:300N received the identification request message) into a list. The analyzer device 200 removes any previous report received from the radio device 300b from the list. Since no previous report was received from the radio device 300b, the report is not removed. The analyzer device 200 checks whether there are k>1 reports for the same base station and whether these k reports all have a timestamp that is not earlier than the threshold time value given by the time window W2. Since there are two reports for the same base station in the list (i.e., k=2) and these reports were both received within the time window W2, this condition is met. Therefore, the base station 20 is identified as being fraudulent. Therefore, the analyzer device 200 can issue a notification.
[0106] S507: The fraudulent base station 20 sends yet another identification request message for the long-term identifier. The identification request message is received by the radio device 300a.
[0107] S508: The radio device 300a provides a report of the identification request message to the analyzer device 200, and also appends its own ID and, optionally, a timestamp indicating when the identification request message was received to the report.
[0108] S506: The analyzer device 200 writes the received report and a timestamp indicating when the report was received (and / or when the identification request message was received by the relevant radio device 300a:300N) into the list. The analyzer device 200 removes from the list any previous report received from the radio device 300a. Since no previous report was received from the radio device 300a, the report is not removed. The analyzer device 200 checks whether there are more than k>1 reports and whether these k reports all have a timestamp that is not earlier than the threshold time value given by the time window W3. The list is now
[0109] There are three reports in the , but the reports from radio 300b and radio 300N are
[0110] The notifications are all received outside the time window W3, so the condition is no longer met. Therefore, the base station 20 is not identified as being fraudulent in this context.
[0111] Thus, in this embodiment, the analyzer device 200 retains in the list only the most recent reports received for each radio device 300a:300N. Furthermore, older reports are periodically removed from the list according to a sliding time window (as given by W1, W2, W3). In this regard, W1, W2, and W3 are examples of threshold durations. Whenever there are k > 1 reports in the list, this indicates that a fraudulent base station has been identified.
[0112] While the condition of k > 1 reports in the list has been used in some of the above embodiments and examples, other conditions are possible. For example, a general condition could require k > z reports in the list, where z > 1. The higher the value of z, the higher the probability that base station 20 is indeed a fraudulent base station. However, increasing the value of z also increases the risk of missing the identification of base station 20 as a fraudulent base station. Generally speaking, the value of z can be set to a value that depends on the total number N of radio devices 300a:300N; the higher the value of N, the higher the value of z can be set to. Of course, z should never be set to a value higher than N.
[0113] Figure 9 The components of the analyzer device 200 according to the embodiment are schematically shown in the form of a plurality of functional units. Figure 13 The processing circuit 210 may be provided by any combination of one or more of a suitable central processing unit (CPU), a multiprocessor, a microcontroller, a digital signal processor (DSP), etc., which execute software instructions in accordance with the embodiment of the present invention (as shown in FIG). The processing circuit 210 may also be provided as at least one application-specific integrated circuit (ASIC) or a field-programmable gate array (FPGA).
[0114] Specifically, the processing circuit 210 is configured to cause the analyzer device 200 to perform a set of operations or steps as disclosed above. For example, the storage medium 230 may store the set of operations, and the processing circuit 210 may be configured to retrieve the set of operations from the storage medium 230 to cause the analyzer device 200 to perform the set of operations. The set of operations may be provided as a set of executable instructions. Thus, the processing circuit 210 is thereby arranged to perform the method as disclosed herein.
[0115] The storage medium 230 may also include permanent storage, which may be, for example, any single one or combination of magnetic storage, optical storage, solid-state storage, or even remotely mounted storage.
[0116] The analyzer device 200 may also include a communication interface 220 for communicating with Figure 1 Thus, the communication interface 220 may include one or more transmitters and receivers including analog and digital components.
[0117] Processing circuitry 210 controls the general operation of analyzer device 200, for example, by sending data and control signals to communication interface 220 and storage medium 230, by receiving data and reports from communication interface 220, and by retrieving data and instructions from storage medium 230. Other components of analyzer device 200 and related functionality are omitted so as not to obscure the concepts presented herein.
[0118] Figure 10 The components of the analyzer device 200 according to the embodiment are schematically shown in the form of a number of functional modules. Figure 10 The analyzer device 200 includes a plurality of functional modules: a receiving module 210 a configured to perform step S102 ; and an identifying module 210 b configured to perform step S104 . Figure 10 The analyzer device 200 may further include a plurality of optional functional modules, such as a determination module 210c configured to perform step S106, a verification module 210d configured to perform step S108, and an issuance module 210e configured to perform step S110. In general, each of the functional modules 210a to 210e may be implemented in hardware or software. Preferably, one or more or all of the functional modules 210a to 210e may be implemented by the processing circuit 210 (possibly in conjunction with the communication interface 220 and / or the storage medium 230). Thus, the processing circuit 210 may be arranged to extract instructions provided by the functional modules 210a to 210e from the storage medium 230 and execute these instructions, thereby performing any steps of the analyzer device 200 as disclosed herein.
[0119] The analyser device 200 may be provided as a standalone device or as part of at least one further device. For example, the analyser device 200 may be provided in a node of a radio access network or in a node of a core network. Alternatively, the functionality of the analyser device 200 may be distributed between at least two devices or nodes. These at least two nodes or devices may be part of the same network portion (e.g. a radio access network or a core network) or may be spread between at least two such network portions. In general, instructions that require real-time execution may be executed in a device or node that is operationally closer to the cell than instructions that do not require real-time execution. Thus, a first part of the instructions executed by the analyser device 200 may be executed in a first device and a second part of the instructions executed by the analyser device 200 may be executed in a second device; the embodiments disclosed herein are not limited to any particular number of devices on which the instructions executed by the analyser device 200 may be executed. Thus, the method according to the embodiments disclosed herein is suitable for execution by the analyser device 200 residing in a cloud computing environment. Thus, although Figure 9 A single processing circuit 210 is shown in FIG, but the processing circuit 210 may be distributed among multiple devices or nodes. The same applies to Figure 10 Functional modules 210a to 210e and Figure 13 Computer program 1320a.
[0120] Figure 11 The components of the radio device 300a: 300N according to the embodiment are schematically shown in the form of a plurality of functional units. Figure 13 The processing circuit 310 may be provided by any combination of one or more of a suitable central processing unit (CPU), a multiprocessor, a microcontroller, a digital signal processor (DSP), etc., which execute software instructions in accordance with the embodiment of the present invention (as shown). The processing circuit 310 may also be provided as at least one application-specific integrated circuit (ASIC) or a field-programmable gate array (FPGA).
[0121] Specifically, the processing circuit 310 is configured to cause the radio device 300a:300N to perform a set of operations or steps as disclosed above. For example, the storage medium 330 may store the set of operations, and the processing circuit 310 may be configured to retrieve the set of operations from the storage medium 330 to cause the radio device 300a:300N to perform the set of operations. The set of operations may be provided as a set of executable instructions. Thus, the processing circuit 310 is thereby arranged to perform the method as disclosed herein.
[0122] The storage medium 330 may also include permanent storage, which may be, for example, any single one or combination of magnetic storage, optical storage, solid-state storage, or even remotely mounted storage.
[0123] The radio device 300a:300N may also include a communication interface 320 for communicating with the Figure 1 Thus, the communication interface 320 may include one or more transmitters and receivers including analog and digital components.
[0124] The processing circuit 310 controls the general operation of the radio devices 300a:300N, for example, by sending data and control signals to the communication interface 320 and the storage medium 330, by receiving data and reports from the communication interface 320, and by retrieving data and instructions from the storage medium 330. Other components of the radio devices 300a:300N and related functionality are omitted to avoid obscuring the concepts presented herein.
[0125] Figure 12 Components of a radio device 300a : 300N according to an embodiment are schematically illustrated in the form of a plurality of functional modules. Figure 12 The radio device 300a: 300N includes a plurality of functional modules: a receiving module 310a configured to perform step S202; and a providing module 310b configured to perform step S204. Figure 12 The radio device 300a:300N may also include a plurality of optional functional modules, such as functional module 310c. In general, each of the functional modules 310a-310c may be implemented in hardware or software. Preferably, one or more or all of the functional modules 310a-310c may be implemented by the processing circuit 310 (possibly in cooperation with the communication interface 320 and / or the storage medium 330). Thus, the processing circuit 310 may be arranged to retrieve instructions provided by the functional modules 310a-310c from the storage medium 330 and execute these instructions, thereby performing any of the steps of the radio device 300a:300N as disclosed herein.
[0126] Figure 13An example of a computer program product 1310a, 1310b comprising a computer-readable device 1330 is shown. The computer-readable device 1330 may store a computer program 1320a that can cause the processing circuit 210 and entities and devices operatively coupled thereto (e.g., communication interface 220 and storage medium 230) to perform methods according to the embodiments described herein. Thus, the computer program 1320a and / or computer program product 1310a can provide means for performing any of the steps of the analyzer device 200 as disclosed herein. The computer-readable device 1330 may store a computer program 1320b that can cause the processing circuit 310 and entities and devices operatively coupled thereto (e.g., communication interface 320 and storage medium 330) to perform methods according to the embodiments described herein. Thus, the computer program 1320b and / or computer program product 1310b can provide means for performing any of the steps of the radio devices 300a, 300N as disclosed herein.
[0127] exist Figure 13 In the example of FIG, computer program products 1310a, 1310b are shown as optical discs, such as CDs (Compact Discs), DVDs (Digital Versatile Discs), or Blu-ray Discs. Computer program products 1310a, 1310b may also be implemented as memories (e.g., random access memories (RAMs), read-only memories (ROMs), erasable programmable read-only memories (EPROMs), or electrically erasable programmable read-only memories (EEPROMs)), and more specifically as non-volatile storage media in devices such as USB (Universal Serial Bus) memories or flash memories (e.g., Compact Flash). Thus, although computer programs 1320a, 1320b are schematically shown here as tracks on the depicted optical discs, computer programs 1320a, 1320b may be stored in any manner suitable for computer program products 1310a, 1310b.
[0128] The inventive concept has been described above mainly with reference to a few embodiments. However, as readily appreciated by a person skilled in the art, other embodiments than the ones disclosed above are equally possible within the scope of the inventive concept as defined by the appended patent claims.
Claims
1. A system (100) for identifying a fraudulent base station (20), the system (100) comprising an analyzer device (200) and at least two radio devices (300a:300N), the system (100) being configured to: When any one of the at least two radio devices (300a:300N) has received an identification request message for a long-term identifier of the any one of the at least two radio devices (300a:300N) from a base station (20), providing a report of the identification request message from the any one of the at least two radio devices (300a:300N) to the analyzer device (200); and The base station (20) is identified by the analyzer device (200) as being fraudulent when reports of the same base station (20) received from at least two different ones of the at least two radio devices (300a:300N) are received within a threshold duration relative to each other.
2. The system (100) according to claim 1, further configured to: A notification of the rogue base station (20) thus identified is issued by the analyzer device (200).
3. The system (100) according to claim 2, wherein The notification is an alarm message sent by the analyzer device (200) to a network management entity.
4. The system (100) according to claim 2 or 3, wherein: The notification is issued only when the analyzer device (200) has received reports from at least k radio devices (300a:300N) that are at most the threshold duration apart from each other, where k is an integer greater than 1.
5. The system (100) according to claim 2, further configured to: The certainty level is determined by the analyzer device (200) based on how many reports have been received that are at most the threshold duration apart from each other and how many at least two radio devices (300a:300N) are operatively connected to the analyzer device (200).
6. The system (100) according to claim 5, wherein The notification is issued only when the certainty level is above a certainty threshold.
7. The system (100) according to claim 5 or 6, wherein: The certainty level is also based on network statistics obtained by the analyzer device (200).
8. The system (100) according to claim 2, further configured to: The analyzer device (200) queries a database and verifies that the base station (20) is not a registered base station before issuing the notification.
9. The system (100) according to claim 1, wherein The at least two radio devices (300a: 300N) are positioned relative to each other to receive signals from the same base station.
10. The system (100) according to claim 1, wherein The report includes the cell ID of the base station (20) that has sent the identification request message.
11. The system (100) according to claim 1, wherein The long-term identifier is the International Mobile Subscriber Identity IMSI.
12. The system (100) according to claim 1, wherein The at least two radio devices (300a:300N) are collectively configured to be served by at least two different mobile network operators.
13. The system (100) of claim 1, wherein: The identity request message is received during an attach procedure, a TAU procedure, or a LAU procedure.
14. The system (100) according to claim 1, wherein The identification request message is received if the either radio device of the at least two radio devices (300a:300N) has not undergone network lock.
15. The system (100) of claim 1, wherein: The identification request message is received when the either radio device of the at least two radio devices (300a:300N) has performed an initial registration since a radio modem of the either radio device was last turned on.
16. The system (100) of claim 1, wherein: Each of the at least two radio devices (300a:300N) is operatively connected to the analyzer device (200) via a wired connection (40a) or a wireless connection (40b).
17. The system (100) of claim 1, wherein: The analyzer device (200) and the at least two radio devices (300a:300N) are integrated, collocated or provided within the same physical entity defining the system (100).
18. The system (100) according to claim 17, wherein The system (100) is configured to be installed in a fixed location.
19. The system (100) of claim 17, wherein: The system (100) is configured to be mobile.
20. An analyzer device (200) for identifying a fraudulent base station (20), the analyzer device (200) comprising a processing circuit configured to cause the analyzer device (200) to: When any one of the at least two radio devices (300a:300N) has received an identification request message for a long-term identifier of the any one of the at least two radio devices (300a:300N) from a base station (20), receiving a report of the identification request message from the any one of the at least two radio devices (300a:300N); and The base station (20) is identified as being fraudulent when reports of the same base station (20) received from at least two different ones of the at least two radios (300a:300N) are received within a threshold duration relative to each other.
21. An analyzer device (200) for identifying a fraudulent base station (20), the analyzer device (200) comprising: a receiving module (210a) configured to, when any one of the at least two radio devices (300a:300N) has received an identification request message for a long-term identifier of the any one of the at least two radio devices (300a:300N) from a base station (20), receive a report of the identification request message from the any one of the at least two radio devices (300a:300N); as well as An identification module (210b) is configured to identify the base station (20) as being fraudulent when reports of the same base station (20) received from at least two different radio devices of the at least two radio devices (300a:300N) are received within a threshold duration relative to each other.
22. A method for identifying a fraudulent base station (20), the method being performed by an analyzer device (200), the method comprising: When any one of the at least two radio devices (300a:300N) has received an identification request message for a long-term identifier of the any one of the at least two radio devices (300a:300N) from the base station (20), receiving (S102) a report of the identification request message from the any one of the at least two radio devices (300a:300N); as well as The base station (20) is identified (S104) as being fraudulent when reports of the same base station (20) received from at least two different ones of the at least two radios (300a:300N) are received within a threshold duration relative to each other.
23. A computer program product for identifying a fraudulent base station (20), the computer program product comprising computer code which, when executed on a processing circuit (210) of an analyzer device (200), causes the analyzer device (200) to perform the method of claim 22.
Citation Information
Patent Citations
System and method for faked base station detection
WO2016206610A1