Fake base station detection using time-map analysis and anomaly detection
Patent Information
- Application Number
- CN202480085379.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-12-08
- Filing Date
- 2024-01-31
- Publication Date
- 2026-08-14
AI Technical Summary
[0003]恶意行为者可能部署无线设备,这些设备伪装成作为合法的移动网络运营商网络(例如,公共陆地移动网络(“PLMN”))的一部分的基站,但实际上并非移动网络运营商网络的合法部分
Smart Images

Figure CN122580911A_ABST
Abstract
Description
Related applications
[0001] This application claims priority to U.S. nonprovisional patent application No. 18 / 534,373, filed December 8, 2023, entitled “FAKE BASE STATION DETECTIONUSING TEMPORAL GRAPH ANALYSIS AND ANOMALY DETECTION”, the entire contents of which are incorporated herein by reference. Background Technology
[0002] The term “New Radio” (NR) associated with fifth-generation mobile wireless communication systems (“5G”) refers to aspects of the technology used in the radio access network (“RAN”), encompassing several Quality of Service (QoS) categories, including Ultra-Reliable Low-Latency Communication (“URLLC”), Enhanced Mobile Broadband (“eMBB”), and Massive Machine-Type Communication (“mMTC”). The URLLC QoS category is associated with stringent latency requirements (e.g., low latency or low signal / message delay) and high reliability of radio performance, while conventional eMBB use cases can be associated with high-capacity wireless communication, which allows for less stringent latency requirements (e.g., higher latency than URLLC) and less reliable radio performance compared to URLLC. Performance requirements for mMTC can be lower than those for eMBB use cases. Some use cases involving mobile devices or mobile user equipment (such as smartphones, wireless tablets, smartwatches, etc.) can impose varying resource loads or demands on a given RAN.
[0003] Malicious actors may deploy wireless devices that masquerade as base stations within a legitimate mobile network operator's network (e.g., a Public Land Mobile Network (“PLMN”), but are not actually a legitimate part of the operator's network. These illicit devices may attempt to lure user devices into connecting to them in order to obtain personal information of the users attempting to connect, or information corresponding to the mobile network operator, such as security credentials. Illicit devices masquerading as legitimate base stations (e.g., masquerading as legitimate RAN nodes) can be referred to as fake base stations, spoofed base stations, or spoofed RAN nodes. Other terms that may refer to fake base stations include “IMSI capture device,” “cellular phone surveillance device,” “rogue base station,” or “cell site simulator.” Summary of the Invention
[0004] The following is a simplified summary of the disclosed subject matter to provide a basic understanding of some embodiments. This content is not a broad overview of the embodiments. It is neither intended to identify key or essential elements of the embodiments nor to define the scope of the embodiments. Its sole purpose is to present some concepts of this disclosure in a simplified form as a prelude to the more detailed description that follows.
[0005] In an example embodiment, a method may include: receiving, by a network computing device including a processor, at least one user equipment radio parameter measurement report generated by at least one user equipment, the at least one user equipment radio parameter measurement report including at least one reported value; and analyzing the at least one reported value by the network computing device to obtain at least one analyzed reported value. Based on the at least one analyzed reported value, the method may further include determining, by the network computing device, at least one connection transition value with respect to at least one radio access network node.
[0006] At least one analyzed reported value may correspond to at least one interval associated with at least one user equipment radio parameter measurement report. The interval may be an interval between times corresponding to the generation of the measurement report. The interval may be a configured time period within which time analysis can be performed on the time corresponding to the at least one user equipment radio parameter measurement report. At least one analyzed reported value may be at least one time-based value. At least one time-based value may be a timestamp.
[0007] In this embodiment, at least one radio access network node may be a first radio access network node. At least one connection transition value may be a first connection transition value, corresponding to at least one user equipment transitioning from a connected state with the first radio access network node to a connected state with a second radio access network node. At least one user equipment radio parameter measurement report may be a first user equipment radio parameter measurement report. At least one report value may be a first time corresponding to the at least one user equipment radio parameter measurement report. The first connection transition value may be determined at least based on the first time and a second time corresponding to the second user equipment radio parameter measurement report.
[0008] In an embodiment, the method may further include determining a second connection transition value by a network computing device based at least on a first connection transition value and a third time corresponding to a third user equipment radio parameter measurement report.
[0009] In an embodiment, at least one radio access network node may be a first radio access network node, and at least one connection transition value may correspond to at least one user equipment being idle and transitioning from a selection residing on the first radio access network node to a selection residing on the second radio access network node.
[0010] In an embodiment, at least one radio access network node may be a first radio access network node, and at least one connection transition value may correspond to at least one user equipment transitioning from being connected to the first radio access network node to being connected to the second radio access network node.
[0011] In an embodiment, at least one connection transition value may be a first connection transition value, which corresponds to a time associated with at least one user equipment radio parameter measurement report. The at least one user equipment radio parameter measurement report may also include at least one radio performance measurement value. The method may further include analyzing the at least one radio performance measurement value by a network computing device to obtain a second connection transition value associated with at least one radio access network node. Based on the first and second connection transition values, the method may further include determining a fake base station score by the network computing device, the fake base station score indicating the probability that at least one radio access network node is a fake base station.
[0012] The method may further include analyzing the fake base station score using a network computing device with respect to a fake base station likelihood score criterion to obtain an analyzed fake base station score. Based on the analyzed fake base station score being determined to meet the fake base station likelihood score criterion, the method may further include determining, by the network computing device, that at least one radio access network node is at least one fake base station, and the method may further include performing a connection establishment action by the network computing device. The connection establishment action may include adding at least one identifier corresponding to at least one fake base station to a base station block list.
[0013] In an embodiment, analyzing at least one radio performance measurement may include analyzing at least one radio performance measurement according to at least one of the following: an isolated forest machine learning model or a local outlier feature machine learning model.
[0014] In an embodiment, at least one radio performance measurement may be at least one of the following: received signal strength value or received signal-to-interference-plus-noise ratio value.
[0015] In an embodiment, at least one connection transition value may be, may correspond to, or may indicate a time map edge, which may indicate the connection activity of at least one user equipment with respect to at least one radio access network node.
[0016] In another example embodiment, a network computing device may include a processor configured to process executable instructions that, when executed by the processor, facilitate the execution of operations, including: receiving at least one user equipment radio parameter measurement report, the at least one user equipment radio parameter measurement report corresponding to at least one radio access network node and generated by at least one user equipment, the at least one user equipment radio parameter measurement report including at least one time value and at least one radio performance measurement value. The operations may further include analyzing the at least one time value to obtain at least one first outlier or score corresponding to the at least one radio access network node, and analyzing the at least one radio performance measurement value to obtain at least one second outlier or score corresponding to the at least one radio access network node. Based on the at least one first outlier and at least one second outlier, the operations may further include determining at least one combination of outlier scores, and analyzing the at least one combination of outlier scores with respect to an outlier score criterion to obtain an analyzed outlier score. Based on meeting the outlier score criterion, the operations may further include performing a connection establishment action. The connection establishment action may include adding at least one identifier associated with at least one radio access network node corresponding to an anomaly score of at least one combination to a prohibited base station list, notifying at least one user equipment that at least one radio access network node may be a fake base station, or notifying radio access network nodes other than at least one radio access network node that at least one radio access network node corresponding to an anomaly score of at least one analyzed combination that meets the anomaly score criteria may be a fake base station.
[0017] In embodiments, determining at least one combination of outlier scores may include applying an ensemble learning model to at least one first outlier and at least one second outlier. In embodiments, analyzing at least one radio performance measurement may include applying at least one of the following to at least one radio performance measurement: an isolated forest learning model or a local outlier factor learning model. In embodiments, analyzing at least one time value may include applying a time graph model to at least one time value, wherein at least one first outlier is at least one time graph edge. At least one time value may be a timestamp corresponding to at least one user equipment radio parameter measurement report. The time value may include a mean or standard deviation determined based on the timestamp corresponding to at least one user equipment radio parameter measurement report. In embodiments, the network computing device may be part of or a component of the wireless communication network core network.
[0018] In another example embodiment, a non-transitory machine-readable medium may include executable instructions that, when executed by a processor of a network computing device, facilitate the execution of operations including receiving at least one user equipment radio parameter measurement report, the at least one user equipment radio parameter measurement report corresponding to at least one radio access network node and generated by at least one user equipment. The at least one user equipment radio parameter measurement report may include at least one time value and at least one radio performance measurement value. The operations may further include analyzing the at least one time value to obtain at least one first outlier or score corresponding to the at least one radio access network node, and analyzing the at least one radio performance measurement value to obtain at least one second outlier or score corresponding to the at least one radio access network node. Based on the at least one first outlier and the at least one second outlier, the operations may further include determining at least one combined outlier score, the combined outlier score indicating the probability that the at least one radio access network node is a fake base station.
[0019] In an embodiment, analyzing at least one time value may include applying a time graph model to the at least one time value. At least one first outlier may correspond to at least one edge of a time graph generated by applying the time graph model to the at least one time value. At least one radio access network (RAN) node may be a first RAN node. At least one edge may correspond to a connection transition activity with respect to the first RAN node and at least a second RAN node. The connection transition activity may include selecting or reselecting at least one RAN node or a RAN node that is a geographical neighbor of at least one RAN node. The connection transition activity may include switching at least one user equipment (UE) to at least one RAN node that is a geographical neighbor of at least one RAN node. Attached Figure Description
[0020] Figure 1 The diagram illustrates the environment of a wireless communication system.
[0021] Figure 2A The illustration depicts an environment where an idle user equipment transmits a user equipment radio parameter measurement report to a fake base station.
[0022] Figure 2B The illustration depicts an environment where idle user equipment transmits user equipment radio parameter measurement reports to legitimate base stations when fake base stations are inactive.
[0023] Figure 2C The illustration shows an environment where connected user equipment transmits user equipment radio parameter measurement reports to a fake base station.
[0024] Figure 2DThe illustration depicts an environment in which connected user equipment transmits user equipment radio parameter measurement reports to both the fake and legitimate base stations during a handover from a fake base station to a legitimate base station.
[0025] Figure 3 The illustration shows sample user equipment radio parameter measurement report information.
[0026] Figure 4 The illustration shows an example learning model architecture used to determine the probability that a wireless access network node is a fake base station.
[0027] Figure 5 The illustration shows an example time graph, where nodes represent multiple legitimate radio access network nodes, which are connected to nodes representing fake base stations by graph edges representing connection transition values corresponding to connection transitions. Connection transitions are associated with user equipment with respect to nodes connected by edges.
[0028] Figure 6 The diagram illustrates a flowchart of an example method for determining whether a node is a fake base station.
[0029] Figure 7 The diagram illustrates the example method.
[0030] Figure 8 The diagram illustrates a block diagram of an example network computing device.
[0031] Figure 9 The diagram illustrates a block diagram of an example non-transitory machine-readable medium.
[0032] Figure 10 The illustration shows an example computer environment.
[0033] Figure 11 The diagram illustrates a block diagram of an example wireless user equipment. Detailed Implementation
[0034] As a preliminary matter, those skilled in the art will readily understand that this embodiment is readily applicable and widely applicable. In addition to those described herein, numerous methods, embodiments, and adaptations of this application, as well as numerous variations, modifications, and equivalent arrangements, will be apparent or reasonably suggested in light of the nature or scope of the various embodiments of this application.
[0035] Therefore, although this application has been described in detail herein with reference to various embodiments, it should be understood that this disclosure is an illustration of one or more concepts expressed by the various example embodiments and is made solely for the purpose of providing a sufficient and practicable disclosure. The following disclosure is not intended and should not be construed as limiting this application or otherwise excluding any such other embodiments, adaptations, variations, modifications, and equivalent arrangements, and the embodiments presented herein are limited only by the appended claims and their equivalents.
[0036] As used in this disclosure, in some embodiments, the terms "component," "system," etc., are intended to refer to or include computer-related entities or entities associated with operating means having one or more specific functions, wherein the entity may be hardware, a combination of hardware and software, software, or software in execution. As an example, a component may be, but is not limited to, a process running on a processor, a processor, an object, an executable file, a thread executing, computer-executable instructions, a program, and / or a computer. By way of illustration and not limitation, both an application running on a server and the server itself can be components.
[0037] One or more components may reside within a process and / or execution thread, and components may be located on a single computer and / or distributed across two or more computers. Furthermore, these components may be executed from various computer-readable media on which various data structures are stored. These components may communicate via local and / or remote processes, such as according to signals having one or more data packets (e.g., data from a component that interacts with a local system, another component in a distributed system, and / or other systems across a network such as the Internet). As another example, a component may be a device having specific functions provided by mechanical parts operated by electrical or electronic circuitry, which is operated by a software or firmware application executed by a processor, wherein the processor may be internal or external to the device and executes at least a portion of the software or firmware application. As yet another example, a component may be a device providing specific functions through electronic components without mechanical parts, which may include a processor to execute software or firmware that at least partially endows these electronic components with functionality. While various components have been illustrated as separate components, it should be understood that multiple components may be implemented as a single component, or a single component may be implemented as multiple components, without departing from the exemplary embodiments.
[0038] As used herein, the term "facilitation" is used in the context of a system, device, or component "facilitating" one or more actions or operations, relative to the nature of a complex computing environment in which multiple components and / or devices may be involved in some computational operations. Non-limiting examples of actions that may or may not involve multiple components and / or devices include: transmitting or receiving data, establishing connections between devices, determining intermediate results toward obtaining a result, etc. In this regard, a computing device or component may facilitate an operation by playing any role in completing the operation. Therefore, when the operation of a component is described herein, it should be understood that, where the operation is described as being facilitated by a component, these operations may optionally be completed in cooperation with one or more other computing devices or components (such as, but not limited to, sensors, antennas, audio and / or visual output devices, other devices, etc.).
[0039] Furthermore, various embodiments can be implemented as methods, apparatus, or articles of art, using standard programming and / or engineering techniques to produce software, firmware, hardware, or any combination thereof to control a computer to achieve the disclosed subject matter. The term "article of art" as used herein is intended to cover a computer program accessible from any computer-readable (or machine-readable) device or computer-readable (or machine-readable) storage / communication medium. For example, computer-readable storage media may include, but are not limited to, magnetic storage devices (e.g., hard disks, floppy disks, magnetic stripes), optical discs (e.g., compact discs (CDs), digital multifunction discs (DVDs)), smart cards, and flash memory devices (e.g., cards, sticks, key drives). Of course, those skilled in the art will recognize that many modifications can be made to this configuration without departing from the scope or spirit of the various embodiments.
[0040] Artificial intelligence (“AI”) and machine learning (“ML”) models can enhance and improve performance and operational capabilities in 5G implementations, such as network automation, optimized signaling overhead, energy efficiency, and maximized traffic capacity. The functionality of AI / ML models can be implemented and constructed in many different forms and with varying vendor-specific designs. A 5G radio access network node (“RAN”) to which a user equipment can attach or register can manage or control the real-time performance of AI / ML models at different user equipment locations for various radio functions. Network computing devices (which may be components of the 5G core network) can operate one or more AI / ML models that perform various functions, including determining the presence and operation of fake base stations.
[0041] Network RAN or core network computing equipment can dynamically control the activation, deactivation, triggering of model retraining (which may be radio function-specific), or updating of the learning model based on the monitoring and analysis of defined real-time performance metrics corresponding to the learning model executed at the user equipment. It should be understood that even if the learning model is implementing a specific radio function, the metric being monitored or analyzed can be a learning model metric, not necessarily a radio function metric (e.g., a mathematical / statistical metric, not necessarily a radio function metric such as, for example, signal strength).
[0042] Fake base station (“FBS”) deployments are considered a security risk to current cellular wireless communication systems. Typical FBS deployments can be implemented by illegitimate, low-capability (e.g., low processing power and low complexity) base stations within the signal coverage area of legitimate cellular network nodes, with the aim of collecting user equipment (UE) device information or installing malicious software on UE devices. For example, a vehicle-mounted mobile FBS can deceive idle-mode UE devices by presenting them as legitimate RAN nodes to be selected / reselected, because the UE may receive significantly better coverage (e.g., signal strength) from a very nearby FBS than from a more distant legitimate RAN node, thus misleading the idle-mode UE device to select / reselect the FBS instead of an available legitimate RAN node. Current FBS prevention measures involve manual intervention when an FBS is detected within a specific coverage area of a legitimate network, where the FBS (and its vehicle) are manually detected using a radio scanner. Conventional techniques do not support dynamic FBS access prevention (e.g., node avoidance based on real-time determination that a node is an active FBS). Using conventional techniques typically results in costly, slow, and unreliable FBS operational prevention.
[0043] Fake base stations can mimic legitimate cellular network operations, which can facilitate various types of attacks, such as identity theft, fraudulent text messages, fraudulent websites, eavesdropping, call interception, denial-of-service attacks, malware distribution, and theft of user bank account information via phishing messages. Due to the low cost and ease of deployment of Software-Defined Radio (“SDR”), incidents and security vulnerabilities caused by fake base stations have increased in recent years, including targeting troops on the battlefield. Conventional detection methods are typically operated through manual inspection using scanning tools and analysis of radio signals. Conventional detection techniques often fail to accurately identify fake base stations and frequently result in a large number of false alarms. Fake base stations can employ detection evasion techniques, such as intermittently shutting down their radio transceivers or moving to another location. The embodiments disclosed herein may use one or more AI / ML models that combine temporal graph analysis and anomaly detection models to enhance the accuracy of fake base station detection. The embodiments disclosed herein may use ensemble models to evaluate the outputs of temporal graph models, isolated forest models, and local outlier factor models. Temporal graph models can analyze the temporal characteristics corresponding to connection or handover events of one or more user equipment. Isolated forest (“IF”) or local outlier factor (“LOF”) models can analyze radio parameter measurements to determine anomalies. The temporal characteristics analyzed by the time-map model, as well as the radio parameter measurements analyzed by IF and LOF, can be obtained via radio measurement reports periodically submitted by user equipment and received by core network computing equipment. These radio measurement reports, typically generated periodically by user equipment and transmitted to one or more radio access network nodes, can be referred to as user equipment radio parameter measurement reports. Information contained in the user equipment radio parameter measurement reports can be analyzed by network computing equipment to determine the likelihood that a radio access network node is a fake base station masquerading as a legitimate radio access network node.
[0044] Using the embodiments disclosed herein, network computing devices can accurately determine whether a radio access network (RAN) node is a fake base station, even if the fake base station employs sophisticated detection evasion techniques. The embodiments disclosed herein can combine time analysis techniques and graph-based analysis techniques with the analysis of radio characteristic / radio performance parameter values corresponding to radio parameters (such as, for example, received signal strength indications (e.g., Reference Signal Received Power (“RSRP”) or Signal-to-Interference-plus-Noise Ratio (“SINR”)). This time information or radio performance parameter information can be included in user equipment (UE) radio parameter measurement reports transmitted by UEs located within a signal coverage area corresponding to one or more RAN nodes, which are indicated in the UE radio parameter measurement reports. Time graph analysis facilitates the analysis of connection and disconnection events or handover events concerning one or more UEs and one or more RAN nodes. Probabilistic detection models, such as the PageRank model, can help analyze the results of time graph analysis to obtain anomaly scores or outliers corresponding to one or more transitions from one RAN node to another during a configured sampling phase. Time graph models can help accurately analyze connection popularity within a given geographic coverage area of a wireless network. Connection popularity can refer to one or more RAN nodes, one or more user equipments being switched to / from these nodes, or one or more user equipments selecting or reselecting to / from these nodes while in idle or standby mode. The embodiments disclosed herein may include pre-trained learning models. The embodiments disclosed herein can facilitate the identification of one or more legitimate RAN nodes / base stations affected by one or more fake base stations that can operate within the radio signal coverage area of legitimate RAN nodes by using information obtained from implementations of these embodiments.
[0045] In wireless network systems (including 5G), periodic user equipment radio parameter measurement reports are generated and transmitted by the user equipment. Therefore, the embodiments disclosed herein do not impose significant (if any) processing or battery load on the user equipment. Typically, user equipment radio parameter measurement reports are transmitted when the user equipment is in an idle mode / state, a standby mode / state, or a connected mode / state. Idle mode measurements are typically used to facilitate cell / RAN node selection or reselection and are generally based on measurements performed by the user equipment regarding System Information Block (“SIB”) message signals. Connected mode measurements are typically used to facilitate handover from one RAN node to another, and the measurements are generally determined based on RRC message signals for a specific UE.
[0046] Typical fake base stations can be facilitated by consumer-grade SDRs, which can lead to poor SINR and RSRP measurements by user equipment (UEs) due to various factors. Factors that can cause poor SINR or RSRP measurements by UEs can include lower-quality equipment compared to legitimate base stations, resulting in weaker signal transmission and higher noise levels. Another factor that can cause poor SINR or RSRP measurements by UEs can include interference with nearby legitimate RAN nodes due to the fake base station being unauthorized and therefore not coordinated with legitimate base stations. This interference can lead to poor SINR measurements determined by UEs that have selected or are connected to the fake base station.
[0047] Fake base stations are typically placed within target user equipment and can be concealed to avoid detection. They employ various detection evasion techniques to avoid manual detection, often utilizing sophisticated radio scanners. These techniques often attempt to blend the fake base station with legitimate base stations, increasing the difficulty of detection by sophisticated radio scanners used in manual detection methods. Common detection evasion techniques involve randomly turning the fake base station on and off. Another technique involves moving a fake base station installed on, embedded in, or inside a vehicle to different locations, thus increasing the difficulty of tracking and locating it. Yet another technique involves altering the cell identifier corresponding to the fake base station to make it appear as a new base station to the user equipment.
[0048] Detection evasion techniques can confuse network monitoring systems and hinder detection. Conventional AI / ML model-based fake base station detection techniques often ignore or fail to detect fake base stations that employ detection evasion techniques. Furthermore, conventional fake base station detection techniques may cause false negatives (meaning the detection technique fails to identify a fake base station) or false positives (meaning the detection technique incorrectly identifies a legitimate base station as a fake base station).
[0049] The embodiments disclosed herein can utilize at least two layers of machine learning models to facilitate the detection of fake base stations, detecting radio characteristic anomalies and connectivity behavior anomalies based on analysis of information contained in or corresponding to user equipment radio parameter measurement reports. The embodiments disclosed herein can use isolated forest anomaly detection learning models or local outlier anomaly detection learning models to analyze radio signal characteristics or measured radio parameter values, such as RSRP and SINR, to identify RAN nodes that may be fake base stations. Probabilistic detection models, such as PageRank learning models, can help determine the connectivity behavior exhibited by user equipment over time using different base stations. Each model layer can provide anomaly scores. Normalized composite or combined fake base station probabilities can be calculated using the anomaly scores corresponding to radio access network nodes. The embodiments disclosed herein can help identify fake base stations with higher accuracy than conventional techniques and significantly reduce false positives.
[0050] Reference Figure 6 In a more detailed example embodiment, the method may analyze feature information contained in a user equipment radio parameter measurement report to determine the likelihood that a base station corresponding to one or more user equipment measurement reports is a fake base station. For example, one or more RSRP values or one or more SINR values contained in one or more user equipment radio parameter measurement reports may be analyzed to identify one or more anomalies corresponding to one or more radio access network nodes. These radio parameter values may be referred to as features in relation to the learning model analysis and may indicate the operation and performance of the RAN node. This example method may apply time analysis to information contained in one or more user equipment radio parameter measurement reports to determine the mean and standard deviation corresponding to time intervals between UE measurement reports regarding the base station where the user equipment is camped (e.g., the UE is in idle or standby mode) or the base station to which the user equipment is connected (e.g., the user equipment is in connected mode). Time analysis may help examine time patterns or identify any specific time anomalies that may indicate the presence of a fake base station within the radio access network or may correspond to fake base station detection evasion techniques.
[0051] Integrated anomaly detection models can receive outputs from probabilistic detection models (such as PageRank models) as well as from IF models or LOF models. IF models isolate anomalies by randomly selecting features and then randomly selecting the split between the maximum and minimum values of those features, which is particularly useful for anomaly detection in high-dimensional datasets. LOF models measure local density deviations in a given sample, thus helping to identify regions of similar density. IF models can help detect anomalies in radio signal parameters / metrics (such as RSRP and SINR). IF models can help isolate rare and anomalous data points within a dataset to identify anomalous signal strength or interference levels that may indicate network anomalies or security vulnerabilities. Similarly, LOF can facilitate anomaly detection by evaluating local density deviations of data points within a dataset. LOF models are useful for detecting anomalies in complex, high-dimensional datasets, thus helping to identify anomalous patterns or outliers regarding wireless communication parameters / metrics. LOF can help pinpoint areas where signal strength or interference levels significantly deviate from normal or baseline signal strength or interference levels.
[0052] A time-graph learning model can generate a time-graph where nodes represent radio access network (RAN) nodes, and edges between nodes correspond to connection activities with respect to the RAN nodes represented by the graph nodes. For each node in the graph, a probabilistic detection model (such as the PageRank model) can be applied to the corresponding edge to obtain outliers associated with at least one RAN node at one end of the edge and another node at the other end of the edge. Outliers obtained by applying the PageRank model or a similar model can be referred to as connection transition values and can correspond to connection transition activities of one or more user equipments (which transmit one or more RAN radio parameter measurement reports), such as selecting a node to camp on or being switched from one node at one end of the edge to another node at the other end of the edge. Connection transition values can be referred to as probability scores, which can correspond to an unusually high number of connection transitions from one RAN node to another RAN node by the UE, and therefore to the probability that one of the RAN nodes connected by the edge is a fake base station. Connection transition values in Figure 5 In Figure 500, the percentage values corresponding to the edges are indicated. PageRank scores are used to help predict network connectivity transitions or handover behavior of user equipment and corresponding base stations. For each RAN node and its corresponding anomaly score, a combined anomaly score can be calculated based on the anomaly score generated by the IF or LOF model, or the connection probability / score generated by the PageRank model. The combined anomaly score can be normalized to a range between 0 and 1 and can be assigned a pseudo-base station probability corresponding to a given RAN node.
[0053] Now turn to the attached image. Figure 1 An example of a wireless communication system 100 supporting blind decoding of PDCCH candidate or search space according to various aspects of this disclosure is illustrated. The wireless communication system 100 may include one or more base stations 105, one or more UEs 115, and a core network 130. In some examples, the wireless communication system 100 may be a Long Term Evolution (LTE) network, an LTE-Advanced (LTE-A) network, an LTE-A Pro network, or a New Radio (NR) network. In some examples, the wireless communication system 100 may support enhanced broadband communication, ultra-reliable (e.g., mission-critical) communication, low-latency communication, communication with low-cost, low-complexity devices, or any combination thereof. As shown, examples of UE 115 may include smartphones, cars or other vehicles, or drones or other aircraft. Another example of a UE may be a virtual reality device 117, such as smart glasses, a virtual reality headset, an augmented reality headset, and other similar devices that can provide the wearer with images, video, audio, touch, taste, or smell. The UE (such as VR device 117) can transmit or receive wireless signals to and from the RAN base station 105 via a long-range wireless link 125, or the UE / VR device can receive or transmit wireless signals via a short-range wireless link 137. The short-range wireless link 137 may include a wireless link with the UE device 115, such as a Bluetooth link, a Wi-Fi link, etc. The UE (such as device 117) can communicate simultaneously via multiple wireless links, such as communicating with the base station 105 via link 125 and communicating via short-range wireless links. The VR device 117 can also communicate with the wireless UE via a cable or other wired connection. The RAN or its components may be referenced. Figure 10 The description refers to the implementation of one or more computer components.
[0054] Continue the discussion Figure 1 Base stations 105 can be distributed throughout a geographical area to form a wireless communication system 100, and can be devices of different forms or with different capabilities. Base stations 105 and UE 115 can communicate wirelessly via one or more communication links 125. Base station 105 can be referred to as a RAN node. Each base station 105 can provide a coverage area 110, on which UE 115 and base station 105 can establish one or more communication links 125. Coverage area 110 can be an example of a geographical area where base station 105 and UE 115 can communicate signals according to one or more radio access technologies.
[0055] UE 115 can be distributed throughout the entire coverage area 110 of the wireless communication system 100, and each UE 115 can be stationary, mobile, or both at different times. UE 115 can be devices in different forms or with different capabilities. Figure 1 The diagram illustrates some example UE 115s. The UE 115 described herein can communicate with various types of devices, such as other UE 115s, base station 105, or network devices (e.g., core network nodes, relay devices, integrated access and backhaul (IAB) nodes, or other network devices). Figure 1 As shown.
[0056] Base station 105 may communicate with core network 130, communicate with each other, or both. For example, base station 105 may interface with core network 130 via one or more backhaul links 120 (e.g., via S1, N2, N3, or other interfaces). Base station 105 may communicate with each other directly (e.g., directly between base stations 105) or indirectly (e.g., via core network 130) or both via backhaul links 120 (e.g., via X2, Xn, or other interfaces). In some examples, backhaul link 120 may include one or more radio links.
[0057] One or more of the base stations described herein as base station 105 may include, or may be referred to by those skilled in the art as, base station, radio base station, access point, radio transceiver, NodeB, eNodeB (eNB), next-generation NodeB or gigabit NodeB (any of which may be referred to as bNodeB or gNB), home NodeB, home eNodeB or other suitable terms.
[0058] UE 115 may include or be referred to as a mobile device, wireless device, remote device, handheld device, or subscriber device, wireless transceiver unit (“WTRU”), or some other suitable term, wherein “device” may also be referred to as a unit, station, terminal, or client, etc. UE 115 may also include or be referred to as a personal electronic device, such as a cellular phone, personal digital assistant (PDA), tablet computer, laptop computer, personal computer, or router. In some examples, UE 115 may include or be referred to as a wireless local loop (WLL) station, Internet of Things (IoT) device, Internet of Everything (IoE) device, or machine-type communication (MTC) device, etc., which can be implemented in various objects, such as appliances, vehicles, or smart meters, etc.
[0059] like Figure 1As shown, UE 115 can communicate with various types of devices, such as other UE 115s that can sometimes act as relays, base station 105, and network devices including macro eNBs or gNBs, small cell eNBs or gNBs, or relay base stations.
[0060] UE 115 and base station 105 can wirelessly communicate with each other via one or more communication links 125 on one or more carriers. The term "carrier" can refer to a set of radio frequency spectrum resources having a defined physical layer structure for supporting communication link 125. For example, a carrier for communication link 125 may include a portion of the radio frequency spectrum band (e.g., a bandwidth portion (BWP)) operating according to one or more physical layer channels for a given radio access technology (e.g., LTE, LTE-A, LTE-A Pro, NR). Each physical layer channel may carry acquisition signaling (e.g., synchronization signals, system information), control signaling coordinating operation for the carrier, user data, or other signaling. Wireless communication system 100 can support communication with UE 115 using carrier aggregation or multi-carrier operation. Depending on the carrier aggregation configuration, UE 115 can be configured with multiple downlink component carriers and one or more uplink component carriers. Carrier aggregation can be used in conjunction with both frequency division duplex (FDD) and time division duplex (TDD) component carriers.
[0061] In some examples (e.g., in a carrier aggregation configuration), a carrier may also have acquisition or control signaling that coordinates operation against other carriers. A carrier may be associated with a frequency channel (e.g., an Evolved Universal Mobile Telecommunications System Terrestrial Radio Access (E-UTRA) Absolute Radio Frequency Channel Number (EARFCN)) and may be located according to a channel grid for discovery by UE 115. A carrier may operate in standalone mode, where initial acquisition and connection can be performed by UE 115 via that carrier, or in non-standalone mode, where connections are anchored using different carriers (e.g., carriers of the same or different radio access technologies).
[0062] The communication link 125 shown in the wireless communication system 100 may include uplink transmission from UE 115 to base station 105, or downlink transmission from base station 105 to UE 115. The carrier may carry downlink or uplink communication (e.g., in FDD mode), or may be configured to carry both downlink and uplink communication (e.g., in TDD mode).
[0063] A carrier can be associated with a specific bandwidth of the radio frequency spectrum, and in some examples, the carrier bandwidth can be referred to as the carrier or the “system bandwidth” of the wireless communication system 100. For example, the carrier bandwidth can be a specific bandwidth (e.g., 1.4, 3, 5, 10, 15, 20, 40, or 80 MHz) of a carrier for a specific radio access technology. Devices of the wireless communication system 100 (e.g., base station 105, UE 115, or both) can have a hardware configuration that supports communication over a specific carrier bandwidth, or can be configured to support communication over a single carrier bandwidth within a set of carrier bandwidths. In some examples, the wireless communication system 100 may include a base station 105 or UE 115 that supports simultaneous communication via carriers associated with multiple carrier bandwidths. In some examples, each served UE 115 may be configured to operate over a portion (e.g., a subband, BWP) or the entire carrier bandwidth.
[0064] The signal waveform transmitted on a carrier can consist of multiple subcarriers (e.g., using multi-carrier modulation (MCM) techniques, such as orthogonal frequency division multiplexing (OFDM) or discrete Fourier transform extended OFDM (DFT-S-OFDM)). In a system employing MCM, a resource element can consist of a symbol phase (e.g., the duration of a modulation symbol) and a subcarrier, where the symbol phase and subcarrier spacing are inversely related. The number of bits carried by each resource element can depend on the modulation scheme (e.g., the order of the modulation scheme, the coding rate of the modulation scheme, or both). Therefore, the more resource elements the UE 115 receives and the higher the order of the modulation scheme, the higher the data rate that can be used for the UE. Wireless communication resources can refer to a combination of radio frequency spectrum resources, temporal resources (e.g., search space), or spatial resources (e.g., spatial layers or beams), and the use of multiple spatial layers can further increase the data rate or data integrity of communication with the UE 115.
[0065] One or more parameter sets for a carrier can be supported, where the parameter sets may include subcarrier spacing (Δf) and cyclic prefix. A carrier can be divided into one or more BWPs with the same or different parameter sets. In some examples, UE 115 can be configured with multiple BWPs. In some examples, a single BWP for a carrier can be active at a given time, and communication for UE 115 can be restricted to one or more active BWPs.
[0066] The time interval of base station 105 or UE 115 can be expressed as a multiple of a basic time unit, which can be, for example, a... The sampling phase is in seconds, where Δf max This can represent the maximum supported subcarrier spacing, and Nf This can represent the maximum supported Discrete Fourier Transform (DFT) size. The time interval of a communication resource can be organized according to radio frames, each with a specified duration (e.g., 10 milliseconds (ms)). Each radio frame can be identified by a System Frame Number (SFN) (e.g., ranging from 0 to 1023).
[0067] Each frame may include multiple consecutively numbered subframes or time slots, and each subframe or time slot may have the same duration. In some examples, a frame may be divided (e.g., in the time domain) into subframes, and each subframe may be further divided into multiple time slots. Alternatively, each frame may include a variable number of time slots, and the number of time slots may depend on the subcarrier spacing. Each time slot may include multiple symbol phases (e.g., depending on the length of the cyclic prefix preceding each symbol number). In some wireless communication systems 100, time slots may be further divided into multiple micro-time slots containing one or more symbols. In addition to the cyclic prefix, each symbol phase may contain one or more (e.g., N) f The sampling phase. The duration of the symbol phase can depend on the subcarrier spacing or the operating frequency band.
[0068] A subframe, time slot, micro-time slot, or symbol can be the smallest scheduling unit of the wireless communication system 100 (e.g., in the time domain) and can be referred to as a transmission time interval (TTI). In some examples, the duration of the TTI (e.g., the number of symbol phases in the TTI) can be variable. Additionally or alternatively, the smallest scheduling unit of the wireless communication system 100 can be dynamically selected (e.g., in a burst of shortened TTIs (sTTIs)).
[0069] Physical channels can be multiplexed on a carrier using various techniques. For example, physical control channels and physical data channels can be multiplexed on a downlink carrier using one or more of time-division multiplexing (TDM), frequency-division multiplexing (FDM), or hybrid TDM-FDM techniques. A control region (e.g., a control resource set (CORESET)) for physical control channels can be defined by multiple symbol phases and can extend across the system bandwidth or a subset of the system bandwidth of a carrier. One or more control regions (e.g., CORESETs) can be configured for a set of UEs 115. For example, one or more UEs in UE 115 can monitor or search control regions or spaces for control information based on one or more search space sets, and each search space set can include one or more control channel candidates in one or more aggregation levels arranged in a cascaded manner. The aggregation level for control channel candidates can refer to the number of control channel resources (e.g., control channel elements (CCEs)) associated with coded information for a control information format having a given payload size. The search space set may include a common search space set configured to send control information to multiple UEs 115 and a UE-specific search space set used to send control information to a specific UE 115. This document discloses additional search spaces and configurations for monitoring and decoding them, which are novel and non-traditional.
[0070] Base station 105 may provide communication coverage via one or more cells (e.g., macro cells, small cells, hotspots, or other types of cells, or any combination thereof). The term "cell" may refer to a logical communication entity used to communicate with base station 105 (e.g., via a carrier) and may be associated with an identifier used to distinguish neighboring cells (e.g., Physical Cell Identifier (PCID), Virtual Cell Identifier (VCID), or other identifier). In some examples, a cell may also refer to a geographic coverage area 110 or a portion of geographic coverage area 110 (e.g., a sector) on which a logical communication entity operates. The extent of such a cell can range from a small area (e.g., a structure, a subset of structures) to a large area, depending on various factors such as the capabilities of base station 105. For example, a cell may be or include buildings, subsets of buildings, or external space between or overlapping geographic coverage areas 110.
[0071] Macro cells typically cover a relatively large geographical area (e.g., a radius of several kilometers) and can allow unrestricted access by UE 115 with a service subscription to a network provider supporting the macro cell. In contrast, small cells can be associated with a lower-power base station 105 and can operate in the same or different (e.g., licensed, unlicensed) frequency bands as macro cells. Small cells can provide unrestricted access to UE 115 with a service subscription to a network provider, or restricted access to UE 115 associated with a small cell (e.g., UE 115 in a Closed Subscriber Group (CSG), or UE 115 associated with a user in a home or office). Base station 105 can support one or more cells and can also use one or more component carriers to support communication on one or more cells.
[0072] In some examples, a carrier can support multiple cells, and different cells can be configured according to different protocol types (e.g., MTC, Narrowband IoT (NB-IoT), Enhanced Mobile Broadband (eMBB)), which can provide access for different types of devices.
[0073] In some examples, base station 105 may be mobile and thus provide communication coverage for mobile geographic coverage areas 110. In some examples, different geographic coverage areas 110 associated with different technologies may overlap, but the different geographic coverage areas 110 may be supported by the same base station 105. In other examples, overlapping geographic coverage areas 110 associated with different technologies may be supported by different base stations 105. Wireless communication system 100 may include, for example, a heterogeneous network, in which different types of base stations 105 use the same or different radio access technologies to provide coverage for various geographic coverage areas 110.
[0074] The wireless communication system 100 can support synchronous or asynchronous operation. For synchronous operation, base stations 105 can have similar frame timing, and transmissions from different base stations 105 can be approximately time-aligned. For asynchronous operation, base stations 105 can have different frame timing, and in some examples, transmissions from different base stations 105 can be time-disaligned. The techniques described herein can be used for both synchronous and asynchronous operation.
[0075] Some UE 115 devices (such as MTC or IoT devices) can be low-cost or low-complexity devices and can provide automated communication between machines (e.g., via machine-to-machine (M2M) communication). M2M communication or MTC can refer to data communication technologies that allow devices to communicate with each other or with base station 105 without human intervention. In some examples, M2M communication or MTC can include communication from devices that integrate sensors or meters to measure or capture information and relay such information to a central server or application, which utilizes the information or presents it to humans interacting with the application. Some UE 115 devices can be designed to collect information or enable automated behavior of machines or other devices. Examples of applications for MTC devices include smart metering, inventory monitoring, water level monitoring, equipment monitoring, healthcare monitoring, wildlife monitoring, weather and geological event monitoring, fleet management and tracking, remote security sensing, physical access control, and transaction-based billing.
[0076] Some UE 115s can be configured to operate in a power-saving mode, such as half-duplex communication (e.g., supporting unidirectional communication via transmission or reception, but not simultaneous transmission and reception). In some examples, half-duplex communication can be performed at a reduced peak rate. Other power-saving techniques for UE 115s include entering a power-saving deep sleep mode when not engaged in active communication, operating on limited bandwidth (e.g., according to narrowband communication), or a combination of these techniques. For example, some UE 115s can be configured to operate using a narrowband protocol type associated with a defined portion or range (e.g., a set of subcarriers or resource blocks (RBs)) within the carrier, within the carrier's guard band, or outside the carrier.
[0077] Wireless communication system 100 can be configured to support ultra-reliable communication or low-latency communication, or various combinations thereof. For example, wireless communication system 100 can be configured to support ultra-reliable low-latency communication (URLLC) or mission-critical communication. UE 115 can be designed to support ultra-reliable, low-latency, or mission-critical functions (e.g., mission-critical functions). Ultra-reliable communication may include dedicated or group communication and may be supported by one or more mission-critical services, such as mission-critical push-to-talk (MCPTT), mission-critical video (MCVideo), or mission-critical data (MCData). Support for mission-critical functions may include service prioritization, and mission-critical services may be used for public safety or general commercial applications. The terms ultra-reliable, low-latency, mission-critical, and ultra-reliable low-latency are used interchangeably herein.
[0078] In some examples, UE 115 may also be able to communicate directly with other UE 115 via device-to-device (D2D) communication link 135 (e.g., using peer-to-peer (P2P) or D2D protocols). Communication link 135 may include a sidelink communication link. One or more UE 115s utilizing D2D communication may be within the geographic coverage area 110 of base station 105. Other UE 115s in such a group may be outside the geographic coverage area 110 of base station 105, or otherwise unable to receive transmissions from base station 105. In some examples, a group of UE 115s communicating via D2D communication may utilize a one-to-many (1:M) system, where a UE transmits to each other UE in the group. In some examples, base station 105 facilitates the scheduling of resources for D2D communication. In other cases, D2D communication is performed between UE 115s without involving base station 105.
[0079] In some systems, the D2D communication link 135 may be an example of a communication channel (such as a sidelink communication channel) between vehicles (e.g., UE 115). In some examples, vehicles may communicate using vehicle-to-everything (V2X) communication, vehicle-to-vehicle (V2V) communication, or some combination thereof. Vehicles may use signals to transmit information related to traffic conditions, signal control, weather, safety, emergencies, or any other information related to the V2X system. In some examples, vehicles in a V2X system may communicate with roadside infrastructure (such as roadside units), or communicate with the network via one or more RAN network nodes (e.g., base station 105) using vehicle-to-network (V2N) communication, or communicate with both.
[0080] Core network 130 can provide user authentication, access authorization, tracking, Internet Protocol (IP) connectivity, and other access, routing, or mobility functions. Core network 130 can be an evolved packet core (EPC) or a 5G core (5GC), and can include at least one control plane entity (e.g., a mobility management entity (MME), access and mobility management function (AMF)) managing access and mobility, and at least one user plane entity (e.g., a serving gateway (S-GW), packet data network (PDN) gateway (P-GW), or user plane function (UPF)) routing packets or interconnects to external networks. The control plane entity can manage non-access stratum (NAS) functions, such as mobility, authentication, and bearer management for UE 115 served by base station 105 associated with core network 130. User IP packets can be transmitted through the user plane entity, which can provide IP address allocation and other functions. The user plane entity can connect to IP service 150 for one or more network operators. IP service 150 may include access to the Internet, intranet(s), IP Multimedia Subsystem (IMS), or packet-switched streaming services.
[0081] Some network devices (such as base station 105) may include sub-components, such as access network entity 140, which may be an example of an access node controller (ANC). Each access network entity 140 may communicate with UE 115 through one or more other access network transport entities 145, which may be referred to as a radio headend, smart radio headend, or transmit / receive point (TRP). Each access network transport entity 145 may include one or more antenna panels. In some configurations, the various functions of each access network entity 140 or base station 105 may be distributed across various network devices (e.g., radio headends and ANCs) or combined into a single network device (e.g., base station 105).
[0082] Wireless communication system 100 can operate using one or more frequency bands, typically in the range of 300 MHz to 300 GHz. The region from 300 MHz to 3 GHz is generally referred to as the Ultra High Frequency (UHF) region or decimeter band because the wavelength range is from approximately one decimeter to one meter. UHF waves can be blocked or redirected by buildings and environmental features, but these waves can penetrate structures sufficiently for macrocells to provide service to UE 115 located indoors. Compared to transmissions using smaller frequencies and longer waves in the High Frequency (HF) or Very High Frequency (VHF) portions of the spectrum below 300 MHz, UHF wave transmission can be associated with smaller antennas and shorter ranges (e.g., less than 100 km).
[0083] The wireless communication system 100 can also operate in the ultra-high frequency (SHF) region (also known as the centimeter band) using a frequency band from 3 GHz to 30 GHz, or in the extremely high frequency (EHF) region of the spectrum (e.g., from 30 GHz to 300 GHz, also known as the millimeter band). In some examples, the wireless communication system 100 can support millimeter-wave (mmW) communication between the UE 115 and the base station 105, and the EHF antennas of the individual devices can be smaller and more closely spaced than UHF antennas. In some examples, this can facilitate the use of antenna arrays within the devices. However, the propagation of EHF transmissions can be subject to even greater atmospheric attenuation and a shorter range than SHF or UHF transmissions. The techniques disclosed herein can be adopted across transmissions using one or more different frequency regions, and the specified frequency band use across these frequency regions can vary by country or regulatory body.
[0084] Wireless communication system 100 can utilize both licensed and unlicensed radio frequency spectrum bands. For example, wireless communication system 100 can employ Licensed Assisted Access (LAA), LTE-Unlicensed (LTE-U) radio access technology, or NR technology in unlicensed bands such as the 5 GHz Industrial, Scientific, and Medical (ISM) band. When operating in unlicensed radio frequency spectrum bands, devices such as base station 105 and UE 115 can employ carrier sensing for collision detection and avoidance. In some examples, operation in unlicensed bands can be based on carrier aggregation configurations that combine component carriers operating in licensed bands (e.g., LAA). Operation in unlicensed spectrum can include downlink transmissions, uplink transmissions, P2P transmissions, or D2D transmissions, etc.
[0085] Base station 105 or UE 115 may be equipped with multiple antennas, which can be used to employ techniques such as transmit diversity, receive diversity, multiple-input multiple-output (MIMO) communication, or beamforming. The antennas of base station 105 or UE 115 may be located within one or more antenna arrays or antenna panels that can support MIMO operation or transmit or receive beamforming. For example, one or more base station antennas or antenna arrays may be located together at an antenna assembly (such as an antenna tower). In some examples, the antennas or antenna arrays associated with base station 105 may be located in different geographical locations. Base station 105 may have an antenna array with multiple rows and columns of antenna ports, which base station 105 can use to support beamforming for communication with UE 115. Similarly, UE 115 may have one or more antenna arrays that can support various MIMO or beamforming operations. Additionally or alternatively, the antenna panel may support radio frequency beamforming for signals transmitted via the antenna ports.
[0086] Base station 105 or UE 115 can use MIMO communication to utilize multipath signal propagation and improve spectral efficiency by transmitting or receiving multiple signals via different spatial layers. This technique can be referred to as spatial multiplexing. For example, multiple signals can be transmitted by a transmitting device via different antennas or different combinations of antennas. Similarly, multiple signals can be received by a receiving device via different antennas or different combinations of antennas. Each of the multiple signals can be referred to as a separate spatial stream and can carry bits associated with the same data stream (e.g., the same codeword) or different data streams (e.g., different codewords). Different spatial layers can be associated with different antenna ports used for channel measurement and reporting. MIMO techniques include single-user MIMO (SU-MIMO) (where multiple spatial layers are transmitted to the same receiving device) and multi-user MIMO (MU-MIMO) (where multiple spatial layers are transmitted to multiple devices).
[0087] Beamforming (also known as spatial filtering, directional transmission, or directional reception) is a signal processing technique that can be used at a transmitting or receiving device (e.g., base station 105, UE 115) to shape or manipulate an antenna beam (e.g., a transmit beam, a receive beam) along a spatial path between the transmitting and receiving devices. Beamforming can be achieved by combining signals transmitted via antenna elements of an antenna array such that some signals propagating with respect to a particular orientation of the antenna array experience constructive interference, while other signals experience destructive interference. Adjustments to the signals transmitted via the antenna elements can include the transmitting or receiving device applying amplitude offset, phase offset, or both to the signals carried via the antenna elements associated with the device. The adjustments associated with each antenna element can be defined by a beamforming weight set associated with a particular orientation (e.g., relative to the antenna array of the transmitting or receiving device, or relative to some other orientation).
[0088] Base station 105 or UE 115 may use beam scanning technology as part of beamforming operations. For example, base station 105 may use multiple antennas or antenna arrays (e.g., antenna panels) to perform beamforming operations for directional communication with UE 115. Some signals (e.g., synchronization signals, reference signals, beam selection signals, or other control signals) may be transmitted multiple times by base station 105 in different directions. For example, base station 105 may transmit signals according to different beamforming weight sets associated with different transmission directions. Transmissions in different beam directions may be used (by the transmitting device (such as base station 105) or the receiving device (such as UE 115)) to identify the beam direction for later transmission or reception by base station 105.
[0089] Some signals (such as data signals associated with a specific receiving device) may be transmitted by base station 105 in a single beam direction (e.g., the direction associated with the receiving device, such as UE 115). In some examples, the beam direction associated with transmission along a single beam direction may be determined based on the signals transmitted in one or more beam directions. For example, UE 115 may receive one or more signals transmitted by base station 105 in different directions and may report to the base station an indication of the signal received by UE 115 with the highest signal quality or otherwise acceptable signal quality.
[0090] In some examples, transmissions by a device (e.g., by base station 105 or UE 115) may be performed using multiple beam directions, and the device may use a combination of digital precoding or radio frequency beamforming to generate a combined beam for transmission (e.g., from base station 105 to UE 115). UE 115 may report feedback indicating precoding weights for one or more beam directions, and this feedback may correspond to the number of beam configurations across the system bandwidth or one or more subbands. Base station 105 may transmit reference signals (e.g., cell-specific reference signals (CRS), channel state information reference signals (CSI-RS)), which may or may not be precoded. UE 115 may provide feedback for beam selection, which may be a precoding matrix indicator (PMI) or codebook-based feedback (e.g., multi-panel type codebook, linear combination type codebook, port selection type codebook). Although these techniques are described with reference to signals transmitted by base station 105 in one or more directions, UE 115 may employ similar techniques to transmit signals multiple times in different directions (e.g., to identify the beam direction for subsequent transmission or reception by UE 115) or to transmit signals in a single direction (e.g., to transmit data to a receiving device).
[0091] A receiving device (e.g., UE 115) may attempt multiple receiving configurations (e.g., directional listening) when receiving various signals (such as synchronization signals, reference signals, beam selection signals, or other control signals) from base station 105. For example, the receiving device may attempt multiple receiving directions by: receiving via different antenna subarrays, processing the received signal according to different antenna subarrays, receiving according to different sets of receiving beamforming weights applied to signals received at multiple antenna elements of the antenna array (e.g., different sets of directional listening weights), or processing the received signal according to different sets of receiving beamforming weights applied to signals received at multiple antenna elements of the antenna array, any of which can be referred to as "listening" according to different receiving configurations or receiving directions. In some examples, the receiving device may use a single receiving configuration to receive along a single beam direction (e.g., when receiving data signals). This single receiving configuration may be aligned on beam directions determined based on listening according to different receiving configuration directions (e.g., beam directions determined to have the highest signal strength, highest signal-to-noise ratio (SNR), or otherwise acceptable signal quality based on listening according to multiple beam directions).
[0092] Wireless communication system 100 can be a packet-based network operating according to a layered protocol stack. In the user plane, communication at the bearer or Packet Data Convergence Protocol (PDCP) layer can be IP-based. The Radio Link Control (RLC) layer can perform packet segmentation and reassembly for communication over logical channels. The Medium Access Control (MAC) layer can perform priority processing and multiplexing from logical channels to transport channels. The MAC layer can also use error detection techniques, error correction techniques, or both to support retransmissions at the MAC layer to improve link efficiency. In the control plane, the Radio Resource Control (RRC) protocol layer can provide the establishment, configuration, and maintenance of RRC connections between UE 115 and base station 105 or core network 130 that support radio bearers for user plane data. At the physical layer, transport channels can be mapped to physical channels.
[0093] UE 115 and base station 105 can support data retransmission to increase the likelihood of successful data reception. Hybrid Automatic Repeat Request (HARQ) feedback is a technique used to increase the likelihood of data being correctly received on communication link 125. HARQ can include a combination of error detection (e.g., using Cyclic Redundancy Check (CRC)), forward error correction (FEC), and retransmission (e.g., Automatic Repeat Request (ARQ)). HARQ can improve MAC layer throughput under adverse radio conditions (e.g., low signal-to-noise ratio conditions). In some examples, the device can support same-slot HARQ feedback, where the device can provide HARQ feedback in a specific time slot for data received in a previous symbol within that time slot. In other cases, the device can provide HARQ feedback in subsequent time slots or according to some other time interval.
[0094] 5G NR Radio Resource Control (“RRC”) signaling typically includes Master Information Block (“MIB”) messages and System Information Block (“SIB”) messages, which can be used to facilitate or may be vulnerable to FBS attacks. Various types or versions of SIB messages can be transmitted by the RAN during the RRC process, where the UE is attempting to establish a connection with the RAN. Different SIB types can be designated by different numeric identifiers, such as SIB1 messages, SIB2 messages, SIB3 messages, etc. MIB messages or SIB1 messages may be referred to as, or may include, content referred to as minimal system information. Other SIB messages can be used to transmit system information during RRC connection establishment.
[0095] The MIB can carry or include channel bandwidth information, PHICH configuration information, transmit power information, antenna quantity information, and the SIB scheduling information to be transmitted. The SIB can be transmitted via the downlink shared channel. A System Information Container (“SI”) can include multiple SIBs. Different SI containers can be transmitted at different frequencies and subframes. SIB messages can be transmitted via the Broadcast Control Channel (“BCCH”).
[0096] Fake base stations are devices that can be operated for malicious purposes, impersonating legitimate cell base stations / RAN nodes to eavesdrop on mobile communications. This can pose a risk to user equipment and communication networks, such as 4G, 5G, 6G, or other wireless networks that can operate on Open Radio Access Network (“Open-RAN”) platforms or operating systems. FBS, also known as International Mobile Subscriber Identity (“IMSI”) catchers, are a threat to cellular wireless communication networks. Typical FBS implementations involve setting up a software-defined radio (“SDR”) to broadcast false cellular information or impersonate a legitimate cell tower / RAN node in an adjacent area. Conventional protection techniques focus on post-authentication protection, so broadcast signaling is unprotected or unauthenticated, thus allowing for widespread attacks. Conventional techniques used in 5G wireless networks can implement subscription to permanent identifiers and hidden identifiers (“SUPI / SUCI”) to prevent IMSI catcher attacks.
[0097] Defending against fake FBSs presents unique challenges for user equipment (UEs) in idle or standby mode. Idle or standby UEs operate in a power-saving mode, limiting power and processor usage and restricting their ability to perform complex tasks such as radio environment scanning or advanced encryption operations. This reduces their ability to determine if signal broadcasts from RAN nodes originate from FBSs. Furthermore, the lack of continuous network monitoring and infrequent re-authentication make idle / standby UEs more vulnerable to FBS attacks than active or connected UEs.
[0098] RAN nodes can transmit prohibition configurations (which may include a list of prohibited RAN nodes) to user equipment to avoid access to RAN nodes identified in the list. This can be useful during node congestion (where nodes cannot accept new connections), and thus the node temporarily prohibits access to itself. Legitimate RAN nodes / cells can determine and broadcast selection / reselection prohibition criteria or access prohibition criteria corresponding to another cell / node considered an active FBS. Idle-mode user equipment can check for the satisfaction of FBS prohibition configuration criteria regarding the configuration of signals received from the target RAN node to be selected or accessed. If one or more criteria are satisfied, the target RAN node can be effectively and dynamically prohibited from selection / reselection or access.
[0099] Integrated scoring model.
[0100] Now go to Figure 2ALegitimate RAN nodes 105A…105n may be located geographically near the fake base station 105FB, allowing the user equipment 115 to reside on or connect to one or more legitimate RAN nodes. In idle states, the UE 115 may transmit a user equipment radio parameter measurement report 205-1 to the fake base station 105FB, which may include radio performance parameters determined by the UE, such as received signal strength indication (e.g., RSRP) or signal-to-interference-plus-noise ratio (e.g., “SINR”), and a timestamp associated with the report.
[0101] like Figure 2B As shown, the fake base station 105FB appears inactive to the user equipment 115. The inactivity of the fake base station 105FB could be due to the fake base station being shut down, the fake base station changing its frequency, the fake base station moving away from the vicinity of the legitimate base stations 105A…105n, or other detection evasion measures that the fake base station can perform to avoid detection. Therefore, the user equipment 115 can transmit a user equipment radio parameter measurement report 205-2 to the legitimate base station 105A. Report 205-2 may include information similar to report 205-1, but has radio performance parameter values measured by the user equipment 115 corresponding to the radio access network node 105A, instead of corresponding to the fake base station 105FB, and has a timestamp corresponding to report 205-2.
[0102] like Figure 2C As shown, User Equipment 115 can transmit User Equipment radio parameter measurement report 210-1 to an unauthorized radio access network node 105FB. The core network computing equipment components may not receive report 210-1 because node 105FB is not a legitimate base station. Figure 2D In the diagram, user equipment 115 is shown being switched from an unauthorized radio access network node 105FB to a legitimate radio access network node 105A. This is in contrast to... Figure 2C The report 210-1 transmitted by user equipment 115 to unauthorized radio access network node 105FB at different times, as shown in the figure. Figure 2D As shown, User Equipment 115 transmits User Equipment Radio Parameter Measurement Report 210-2 not only to the unauthorized radio access network node 105FB but also to the legitimate radio access network node 105A. Therefore, because the legitimate radio access network node 105A can be connected to core network computing equipment components that may be part of the core network, such as… Figure 1The core network 130 shown allows the network computing device to receive or access information corresponding to node 105A, including radio parameter measurements and timestamps corresponding to report 205-2. Therefore, the network computing device can use the radio performance measurements and timestamps included in report 205-2 to perform analysis regarding an illegal radio access network node 105FB and one or more legitimate radio access network nodes 105A…105n, according to the embodiments disclosed herein.
[0103] Now go to Figure 3 The diagram illustrates as follows Figure 2A and 2B The example information shown is from the transmitted user equipment radio parameter measurement report 205. It should be understood that... Figure 2C and 2D Report 210, transmitted during the handover of a user equipment (UE) from a first base station to a second base station, may include information similar to report 205. Report 205 may include a radio access network (RAN) node identifier 305 corresponding to the RAN node to which the UE transmits report 205. Report 205 may include a UE identifier 310 corresponding to the UE transmitting report 205. Report 205 may include an RSRP value 315, which may correspond to the signal strength determined by the UE identified by identifier 310 and associated with the signal received by the UE from the RAN node identified by identifier 305. Report 205 may include an SINR value 320, which may correspond to the interference determined by the UE identified by identifier 310 and associated with the signal received from the RAN node identified by identifier 305. Report 205 may include UE location information 325 (e.g., GPS coordinates or location information determined by the wireless communication network in which the UE is operating), which corresponds to the location of the UE when report 205 is generated. Report 205 may include base station location information 330, which may correspond to the location of a radio access network node identified by identifier 305. Report 205 may include distance information 335, indicating the distance between the user equipment identified by identifier 310 and the radio access network node identified by identifier 305 when the user equipment generates report 205. Report 205 may include time-related information, such as a timestamp, corresponding to the time when the user equipment identified by identifier 310 generates or transmits report 205. Timestamp 340 may be used by the network computing device component to perform time analysis or generate a time map according to the embodiments described herein.
[0104] Now go to Figure 4The diagram illustrates an example learning model architecture 400 used to determine the probability that a radio access network node is a fake base station. The time analysis module 410 can determine the average time difference or interval between times corresponding to multiple user equipment radio parameter measurement reports 205 or 210. The time analysis module 410 can determine the standard deviation of the multiple radio parameter measurement reports 205 or 210. The time graph module 415 can determine a set of nodes corresponding to the multiple radio access network nodes, and the network computing device can analyze one or more radio parameter measurement reports 205 or 210 with respect to the node set. The time graph module 415 can determine the set of edges corresponding to the nodes of the graph. The Pagerank scoring module 420 can determine the ranking of the edges determined by the time graph module 415. The feature extraction module 425 can retrieve radio features or radio parameter values, such as signal strength values (e.g., RSRP values) or signal strength ratios (e.g., SINR values), from the user equipment radio parameter measurement reports 205 or 210. Feature extraction 425 can forward the radio parameter values extracted from the user equipment radio parameter measurement report to one or more anomaly determination modules, such as the isolated forest model module 430 or the local outlier feature model module 435.
[0105] The isolated forest model module 430 can help detect anomalies in radio signal parameter values such as RSRP and SINR. The isolated forest model module 430 can help isolate rare and anomalous data points within a dataset, such as datasets containing radio parameter values extracted by the feature extraction module 425, thus helping to identify anomalous signal strength or interference levels that may correspond to network anomalies or security vulnerabilities.
[0106] The Local Outlier Factor Model Module 435 can help evaluate local density biases of data points within a dataset. This module can help detect anomalies in complex, high-dimensional datasets, thus aiding in identifying anomalous patterns or outliers in wireless communication parameter datasets. Regarding the radio features extracted by the Feature Extraction Module 425, the Local Outlier Feature Model Module can help determine the density of measured radio parameter values within the dataset using information extracted from one or more user equipment radio parameter measurement reports (including location information and radio parameter values). It should be understood that when describing an anomaly detection learning model, the term "density" can refer to the "density" within a clustered region (with k nearest neighbor clusters). Therefore, the Local Outlier Feature Model Module can help identify regions corresponding to signal strength or interference levels.
[0107] The integrated model module 440 can combine the outputs of modules 420, 430, and 435 to obtain output 445, which may include or be referred to as a combined score or a combined anomaly score. The combined anomaly score can be analyzed with respect to anomaly score criteria to obtain an analyzed anomaly score, and based on the analysis of the anomaly score satisfying the anomaly score criteria, the network computing device can perform connection establishment actions, such as adding the radio access network node identifier corresponding to the analyzed anomaly score to the prohibited base station list or prohibited base station configuration.
[0108] Figure 5 The illustration shows example time graph 500, where nodes represent multiple legitimate radio access network nodes 105A to 105H and a pseudo base station 105FB. Graph edges between nodes 105 represent connection transition values corresponding to connection transitions, which are associated with user equipment (UEs) about the nodes connected by the edges. For example, a connection transition might correspond to one or more UEs selecting legitimate nodes 105A to 105H to camp on instead of camping on pseudo base station 105FB. In another example, a connection transition might correspond to one or more UEs being switched from pseudo base station 105FB to legitimate base stations 105A to 105H. Although network computing devices (e.g., Figure 1 The components of the core network 130 shown may not receive user equipment radio parameter measurement reports directed from the user equipment to the fake base station 105FB, but the network computing equipment may receive user equipment radio parameter measurement reports corresponding to the user equipment selecting legitimate base stations 105A to 105H or corresponding to the user equipment switching from a fake base station to a legitimate base station. Legitimate base stations may receive remote user equipment radio parameter measurement reports from the user equipment when the user equipment selects a legitimate base station or when the user equipment is switched to a legitimate base station.
[0109] like Figure 4 The timeline module 415 shown can generate Figure 5 As shown in Figure 500, the PageRank scoring module 420 can determine the boundary values of Figure 500 based on time-related values associated with one or more user equipments being selected or switched to legitimate base stations 105A to 105H from pseudo base station 105FB. Arrows in Figure 500 can indicate transitions from pseudo base station 105FB to legitimate base stations 105A to 105H. Boundary values (shown as percentage values in Figure 500) can correspond to the probability that a user equipment will switch from pseudo base station 105FB to legitimate base stations 105A to 105H during a given sampling phase (which can be a configured phase). The boundary probabilities shown in Figure 500 can be determined based on time-related values, such as timestamps in user equipment radio parameter measurement reports transmitted by one or more user equipments during a configured sampling phase.
[0110] In the example, the number of handovers during the configured phase corresponding to handovers from base station 105FB to base station 105B (as indicated by the timestamps associated with user equipment radio parameter measurement reports transmitted by one or more user equipments during the configured phase) can result in a 100% side probability, while the probability corresponding to handovers to other base stations 105A and 105C to 105H can be less than 10%, including the probabilities corresponding to handovers from base station 105B to base station 105C and from base station 105B to base station 105G. The side probabilities shown in Figure 500 can be derived from... Figure 4 The PageRank model module 420 shown is determined and provided to the integrated model module 440. Therefore, by Figure 4 The ensemble learning model module 440 shown can... Figure 5 The edge probabilities shown in Figure 500 are combined with the anomaly scores generated by the Isolation Forest module 430 and the Local Outlier Feature module 435 to obtain a combined anomaly score, which can indicate the probability that a radio access network node is a fake base station. It should be understood that if the Isolation Forest model module 430 or the Local Outlier Feature model module 435 indicates non-abnormal radio parameter measurements corresponding to a given base station, then the high edge probabilities corresponding to connection actions (e.g., selecting or switching to a given base station) with respect to that given base station can be... Figure 4 The integrated model module 440 shown is considered not to correspond to a fake base station. However, if in the time map (e.g.) Figure 5 In the example figure 500 shown, the determination of the high-side probability corresponding to the base station is even if Figure 4 The isolated forest model module 430 and the local outlier feature model module 435, as shown, indicate non-abnormal radio parameter measurements corresponding to a given base station. The integrated model module 440 can also identify a given base station as a fake base station. The integrated model module 440 can apply different weight values to the outputs of modules 420, 430, and 435, respectively. The different weight values that can be applied to the outputs of modules 420, 430, and 435 can be manually configured into the integrated module 440, or can be determined through training or via machine learning.
[0111] The combined anomaly scores can be normalized to a range between 0 and 1 and can be assigned as pseudo base station scores for a radio access network (RAN) node identifier, with the combined anomaly score corresponding to that RAN node identifier. The combined anomaly scores can be grouped according to the RAN node identifier. Based on the grouping of the combined anomaly scores for RAN node identifiers, the average pseudo base station probability can be determined, which can be compiled into a list of RAN node identifiers to obtain a list of RAN node identifiers and their associated probabilities with the corresponding RAN access record identifiers associated with pseudo base stations.
[0112] Now go to Figure 6 This figure illustrates a flowchart of an example method for determining the probability that a radio access network node is a fake base station. Method 600 begins with action 605. In action 610, one or more user equipments may measure radio parameters and transmit the measured radio parameter values in a user equipment radio parameter measurement report. The measured radio parameter values may include RSRP or SINR values. The user equipment radio parameter measurement report may include a timestamp corresponding to the report. In action 615, a network computing device may receive one or more user equipment radio parameter measurement reports corresponding to a configured measurement / sampling phase. The configured phase may be configured to facilitate determining, based on information contained in the one or more user equipment radio parameter measurement reports, whether a radio access network node indicated in the report received in action 615 is likely a fake base station.
[0113] In action 620, the network computing device can analyze the information contained in one or more user equipment radio parameter measurement reports with respect to time values or other time information corresponding to or based on the time indicated in each of the one or more user equipment radio parameter measurement reports. In action 625, the network computing device can generate a time graph based on the time information analyzed in action 620. The edges of the time graph can indicate or correspond to connection activities (e.g., selection / reselection or handover) corresponding to one or more radio access network nodes indicated in the one or more user equipment radio parameter measurement reports and the user equipment transmitting one of the one or more user equipment radio parameter measurement reports in 620. In action 630, the network computing device can apply a PageRank model to the values corresponding to the edges of the time graph determined in action 625 to obtain one or more connection transition values. For example, during a configuration phase (corresponding to the one or more user equipment radio parameter measurement reports analyzed in action 620), an edge corresponding to more connection transition activities (e.g., more selection / reselection or handover) can result in a higher corresponding rank or score generated by the PageRank model in action 630.
[0114] In Action 635, the network computing device may apply one or more anomaly detection learning models (e.g., one or more of the isolated forest model or local outlier feature model) to the radio parameter measurements received in Action 615 from one or more user equipment radio parameter measurement reports. The one or more anomaly detection learning models may provide one or more anomaly scores as outputs corresponding to one or more radio access network nodes indicated in the one or more user equipment radio parameter measurement reports received in Action 615. It should be understood that applying one or more anomaly detection learning models in Action 635 may be optional, therefore... Figure 6 Enclosed in a dashed box.
[0115] In action 640, the anomaly score generated by action 635 or the connection transition value determined in action 630 can be combined by the ensemble learning model into a combined anomaly score. In action 645, the combined anomaly score can be analyzed with respect to anomaly scoring criteria (which may be referred to as the fake base station criterion) to obtain an analyzed combined anomaly score. In action 650, it is determined whether the analyzed combined anomaly score meets the anomaly scoring criteria. If it is determined in action 650 that the analyzed combined anomaly score does not meet the anomaly scoring criteria, then method 600 can return to action 610, and the user equipment can continue to generate a user equipment radio parameter measurement report, and method 600 can continue as described above.
[0116] If, in action 650, it is determined that the abnormal score of the analyzed combination meets the abnormal score criteria, then method 600 proceeds to action 655. In action 655, a connection establishment action may be performed. The connection establishment action performed in action 655 may include adding the identifier corresponding to the radio access network node that was identified as a fake base station in action 650 based on the abnormal score of the analyzed combination and was thus determined to meet the abnormal score criteria. After performing the connection establishment action in action 655, method 600 proceeds to action 660 and terminates.
[0117] Now go to Figure 7 The figure illustrates an example embodiment of method 700, in which a network computing device including a processor receives at least one user equipment radio parameter measurement report generated by at least one user equipment, the at least one user equipment radio parameter measurement report including at least one report value; in a block 710, the network computing device analyzes the at least one report value to obtain at least one analyzed report value; and in a block 715, based on the at least one analyzed report value, the network computing device determines at least one connection transition value with respect to at least one radio access network node.
[0118] Now go to Figure 8The figure illustrates a network computing device 800. In block 805, a processor is included, configured to process executable instructions that, when executed by the processor, facilitate the execution of operations including receiving at least one user equipment radio parameter measurement report, the at least one user equipment radio parameter measurement report corresponding to at least one radio access network node and generated by at least one user equipment, the at least one user equipment radio parameter measurement report including at least one time value and at least one radio performance measurement value; in block 810, analyzing at least one time value to obtain at least one first anomaly value corresponding to at least one radio access network node; in block 815, analyzing at least one radio performance measurement value to obtain at least one second anomaly value corresponding to at least one radio access network node; in block 820, determining an anomaly score for at least one combination based on at least one first anomaly value and at least one second anomaly value; in block 825, analyzing the anomaly score for at least one combination with respect to anomaly score criteria to obtain an analyzed anomaly score; and in block 830, performing a connection establishment action based on meeting the anomaly score criteria.
[0119] Now go to Figure 9 The figure illustrates a non-transitory machine-readable medium 900. Block 905 includes executable instructions that, when executed by a processor of a network computing device, facilitate the execution of operations including receiving at least one user equipment radio parameter measurement report, the at least one user equipment radio parameter measurement report corresponding to at least one radio access network node and generated by at least one user equipment, the at least one user equipment radio parameter measurement report including at least one time value and at least one radio performance measurement value; in block 910 analyzing at least one time value to obtain at least one first anomaly value corresponding to at least one radio access network node; in block 915 analyzing at least one radio performance measurement value to obtain at least one second anomaly value corresponding to at least one radio access network node; and in block 920 determining at least one combined anomaly score based on at least one first anomaly value and at least one second anomaly value, the combined anomaly score indicating the probability that at least one radio access network node is a fake base station.
[0120] To provide additional context for the various embodiments described herein, Figure 10 The following discussion is intended to provide a brief, general description of a suitable computing environment 1000 in which various embodiments of the embodiments described herein may be implemented. While the embodiments have been described above in the general context of computer-executable instructions that can run on one or more computers, those skilled in the art will recognize that these embodiments may also be implemented in combination with other program modules and / or as a combination of hardware and software.
[0121] Typically, program modules include routines, programs, components, data structures, etc., that perform specific tasks or implement specific abstract data types. Furthermore, those skilled in the art will understand that these methods can be practiced using other computer system configurations, including single-processor or multi-processor computer systems, minicomputers, mainframes, IoT devices, distributed computing systems, and personal computers, handheld computing devices, microprocessor-based or programmable consumer electronics, each of which can be operatively coupled to one or more associated devices.
[0122] The embodiments described herein can also be practiced in a distributed computing environment, where certain tasks are performed by remote processing devices linked via a communication network. In a distributed computing environment, program modules can reside on both local and remote memory storage devices.
[0123] Computing devices typically include a variety of media, which may include computer-readable storage media, machine-readable storage media, and / or communication media, these terms being used herein in ways distinct from each other. A computer-readable storage medium or a machine-readable storage medium can be any available storage medium accessible by a computer, and includes both volatile and non-volatile media, removable and non-removable media. By way of example and not limitation, a computer-readable storage medium or a machine-readable storage medium can be implemented in conjunction with any method or technique used for storing information, such as computer-readable or machine-readable instructions, program modules, structured data, or unstructured data.
[0124] Computer-readable storage media may include, but are not limited to, random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD), Blu-ray disc (BD) or other optical disc storage devices, magnetic cartridges, magnetic tapes, disk storage devices or other magnetic storage devices, solid-state drives or other solid-state storage devices, or other tangible and / or non-transitory media that can be used to store desired information. In this regard, the terms “tangible” or “non-transitory” as used herein for storage devices, memories, or computer-readable media shall be understood to exclude only the propagated transient signal itself as a modifier, and shall not waive the rights to all standard storage devices, memories, or computer-readable media that do not merely propagate transient signals themselves.
[0125] A computer-readable storage medium can be accessed by one or more local or remote computing devices, for example via access requests, queries or other data retrieval protocols, for various operations relating to the information stored on the medium.
[0126] Communication media typically embody computer-readable instructions, data structures, program modules, or other structured or unstructured data in the form of data signals (such as modulated data signals, like carrier waves or other transmission mechanisms), and include any medium for delivering or transmitting information. The term "modulated data signal" or signal refers to a signal whose characteristics are set or altered in a manner that encodes information in one or more signals. By way of example and not limitation, communication media include wired media (such as wired networks or direct wired connections) and wireless media (such as acoustic, RF, infrared, and other wireless media).
[0127] Refer again Figure 10 An example environment 1000 for implementing various embodiments of the aspects described herein includes a computer 1002, which includes a processing unit 1004, system memory 1006, and a system bus 1008. The system bus 1008 couples system components (including, but not limited to, system memory 1006) to the processing unit 1004. The processing unit 1004 can be any processor from a variety of commercially available processors and may include cache memory. Dual microprocessors and other multiprocessor architectures may also be used as the processing unit 1004.
[0128] System bus 1008 can be any type of bus architecture among several types of bus architectures, which can be further interconnected to memory buses (with or without memory controllers), peripheral buses, and local buses using any of the various commercially available bus architectures. System memory 1006 includes ROM 1010 and RAM 1012. The Basic Input / Output System (BIOS) can be stored in non-volatile memory (such as ROM, erasable programmable read-only memory (EPROM), EEPROM), containing basic routines that facilitate the transfer of information between components within computer 1002 (such as during startup). RAM 1012 may also include high-speed RAM, such as static RAM, for caching data.
[0129] Computer 1002 also includes an internal hard disk drive (HDD) 1014 (e.g., EIDE, SATA), one or more external storage devices 1016 (e.g., floppy disk drive (FDD) 1016, memory stick or flash drive reader, memory card reader, etc.), and an optical disc drive 1020 (e.g., capable of reading from or writing to CD-ROMs, DVDs, BDs, etc.). Although the internal HDD 1014 is illustrated as being located within computer 1002, the internal HDD 1014 can also be configured for external use in a suitable chassis (not shown). Additionally, although not shown in environment 1000, a solid-state drive (SSD) may be used in addition to, or in place of, HDD 1014. HDD 1014, external storage devices(s) 1016, and optical disc drive 1020 may be connected to system bus 1008 via HDD interface 1024, external storage interface 1026, and optical disc drive interface 1028, respectively. The interface 1024 for external driver implementation may include at least one or both of Universal Serial Bus (USB) and Institute of Electrical and Electronics Engineers (IEEE) 1394 interface technologies. Other external driver connectivity technologies are also within the scope of the embodiments described herein.
[0130] The drive and its associated computer-readable storage medium provide non-volatile storage means for data, data structures, computer-executable instructions, etc. For computer 1002, the drive and storage medium accommodate storage of any data in a suitable digital format. While the above description of computer-readable storage media refers to a corresponding type of storage device, those skilled in the art will understand that other types of computer-readable storage media (whether currently existing or developed in the future) may also be used in the example operating environment, and further, any such storage medium may contain computer-executable instructions for performing the methods described herein.
[0131] Multiple program modules can be stored in the drive and RAM 1012, including the operating system 1030, one or more application programs 1032, other program modules 1034, and program data 1036. All or part of the operating system, applications, modules, and / or data can also be cached in RAM 1012. The systems and methods described herein can be implemented using various commercially available operating systems or combinations of operating systems.
[0132] Computer 1002 may optionally include emulation technology. For example, a hypervisor (not shown) or other intermediary may emulate a hardware environment for operating system 1030, and the emulated hardware may optionally be compatible with... Figure 10The hardware shown differs. In such an embodiment, the operating system 1030 may include one of a plurality of virtual machines (VMs) hosted at the computer 1002. Furthermore, the operating system 1030 may provide a runtime environment for the application 1032, such as the Java Runtime Environment or the .NET Framework. A runtime environment is a consistent execution environment that allows the application 1032 to run on any operating system that includes that runtime environment. Similarly, the operating system 1030 may support containers, and the application 1032 may be in the form of a container, which is a lightweight, standalone, executable software package that includes, for example, code, runtime, system tools, system libraries, and settings for the application.
[0133] Furthermore, computer 1002 may include a security module, such as a Trusted Processing Module (TPM). For example, before loading the next boot component, the boot component uses the TPM to hash the next boot component in time and waits for the result to match a security value. This process can occur at any layer of the code execution stack of computer 1002, such as at the application execution level or the operating system (OS) kernel level, thereby achieving security at any level of code execution.
[0134] Users can input commands and information into computer 1002 through one or more wired / wireless input devices, such as keyboard 1038, touchscreen 1040, and pointing devices (such as mouse 1042). Other input devices (not shown) may include microphones, infrared (IR) remote controls, radio frequency (RF) remote controls or other remote controls, joysticks, virtual reality controllers and / or virtual reality headsets, game controllers, styluses, image input devices (such as cameras), gesture sensor input devices, visual motion sensor input devices, emotion or face detection devices, biometric input devices (such as fingerprint or iris scanners), etc. These and other input devices are typically connected to processing unit 1004 via input device interface 1044, which can be coupled to system bus 1008, but may also be connected via other interfaces, such as parallel ports, IEEE 1394 serial ports, game ports, USB ports, IR interfaces, BLUETOOTH® interfaces, etc.
[0135] Monitor 1046 or other types of display devices can also be connected to system bus 1008 via an interface such as video adapter 1048. In addition to monitor 1046, computers typically include other peripheral output devices (not shown), such as speakers, printers, etc.
[0136] Computer 1002 can operate in a networked environment using logical connections to one or more remote computers (such as (multiple) remote computers 1050) via wired and / or wireless communications. The (multiple) remote computers 1050 can be workstations, server computers, routers, personal computers, laptops, microprocessor-based entertainment devices, peer-to-peer devices, or other public network nodes, and typically include many or all of the elements described relative to computer 1002, although for simplicity, only memory / storage device 1052 is illustrated. The depicted logical connections include wired / wireless connections to a local area network (LAN) 1054 and / or a larger network (e.g., a wide area network (WAN) 1056). Such LAN and WAN networking environments are common in offices and companies and facilitate enterprise-wide computer networks (such as intranets), all of which can connect to global communications networks such as the Internet.
[0137] When used in a LAN networking environment, computer 1002 can connect to local area network 1054 via a wired and / or wireless communication network interface or adapter 1058. Adapter 1058 can facilitate wired or wireless communication to LAN 1054, which may also include a wireless access point (AP) configured thereon for communicating with adapter 1058 in wireless mode.
[0138] When used in a WAN networking environment, computer 1002 may include modem 1060, or may be connected to a communication server on WAN 1056 via other means (such as via the Internet) for establishing communication over WAN 1056. Modem 1060 (which may be internal or external, wired or wireless) may be connected to system bus 1008 via input device interface 1044. In a networking environment, program modules depicted relative to computer 1002 or parts thereof may be stored in remote memory / storage device 1052. It will be understood that the network connection shown is an example, and other means of establishing communication links between computers may be used.
[0139] When used in a LAN or WAN networking environment, computer 1002 can access cloud storage systems or other network-based storage systems in addition to or in place of external storage device 1016. Typically, the connection between computer 1002 and the cloud storage system can be established, for example, on LAN 1054 or WAN 1056 via adapter 1058 or modem 1060, respectively. When computer 1002 is connected to an associated cloud storage system, external storage interface 1026 can manage the storage provided by the cloud storage system with the help of adapter 1058 and / or modem 1060, just as it manages other types of external storage. For example, external storage interface 1026 can be configured to provide access to cloud storage sources as if these sources were physically connected to computer 1002.
[0140] Computer 1002 can be operated to communicate with any wireless device or entity operably configured for wireless communication, such as printers, scanners, desktop and / or portable computers, portable data assistants, communication satellites, any device or location associated with a wirelessly detectable tag (e.g., newsstands, newsstands, store shelves, etc.), and telephones. This can include Wi-Fi and BLUETOOTH® wireless technologies. Therefore, communication can be a predefined structure like a traditional network, or simply self-organizing communication between at least two devices.
[0141] Turn now Figure 11 The figure illustrates a block diagram of example UE 1160. UE 1160 may include a smartphone, wireless tablet, wirelessly capable laptop computer, wearable device, machine equipment that can facilitate vehicle telematics, etc. UE 1160 includes a first processor 1130, a second processor 1132, and shared memory 1134. UE 1160 includes a radio front-end circuitry 1162, which may be referred to herein as a transceiver, but should be understood to generally include transceiver circuitry, separate filters, and separate antennas for facilitating communication via wireless links (such as...). Figure 1 Transceiver 1162 may transmit and receive signals from one or more wireless links 115, 135, or 137 as shown. Furthermore, transceiver 1162 may include multiple sets of circuitry or may be tunable to accommodate different frequency ranges, different modulation schemes, or different communication protocols to facilitate long-range wireless links (such as link 115), device-to-device links (such as link 135), and short-range wireless links (such as link 137).
[0142] Continue to Figure 11As described above, UE 1160 may also include SIM 1164 or SIM profile, which may include memory (memory 1134 or a separate memory portion) for facilitating communication with... Figure 1 Information on wireless communication of RAN 105 or core network 130 shown. Figure 11 The SIM 1164 is shown as a single component in the shape of a traditional SIM card, but it will be understood that the SIM 1164 can represent multiple SIM cards, multiple SIM profiles, or multiple eSIMs, some or all of which can be implemented in hardware or software. It will be understood that a SIM profile may include security credentials (e.g., encryption keys, values that can be used to generate encryption keys, or information about the connection between the SIM 1164 and another device, which may be...) Figure 1 Information shared between components of RAN 105 or core network 130 (as shown in the diagram). SIM profile 1164 may also include unique identification information for the SIM or SIM profile, such as, for example, International Mobile Subscriber Identity (“IMSI”) or information that may constitute an IMSI.
[0143] SIM 1164 is shown coupled to both the first processor portion 1130 and the second processor portion 1132. This implementation offers the advantage that the first processor portion 1130 does not need to request or receive information or data that the second processor 1132 might request from SIM 1164, thus eliminating the first processor's role as a "man-in-the-middle" when the second processor uses information from the SIM in performing its functions and executing applications. The first processor 1130 (which may be a modem processor or a baseband processor) is shown smaller than processor 1132 (which may be a more complex application processor) to visually indicate the relative level of complexity (i.e., processing power and performance) and the corresponding relative level of operating power consumption between the two processor portions. When the UE 1160 does not require the second processor section 1132 to perform applications and process application-related data, keeping the second processor section 1132 in a sleep / inactive / low-power state provides the following advantages: reduced power consumption when the UE only needs to use the first processor section 1130 in bearer management and mobility management / maintenance processes for monitoring routine configuration, or in listening mode for monitoring the search space that the UE has been configured to monitor while the second processor section remains inactive / sleep.
[0144] UE 1160 may also include sensors 1166, such as temperature sensors, accelerometers, gyroscopes, barometers, humidity sensors, etc., which can provide signals to the first processor 1130 or the second processor 1132. Output devices 1168 may include, for example, one or more visual displays (e.g., computer monitors, VR devices, etc.), acoustic transducers (such as speakers or microphones), vibration components, etc. Output devices 1168 may include software that interfaces with output devices (e.g., visual displays, speakers, microphones, haptic devices, olfactory or gustatory devices, etc., which are external to UE 1160).
[0145] The following glossary of terms given in Table 1 can be applied to one or more descriptions of the embodiments disclosed herein. Table 1
[0146] The above description includes non-limiting examples of various embodiments. It is certainly not possible to describe every contemplative combination of components or methods for the purpose of describing the disclosed subject matter, and those skilled in the art will recognize that further combinations and arrangements of various embodiments are possible. The disclosed subject matter is intended to cover all such changes, modifications, and variations falling within the spirit and scope of the appended claims.
[0147] In relation to the various functions performed by the aforementioned components, devices, circuits, systems, etc., the terminology used to describe such components (including references to "apparatus") is also intended (unless otherwise stated) to include any structure(s) performing the specified functions of the described component (e.g., functional equivalents), even if not structurally equivalent to the disclosed structure. Furthermore, while specific features of the disclosed subject matter may have been disclosed with respect to only one of several implementations, such features may be combined with one or more other features that may be desirable and advantageous for any given or particular application.
[0148] The terms “exemplary” and / or “illustrative” or variations thereof, as may be used herein, are intended to refer to examples, instances, or illustrations. For the avoidance of doubt, the subject matter disclosed herein is not limited to such examples. Furthermore, any aspect or design described herein as “exemplary” and / or “illustrative” is not necessarily to be construed as preferred or advantageous over other aspects or designs, nor does it imply the exclusion of equivalent structures and techniques known to those skilled in the art. Moreover, with respect to the use of the terms “include,” “have,” “comprising,” and other similar words in the context of the detailed description or claims, such terms are intended to be inclusive—in a manner similar to the term “comprising” as an open-ended transitional phrase—without excluding any additional or other elements.
[0149] The term “or” as used herein is intended to mean inclusive rather than exclusive. For example, the phrase “A or B” is intended to include instances of A, instances of B, and instances of both A and B. Additionally, the articles “a” and “an” as used in this application and the appended claims should generally be interpreted as meaning “one or more” unless otherwise specified or clearly indicated from the context as referring to the singular form.
[0150] The term "set" as used herein excludes the empty set, i.e., a set containing no elements. Therefore, "set" as used in this disclosure includes one or more elements or entities. Similarly, the term "group" used herein refers to a collection of one or more entities.
[0151] The terms “first,” “second,” “third,” etc., used in the claims are for clarity only and do not otherwise indicate or imply any order of time, unless the context clearly states otherwise. For example, “first determination,” “second determination,” and “third determination” do not indicate or imply that the first determination is made before the second determination, or vice versa, etc.
[0152] The description of the illustrative embodiments of this disclosure provided herein (including those described in the abstract) is not intended to be exhaustive or to limit the disclosed embodiments to the precise forms disclosed. While specific embodiments and examples have been described herein for illustrative purposes, various modifications are possible within the scope of such embodiments and examples, as will be appreciated by those skilled in the art. In this regard, although the subject matter has been described in conjunction with various embodiments and corresponding drawings, it should be understood where applicable that other similar embodiments may be used, or modifications and additions may be made to the described embodiments to perform the same, similar, alternative, or substitute functions of the disclosed subject matter without departing from the disclosed subject matter. Therefore, the disclosed subject matter should not be limited to any single embodiment described herein, but should be interpreted broadly and comprehensively in accordance with the appended claims.
Claims
1. A method comprising: A network computing device including a processor receives at least one user equipment radio parameter measurement report generated by at least one user equipment, the at least one user equipment radio parameter measurement report including at least one reported value; The network computing device analyzes the at least one reported value to obtain at least one analyzed reported value; as well as Based on the at least one analyzed reported value, the network computing device determines at least one connection transition value for at least one wireless access network node.
2. The method of claim 1, wherein the at least one analyzed reported value corresponds to at least one interval associated with the at least one user equipment radio parameter measurement report.
3. The method of claim 1, wherein the at least one analyzed reported value is at least one time-based value.
4. The method of claim 1, wherein the at least one radio access network node is a first radio access network node, wherein the at least one connection transition value is a first connection transition value, the first connection transition value corresponding to the at least one user equipment transitioning from a connected state with the first radio access network node to a connected state with the second radio access network node, wherein the at least one user equipment radio parameter measurement report is a first user equipment radio parameter measurement report, wherein the at least one report value is a first time corresponding to the at least one user equipment radio parameter measurement report, and wherein the first connection transition value is determined at least based on the first time and a second time corresponding to the second user equipment radio parameter measurement report.
5. The method according to claim 4, further comprising: The network computing device determines the second connection transition value based at least on the first connection transition value and a third time corresponding to the radio parameter measurement report of the third user equipment.
6. The method of claim 1, wherein the at least one radio access network node is a first radio access network node, and wherein the at least one connection transition value corresponds to the at least one user equipment being idle and transitioning from a selection residing on the first radio access network node to a selection residing on the second radio access network node.
7. The method of claim 1, wherein the at least one radio access network node is a first radio access network node, and wherein the at least one connection transition value corresponds to the at least one user equipment transitioning from being connected to the first radio access network node to being connected to a second radio access network node.
8. The method of claim 1, wherein the at least one connection transition value is a first connection transition value, the first connection transition value corresponding to a time associated with the at least one user equipment radio parameter measurement report, wherein the at least one user equipment radio parameter measurement report further includes at least one radio performance measurement value, and wherein the method further includes: The network computing device analyzes the at least one radio performance measurement to obtain a second connection conversion value associated with the at least one wireless access network node; as well as Based on the first connection conversion value and the second connection conversion value, the network computing device determines a fake base station score, which indicates the probability that the at least one wireless access network node is a fake base station.
9. The method according to claim 8, further comprising: The network computing device analyzes the fake base station score according to the fake base station scoring standard to obtain the analyzed fake base station score; Based on the analyzed fake base station score, it is determined that the fake base station score standard is met, and the network computing device determines that the at least one wireless access network node is at least one fake base station. as well as The connection establishment action is performed by the network computing device.
10. The method of claim 9, wherein the connection establishment action comprises: Add at least one identifier corresponding to the at least one fake base station to the base station block list.
11. The method of claim 8, wherein analyzing the at least one radio performance measurement comprises: The at least one radio performance measurement is analyzed based on at least one of the following: an isolated forest machine learning model or a local outlier feature machine learning model.
12. The method of claim 8, wherein the at least one radio performance measurement is at least one of the following: a received signal strength value or a received signal-to-interference-plus-noise ratio value.
13. The method of claim 1, wherein the at least one connection transformation value is a time graph edge.
14. A network computing device, comprising: A processor configured to process executable instructions, which, when executed by the processor, facilitate the execution of operations, including: Receive at least one user equipment radio parameter measurement report, the at least one user equipment radio parameter measurement report corresponding to at least one radio access network node and generated by at least one user equipment, the at least one user equipment radio parameter measurement report including at least one time value and at least one radio performance measurement value; Analyze the at least one time value to obtain at least one first outlier value corresponding to the at least one wireless access network node; Analyze the at least one radio performance measurement to obtain at least one second anomaly corresponding to the at least one wireless access network node; Based on the at least one first outlier and the at least one second outlier, determine at least one combination of outlier scores; The abnormality score is analyzed based on the abnormality score of at least one combination of the above-mentioned abnormality scores to obtain the analyzed abnormality score; and Based on meeting the aforementioned anomaly score criteria, a connection establishment action is performed.
15. The network computing device of claim 14, wherein determining the anomalous score of the at least one combination comprises: The ensemble learning model is applied to the at least one first outlier and the at least one second outlier.
16. The network computing device of claim 14, wherein analyzing the at least one radio performance measurement comprises: Apply at least one of the following to the at least one radio performance measurement: an isolated forest learning model or a local outlier learning model.
17. The network computing device of claim 14, wherein analyzing the at least one time value comprises: The time graph model is applied to the at least one time value, and the at least one first outlier is at least one time graph edge.
18. The network computing device of claim 14, wherein the network computing device is part of the core network of a wireless communication network.
19. A non-transitory machine-readable medium comprising executable instructions that, when executed by a processor of a network computing device, facilitate the execution of operations, the operations including: Receive at least one user equipment radio parameter measurement report, the at least one user equipment radio parameter measurement report corresponding to at least one radio access network node and generated by at least one user equipment, the at least one user equipment radio parameter measurement report including at least one time value and at least one radio performance measurement value; Analyze the at least one time value to obtain at least one first outlier value corresponding to the at least one wireless access network node; Analyze the at least one radio performance measurement to obtain at least one second anomaly corresponding to the at least one wireless access network node; as well as Based on the at least one first outlier and the at least one second outlier, an outlier score of at least one combination is determined, the outlier score of the at least one combination indicating the probability that the at least one wireless access network node is a fake base station.
20. The non-transient machine-readable medium of claim 19, wherein analyzing the at least one time value comprises: The time graph model is applied to the at least one time value, wherein the at least one first outlier corresponds to at least one edge of the time graph generated by applying the time graph model to the at least one time value, wherein the at least one radio access network node is a first radio access network node, and wherein the at least one edge corresponds to a connection transition activity with respect to the first radio access network node and at least a second radio access network node.