Enhanced mechanisms for detecting false base station attacks
Randomizing communication resources and identifiers in wireless networks prevents attackers from predicting resource allocations, effectively detecting and mitigating MitM attacks, achieving a high detection success rate.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- KONINKLIJKE PHILIPS NV
- Filing Date
- 2021-12-30
- Publication Date
- 2026-04-24
AI Technical Summary
Existing wireless communication systems are vulnerable to fake base station (FBS) attacks, particularly man-in-the-middle (MitM) attacks, which are difficult to detect due to the ability of attackers to anticipate resource allocations and lack of beamforming availability in relay scenarios.
Implementing a mechanism that randomizes the assignment of communication resources and identifiers using true or pseudorandom number generators, ensuring attackers cannot predict these assignments, thereby facilitating detection of FBS attacks.
The randomized resource allocation makes it impossible for attackers to monitor and profile communication patterns, enhancing the detection and prevention of MitM attacks, with a success rate greater than 99.99%.
Smart Images

Figure 0007851317000001 
Figure 0007851317000002 
Figure 0007851317000003
Abstract
Description
Technical Field
[0001] The present invention relates to security techniques for fake or spoofed base station (FBS) attacks or man-in-the-middle (MitM) attacks in wireless communication networks such as cellular communication networks, although not limited thereto.
Background Art
[0002] Many wireless communication systems use access devices (base stations, Node Bs (eNB, eNodeB, gNB, gNodeB, ng-eNB, etc.), access points, etc.) to provide a geographical service area in which a wireless communication device (e.g., an end device or terminal device such as a mobile station or user equipment (UE)) communicates with an access device that provides services to a specific geographical service area where the terminal device is located. The access device is connected within the network and enables a communication link to be established between the wireless communication device and other devices.
[0003] In such a telecommunication system, a wireless communication device can access various types of services, including voice and data services, through a locally deployed access device. The network access device is connected to a core network (CN) that controls the telecommunication system and directs service provision (managed by a network operator).
[0004] Throughout this disclosure, the term "spoofed base station" or "fake base station" (FBS) is generally used to refer to a wireless device that masquerades as a legitimate or real base station (RBS) or other type of legitimate or real network access device.
[0005] Attackers are using FBS devices to attack wireless communication devices in many ways. FBS devices act as legitimate base stations managed by network operators and aim to attract wireless communication devices with various objectives, including performing denial-of-service (DoS) attacks to block network access, obtaining private user data, performing man-in-the-middle (MitM) attacks and subsequent attacks (such as active cryptographic attacks (aLTEr), impersonation attacks (imp4gt), and network misconfiguration), performing authentication relay attacks, performing self-organizing network poisoning attacks, and sending false public alert information.
[0006] FBS is an International Mobile Subscriber Identification Number (IMSI) catcher. However, the capabilities of FBS vary depending on whether the mobile network is based on General-Purpose Packet Radio Service (GPRS), Universal Mobile Communications System (UMITS), Long-Term Evolution (LTE), or 5G. 5G systems, in particular, have already made significant improvements to address FBS issues, such as encryption of International Mobile Subscriber Identifiers (SUPIs), guaranteed globally unique temporary identifiers (GUTIs), protected redirection, and a general information detection framework. There are also other security features that 5G security inherits from previous generations, such as mutual authentication between the UE and the network, integrity-protected signaling, and secure algorithm negotiation.
[0007] Further details on protective measures can be found in 3GPP® specification TR 33.809, “A Study on Enhancing 5G Security Against Fake Base Stations (FBS).” Additionally, studies on security solutions, constraints, and requirements are disclosed in 3GPP® specification TR 33.969, “A Study on Security Aspects of Public Warning Systems (PWS).”
[0008] Such telecommunications systems are also evolving further, with wireless communication devices having access to the CN not only through a true base station (RBS), but also through other relay devices. For example, a remote UE (i.e., a UE that cannot reach the RBS directly) connects to the CN using a relay UE (i.e., a UE connected to the CN via another UE or RBS). In such communication scenarios, the MitM device is, for example, a relay UE that forwards communication between the remote UE and the RBS. However, proposed solutions for detecting MitM attacks are not feasible because the allocated resources can be anticipated by the MitM attacker and / or beamforming is not always available. Therefore, it remains desirable to extend the security capabilities available in wireless communication systems so that the risks caused by FBS-based attacks can be minimized. [Overview of the project] [Problems that the invention aims to solve]
[0009] The objective of the present invention is to provide an enhanced mechanism for detecting and / or avoiding FBS attacks. [Means for solving the problem]
[0010] This objective is achieved by the apparatus claimed in claim 1, the network device claimed in claim 13, the attack detection system claimed in claim 14, the method claimed in claim 15, the computer program claimed in claim 16, and the network system claimed in claim 17.
[0011] According to the first aspect, a device for detecting the presence of a fake wireless device impersonating a genuine or authentic access device in a wireless network or an attack by such a fake wireless device, wherein the device A randomizer for randomizing the assignment of at least one communication resource and / or identifier used to communicate with a wireless communication device, An attack testing unit for checking whether a wireless communication device has used at least one communication resource and / or identifier assigned by randomized assignment, and whether, for example, other communication resources and / or identifiers, and for determining the presence of a fake wireless device or an attack by such fake wireless device based on the results of the check. An apparatus is provided that includes the following.
[0012] According to a second aspect, a method for detecting an attack by a fake wireless device that impersonates a genuine or authentic access device in a wireless network, wherein the method is: A step of randomizing the assignment of at least one communication resource and / or identifier used to communicate with a wireless communication device, A step of checking whether a transmission received from a wireless communication device used at least one communication resource and / or identifier assigned by randomized assignment, A step to determine the presence of a fake wireless device or an attack by said fake wireless device based on the results of the inspection step. A method is provided that has the following characteristics.
[0013] According to a third embodiment, a network device for a wireless network (e.g., an access device such as a base station, gNB, or access point, or a relay device or core network device) is provided, comprising the apparatus of the first embodiment. Thus, randomized allocation of resource / identifiers can be performed in the access device, or in other network devices such as the core network device or relay device.
[0014] According to a fourth aspect, an attack detection system is provided comprising a network device of the third aspect and a wireless communication device, wherein the wireless communication device is configured to detect at least one assigned communication resource and / or identifier and to apply the detected at least one communication resource and / or identifier to communication with the network device. Logic for presence or attack detection is also provided in various network devices, for example, in a CN. In one example, an access device (e.g., a base station) may only transmit communication statistics (e.g., whether a message arrived slightly late), while a network device in a CN may perform logic for detecting whether an attack exists by correlating information related to several wireless communication devices.
[0015] Finally, according to the fifth aspect, a computer program is provided which, when executed on a single or more distributed computer devices, comprises coding means for producing the steps of the method of the second aspect.
[0016] Finally, according to the sixth aspect, a network system is provided comprising two or more distributed network devices configured to jointly perform the steps of the method of the second aspect. Thus, the proposed solution can be performed by two different network devices, such as an access device (e.g., a base station or gNB) and a relay device (e.g., a relay UE).
[0017] Therefore, the proposed assignment of at least one randomized communication resource and / or identifier ensures that it is impossible for an attacker to monitor the expected behavior of the access device or wireless communication device to derive the assigned resource and / or identifier, thereby making it easier to detect MitM devices or MitM attacks. Furthermore, this also prevents attackers from profiling the communication patterns of the wireless communication device.
[0018] It should be noted that the proposed randomized assignments are based either on a true random number generator (e.g., using a physical process such as thermal noise to generate random numbers) or on the extraction of pseudorandom numbers from a secure pseudorandom number generator (e.g., SHAKE (SHA3)) and / or a seed (the seed is obtained from a true random number generator).
[0019] According to the first option, which can be combined with any of the first to sixth embodiments described above, the randomizer is configured to calculate, for example, at least one uniformly distributed random parameter value within a range of predetermined values, and to allocate time or frequency resources (e.g., subsequent frames, subsequent slots, or subsequent frequency ranges) to communication with the wireless communication device based on the calculated at least one parameter value. This provides an efficient randomization option that can be easily implemented with little hardware effort.
[0020] According to the first option or the second option combined with any of the first to sixth embodiments described above, the randomizer is configured to determine a random latency, the device is configured to send a resource activation message to the wireless communication device after the random latency has expired, and the attack inspection unit is configured to check, based on a timer function, whether a direct response has been received from the wireless communication device. Thus, the proposed attack detection technique can be implemented based on a single message from the wireless communication device to the access device.
[0021] According to the first or second option, or a third option which may be combined with any of the first to sixth embodiments described above, the attack inspection unit is configured to inspect whether the received direct response contains downlink control information included in the resource activation message. Thus, the reception time and the content of the received response may be used to inspect for FBS or MitM attacks.
[0022] According to any one of the first to third options, or a fourth option that can be combined with any one of the first to sixth aspects described above, the apparatus is configured to transmit at least one communication resource and / or identifier assigned in a protected message (e.g., an encrypted message). This measure has the advantage that an attacker cannot analyze the relevant message used for the transmission of the assigned communication resource or identifier to derive the assigned communication resource or identifier.
[0023] According to any one of the first to fourth options, or a fifth option that can be combined with any one of the first to sixth aspects described above, at least one assigned communication resource includes at least one of a random time domain offset value, a random time domain allocation value, and a random frequency domain allocation value to be used for the response by the wireless communication device. These specific randomized values enable an effective way to secure the transmission against FBS or MitM attacks.
[0024] According to any one of the first to fifth options, or a sixth option that can be combined with any one of the first to sixth aspects described above, the time domain offset value indicates a time offset with respect to the system frame number (SFN) at which the wireless communication device starts transmission. The attack inspection unit is configured to monitor that no response message is received from the wireless communication device before or after the expected transmission time. Thereby, randomization is achieved in an efficient way by signaling a random offset with respect to the frame number.
[0025] According to any one of the first to sixth options, or a seventh option that can be combined with any one of the above first to sixth aspects, at least one of the time domain allocation value and the frequency domain allocation value indicates a row or a column of a look-up table. Thereby, an efficient way to achieve additional randomized resource allocation is realized by simply referring to a row or a column of the look-up table in which resource information is stored.
[0026] According to any one of the first to eighth options, or a ninth option that can be combined with any one of the above first to sixth aspects, the attack inspection unit is configured to execute an inspection operation after security establishment when the wireless communication device connects to the wireless network (for example, establishes a secure connection with the network), or after a handover of the wireless communication device. Thereby, it can be ensured that an FBS or MitM attack can be detected each time a new connection is established.
[0027] According to any one of the first to ninth options, or a tenth option that can be combined with any one of the above first to sixth aspects, the randomizer is configured to determine a random seed value to be transferred to the wireless communication device in a protected (i.e., encrypted and / or integrity-protected) manner in order to allocate communication resources (e.g., time slots or frequency ranges) to the response message based on a pseudo-random sequence. Therefore, an efficient way to signal a time slot or a frequency range allocated in a secure manner can be realized.
[0028] According to any of the first to ninth options, or a tenth option which may be combined with any of the first to sixth embodiments described above, the randomizer is configured to determine at least one list of random ephemeral network identifiers (e.g., RNTIs), or a random seed value for deriving pseudorandom ephemeral network identifiers by a pseudorandom function; the device is configured to transfer at least one list of random ephemeral network identifiers or a random seed to a wireless communication device in a protected manner for the selection of random ephemeral network identifiers in subsequent transmissions; and the attack testing unit is configured to determine an attack by a fake wireless device based on the received random ephemeral network identifiers, in particular, whether the received random ephemeral network identifiers are used in the correct order or instantaneously for a predetermined time. This measure provides an efficient way to detect FBS or MitM attacks using randomized ephemeral network identifiers.
[0029] According to any of the first to tenth options, or an eleventh option which may be combined with any of the first to sixth embodiments described above, the randomizer is configured to determine a first list of random temporary network identifiers to be used by the wireless communication device and a second list of temporary network identifiers to be used by the device. This has the advantage that both connection terminals (i.e., the wireless communication device and the access device) can easily check whether the correct temporary network identifier has been received.
[0030] It should be noted that the above-mentioned devices are implemented based on individual hardware circuit configurations having arrangements of individual hardware components, integrated chips, or chip modules, or on signal processing devices or chips controlled by software routines or programs stored in memory, written to computer-readable media, or downloaded from a network such as the Internet.
[0031] It should be understood that the apparatus of claim 1, the network device of claim 13, the attack detection system of claim 14, the method, computer program, and network system of claim 15 have similar and / or identical preferred embodiments, in particular, as defined in the dependent claims.
[0032] Furthermore, it should be understood that the apparatus of claim 1, the network device of claim 13, the attack detection system of claim 14, and the method of claim 15 may be attached to or executed on a single or multiple distributed network devices.
[0033] It should be understood that preferred embodiments of the present invention may also be dependent claims, each accompanied by an independent claim, or any combination of the above embodiments.
[0034] These and other aspects of the present invention will become clearer and more apparent with reference to the embodiments described below. [Brief explanation of the drawing]
[0035] [Figure 1] This figure schematically illustrates a network architecture in which the present invention can be implemented. [Figure 2] This is a schematic block diagram illustrating enhanced access devices in various embodiments. [Figure 3] This is a signaling and processing diagram schematically illustrating the FBS detection procedure according to the first embodiment. [Figure 4] This is a schematic signaling and processing diagram illustrating the FBS detection procedure according to the second embodiment, both with and without a MitM attack. [Figure 5] This is a more detailed signaling and processing diagram illustrating the FBS detection procedure according to the second embodiment in the absence of a MitM attack. [Figure 6] This is a more detailed signaling and processing diagram illustrating the FBS detection procedure according to the second embodiment in the case of a MitM attack. [Figure 7] This is a schematic signaling and processing diagram illustrating the FBS detection procedure according to the third embodiment, both with and without a MitM attack. [Figure 8] This is a schematic signaling and processing diagram illustrating an example of the FBS detection procedure according to the third embodiment. [Figure 9] This figure schematically illustrates a solution to a certain MitM attack according to a further embodiment of the present invention. [Figure 10] This diagram provides a schematic illustration of how a possible MitM attack works. [Figure 11] This diagram schematically illustrates an advanced MitM attacker using RF repeaters. [Modes for carrying out the invention]
[0036] Herein, embodiments of the present invention will be described based on radio resource control (RRC) signaling for 5G cellular networks.
[0037] Throughout this disclosure, the abbreviation “gNB” (5G term) is intended to mean an access device such as a cellular base station or WiFi access point. A gNB consists of a centralized control plane unit (gNB-CU-CP), multiple centralized user plane units (gNB-CU-UP), and / or multiple distributed units (gNB-DU). A gNB is part of a radio access network (RAN), which provides an interface to the functions of the core network (CN). The RAN is part of a wireless communications network. The RAN implements radio access technology (RAT). Conceptually, the RAN exists between communications devices such as mobile phones, computers, or any remotely controlled machines, enabling their connection to the CN. The CN is the core part of the communications network, providing numerous services to customers interconnected via the RAN. More specifically, the CN directs the stream of communications across the communications network and, potentially, other networks.
[0038] The elements for implementing the scheduling mechanism are end-to-end radio resource control (RRC) protocols that can operate on wireless communication devices (UEs in 5G terminology).
[0039] Another element for implementing scheduling mechanisms is the control element (CE) of the Medium Access Control (MAC) protocol, which is a short element (or information element (IE)) inserted between existing uplink (UL), downlink (DL), or sidelink (SL) transmissions over the MAC layer, used to efficiently signal specific events, measurements, or settings. Furthermore, MAC CEs are used by access devices (e.g., gNBs) to control the behavior of communication devices (e.g., UEs) when implementing various other 3GPP® mechanisms such as channel status information (CSI) reporting, sounding reference signals (SRS), or intermittent reception (DRX).
[0040] A further element is the use of Downlink Control Information (DCI), which is a short message sent over a low-bitrate control channel (e.g., a Physical Downlink Control Channel (PDCCH)) with special blind-detectable modulation or coding. This mechanism is implemented at the Physical Protocol Layer (PHY L1) and does not require the use of a MAC PDU header structure. Here, various DCI formats can be defined using different information content. Communication resources for dynamic scheduling can be indicated in the DCI.
[0041] 3GPP® specification TS 33.501 discloses how networks use information sent in measurement reports in RRC_CONNECTED mode to perform UE-assisted network-based detection of fake or spoofed base stations (FBS). Furthermore, 3GPP® specification TR 33.809, mentioned at the beginning, discloses research reports on the FBS problem and discusses various solutions for evading / detecting FBS and MitM attackers.
[0042] Figure 1 schematically shows a network architecture with a MitM attacker system 20 positioned between a real UE (RUE) 10 and a real base station (RBS) 30 (e.g., a gNB). However, it should be noted that the RBS 30 could also be a relay device (such as a relay UE).
[0043] The MitM attacker system 20 includes an FBS 23, which is a base station (e.g., a gNB) operated by an attacker with the aim of attracting UEs and disrupting their normal operation. Furthermore, the MitM attacker system 20 includes a fake UE (FUE) 21, which is located between the RUE 10 and the RBS 30. The FUE 21 can establish communication with the core network (not shown) via the RBS 30 so that the MitM attacker system 20 can forward communications. The FUE 21 can then perform further actions, including intercepting (I), forwarding (F), manipulating (M), or discarding (D) messages exchanged between the RUE 10 and the RBS 30.
[0044] Figure 2 schematically shows block diagrams of enhanced access devices according to various embodiments.
[0045] Note that only the blocks related to the proposed MitM detection function are shown in Figure 2. Other blocks have been omitted for brevity.
[0046] According to various embodiments, it is proposed to implement randomized communication parameters, such as randomized transmission resources or randomized communication identifiers, to enable detection and / or avoidance of MitM attacks. As a result, randomized resource allocation is achieved to detect and / or avoid FBS attacks, and the RBS can verify that the wireless communication device (e.g., UE) is not transmitting on other resources and is only transmitting on the assigned randomized resources.
[0047] The access devices in Figure 2 correspond to the RBS (e.g., gNB or relay device) or any other type of access device for any wireless network in Figure 1.
[0048] As shown in Figure 2, the access device includes a transceiver unit (TRX) 26 for sending and receiving wireless messages and / or other wireless signals via an antenna. Messages with randomized communication resources and / or identifiers (randomized resource allocations) are created and / or signaled by the scheduler 24 based on a randomization function or randomizer (RM) 25, which is a separate unit from the scheduler 24's aggregate unit. The scheduler 24 is expected to handle good agreement between resource allocations and the recommended bitrate values they send to the UE. Randomized resource allocations are created or signaled in response to trigger events generated by the detector unit (DET) 22 when the DET 22 detects a triggering message received from a wireless communication device (e.g., RUE 10 in Figure 1) via the transceiver unit 21. Furthermore, the detector unit 22 is configured to detect or determine FBS or MitM attacks based on an analysis of the received messages.
[0049] Furthermore, the randomizer 25 includes memory with a lookup table that provides a mapping table for generating pseudo-randomized output values, which will be described later.
[0050] In the example, the proposed randomized resource allocation may be achieved by introducing random latency and introducing frame numbers (e.g., system frame numbers (SFNs)), subframes, transmit slots, frequency resources, or ephemeral network identifiers in a random, or at least random-looking, and / or secure manner.
[0051] For example, the proposed exchange of randomized communication parameters may be carried out in a secure manner. Communication carried out in a secure manner is intended to be protected, and protection may include multiple security characteristics such as "encryption" or "integrity protection."
[0052] This means that the allocated resources follow a random or at least seemingly random pattern, making it impossible for a MitM attacker to predict when a wireless communication device will transmit data.
[0053] According to various embodiments, randomized resource allocation is applied in connection with various communication protocol options such as the RRC protocol (in which RRC messages are transported sequentially via PDCP, via Radio Link Control (RLC), and / or via the MAC protocol, potentially over multiple hops, with the advantage that transport reliability is guaranteed and integrity protection is applied (via the Packet Data Convergence Protocol (PDCP) using retransmission), PDCP control, or data packet data unit (PDU).
[0054] Figure 3 schematically shows the signaling and processing diagram of the FBS detection procedure according to the first embodiment.
[0055] In the signaling and processing sequence in Figure 3, and subsequently in Figures 4 to 9, the vertical direction from top to bottom corresponds to the time axis, so messages or processing steps that are above other messages or processing steps occur at an earlier time. The devices involved are the real UE (RUE) 10, the MitM attacker system 20 (e.g., comprising a fake base station (FBS) 23 (e.g., gNB) and a fake UE (FUE) 21), and the real base station (RBS) 30 (e.g., gNB).
[0056] In the first step S300, RUE10 establishes a connection with RBS30 through MitM attacker system 20, and RRC security is established. This is followed by a resource allocation step 320 by FBS23, which involves allocating time and / or frequency resources, such as a first set of SFN parameters SFN1 (e.g., system frame number, subframe number, and slot).
[0057] Furthermore, in step S310, which is parallel, subsequent, or preceding the first step S300, the RBS30 (for example, the randomizer 25 in Figure 2) calculates a random allocation parameter r (for example, in the range between 0 and N-1, where N is an integer, for example, 10240) for the subsequent time resource allocation in step S340.
[0058] In step S330, RUE10 initiates the communication process by sending an RRC message to RBS30. For simplicity, a null RRC message may be sent.
[0059] In step S350, the FUE21 of the MitM attacker system 20 forwards the RRC message to the RBS30. Similarly, in step 340, the RBS30 pre-allocates time and / or frequency resources, such as a second set of SFN parameters, SFN2 (e.g., system frame number, subframe number, and slot), to the FUE21.
[0060] Note that RBS30 (for example, scheduler 24 in Figure 2) assigns the next transmit slot in step S330 using a random assignment parameter r (uniformly distributed in the range 0, ..., N-1 and calculated in step S310) to determine, for example, the frame number r / 10 and the subframe number r%10. Therefore, the second set of SFN parameters SFN2 assigned by RBS30 does not need to be equal to the first set of SFN parameters SFN1 assigned by FBS23 in step S320. Here, the symbol " / " means integer division, for example, "125 / 10" is equal to 12. Furthermore, the symbol "%" means the modulo operator that returns the remainder of an integer division, for example, "125%10" is equal to 5. Thus, if N=10240 is selected, the collision probability is 1 / 10240. In other words, it is possible to assign 1024 possible system frame numbers and 10 subframe numbers, so the detectability of a MitM attack is greater than 99.99%.
[0061] Furthermore, it should be noted that FBS23 cannot modify the second set of SFN parameters, SFN2, which is controlled by RBS30. In addition, FBS23 cannot reschedule the first set of SFN parameters, SFN1, which was allocated earlier. If the MitM attacker system 20 does not support step S330, the MitM attacker system 20 cannot forward the RRC message with the allocated resources in step S350. This means that a new SFN2 resource needs to be allocated, resulting in a rescheduling or connection timeout of SFN2.
[0062] In step S360, RBS30 stores the set of SFN parameters it has assigned, SFN2. Note that RBS30 may also store only the first set of SFN parameters it has assigned (including any time and frequency resources).
[0063] In the subsequent step S370, RUE10 sends a first set of SFN parameters SFN1 that it received in the protected message (e.g., a secure RRC message from FBS23), and FBS23 forwards the RRC message to RBS30 via FUE21 in step 380.
[0064] Finally, in step S390, the RBS30 (for example, the detector unit 22 in Figure 2) compares a first set of SFN parameters, SFN1, with a second set of SFN parameters, SFN2, to determine whether an FBS or MitM attacker is involved in the transmission. If SFN1 and SFN2 do not match, or if no message was received in step S380, the RBS30 determines the presence of a MitM system or device.
[0065] The proposed introduction of randomized resource allocation by at least one random allocation parameter ensures that the MitM attack system 20 can no longer predict the scheduling process by RBS30 (e.g., allocation of time slots and / or frequencies after RRC security is established) by monitoring the operation of RBS30. If the MitM attack system 20 allocates time slots before RBS30 allocates them, the first set of allocated SFN parameters will not match the second set of SFN parameters SFN2 allocated by RBS30.
[0066] As an exemplary option to reduce the latency of the allocated time slots, RBS30 can pick a smaller value N (e.g., N=2560, reducing the latency to a maximum of 2.56s). However, this increases the probability of collisions between the first and second parameter sets SFB. Again, to further reduce this probability, RBS30 (e.g., randomizer 25 in Figure 2) can compute an additional random assignment parameter r' that is uniformly distributed over multiple random parameters, e.g., in the range of 0, ..., N'-1. This assignment parameter r' is used for the random allocation of frequency resources used in transmission.
[0067] Please note that Figure 3 shows an example of resource allocation (uplink) for dynamic grants.
[0068] The possible mechanism proposed in S3-210193, submitted to SA3-102-e, is as follows, referring to Figure 9. 1. Assume that the UE has established a connection with the real gNB through the MitM gNB. RRC security is established; that is, all RRC messages are protected from FBS. 2. In order for the UE to send an RRC message (to trigger FBS detection), the UE requests resources from the FBS according to the current RAN procedure. Assume that the set of SFN parameters assigned by the FBS is indicated by SFN1 (system frame number, subframe number, and time slot). 3. The UE triggers FBS detection by sending an RRC message. For simplicity, a null RRC message may be sent. 4. As usual, the FBS intends to forward the RRC message to the gNB. First, the FBS (fake UE) needs to request resources from the gNB. Assume that the gNB assigns a set of SFN parameters, namely SFN2, to the fake UE. Note: Generally, the SFN2 assigned by gNB varies. Depending on the system parameters (subcarrier interval), there are a total of 10,240, 20,480, or more time slots. FBS cannot predict the value of SFN2 (i.e., FBS cannot make an earlier assigned SFN1 equal to SFN2). FBS also cannot reschedule UEs after receiving SFN2 (which occurred earlier) so that SFN1=SFN2. Therefore, slots scheduled for false UEs are wasted because rescheduling UEs would exceed the time budget for FBS. 5. The FBS (fake UE) forwards the RRC message to the gNB according to the scheduled SFN2. 6. The gNB remembers the SFN2 it was assigned. 7. The UE sends the SFN1 value (assigned in step 2) in an RRC message (secured from FBS). 8. FBS (fake UE) unknowingly forwards the data to gNB. 9. The gNB compares the SFN1 value with the stored SFN2 value to determine whether FBS is present.
[0069] However, according to this mechanism, • MitM can request a scheduling request immediately after receiving message 2 (step 4). In other words, it is not necessary for MitM to wait for message 3 to be received. The MitM can monitor the current frame number of the gNB (which we will call SFN_gNB) and set its own frame number (which we will also call SFN_gNB) by slightly advancing SFN_gNB. Once this is done, the MitM can immediately send a scheduling request (SR) to the gNB as soon as it receives one from the UE. At this stage, the following considerations can be made:
[0070] A) Assuming that the resource allocation behavior of MitM and gNB is completely independent, the allocated resources (system frame number, subframe number, time slot) in SFN1 and SFN2 may coincide. This is because even with 10,240 time slots (1ms, SCS=15kHz), this does not mean that the collision probability is equal to 1 / 10240. This is because the scheduler is optimized to reduce latency, so the allocated time slots are unlikely to be far off in the future. This means that if MitM allocates a transmit slot just a little bit ahead, there is a non-negligible chance of success.
[0071] B) It can be assumed that gNB sends DCI messages in accordance with TS.38.331.
[0072] PUSCH-TimeDomainResourceAllocation ::= SEQUENCE { k2 INTEGER(0..32) OPTIONAL, -- Need S mappingType ENUMERATED {typeA, typeB}, startSymbolAndLength INTEGER (0..127) }
[0073] Here, k2 refers to the delay in the time slot from the allocation (PDCCH) to the allocated time slot (PUSCH). startSymbolAndLength(SLIV) refers to the start symbol and the number of symbols as defined in TS38.214 5.1.2.1. In other words, SLIV is the start and length indicator for time domain allocation to PDSCH.
[0074] From this perspective, the definition of SFN1 in Step 2, which includes the system frame number, subframe number, and time slot, is not entirely accurate. Furthermore, unlike 4G, 5G allows for the assignment of specific symbols in addition to time slots, so this particular structure should also include SLIV. Moreover, the definition can be extended using resources allocated in the frequency domain.
[0075] Note that SLIV takes 128 values, but encodes 14 possible symbols and various possible lengths. Ultimately, from a security standpoint (since the required length of an RRC(null) message will be known), only the start symbol matters. Therefore, assuming the SLIV value is randomized, it introduces a 1 / 14 uncertainty. Note that comparing SFN / subframe / timeslot results in an uncertainty of 1 / 33, not 1 / 10240, for example, assuming k2 is randomized. Therefore, if both k2 and SLIV are randomized in a secure way, the maximum collision probability can be 1 / (14×33)=0.002.
[0076] C) At point A, it was assumed that the resource allocation behavior of MitM and gNB is completely independent. However, an attacker may monitor / learn (or reverse engineer) the behavior of gNB. In that case, the probability of MitM picking the same SFN / subframe / time slot becomes even higher. For example, if an attacker discovers that gNB always tends to allocate SRs using specific values of k2 / SLIV under certain specific circumstances, the probability of MitM success becomes much higher, and this solution cannot prevent it. Since scheduling strategies are left to their implementation, there is no guarantee that they are unpredictable to an attacker.
[0077] D) The MitM UE can also affect the behavior of scheduled resources. For example, according to [https: / / 5g-lena.cttc.es / static / archive / K2_GC.pdf], N1 and N2 determine the processing delay on the UE side. The N2 value is transmitted to the gNB as part of the UE processing capability. This means that the characteristics of the method in Figure 9 depend on the UE processing capability. For example, if a MitM attacker can modify N2, the MitM can, for example, affect the K2 value. In this example, since N2 < k2 <= 33, if N2 is modified to be larger, this will narrow the executable range of k2, increasing the possibility that the MitM can accurately guess the assigned k2.
[0078] E) Since the MitM can request a scheduling request (step 4) immediately after receiving message 2, the following attack can also be executed by referring to Figure 10 (initial situation: The MitM has SFN_MitM that is slightly advanced from SFN_gNB, for example, by 1 time slot. For example, SFN_MitM = 11 and SFN_gNB = 10). · Step 1: The UE sends the SR to the MitM. · Step 2: The MitM sends the SR to the gNB (almost without delay). · Step 3: The gNB allocates resources very quickly and sends DCI to the MitM with a k2_gNB value for a slightly too large SFN_gNB, for example, k2_gNB = 2. · Step 4: The MitM sends the corresponding DCI message to the UE with a k2_MitM value for SFN_MitM that is smaller than k2_gNB, for example, k2_MitM = 1. · Step 5: (Since k2_MitM = 1, in the next time slot SNF_MitM = 11 + 1) the UE replies very quickly using RRC(null). · Step 6: Since k2_gNB = 2 and SFN_gNB = 10 + 2 = 12, the MitM forwards RRC(null) 2 time slots later for SFN_gNB.
[0079] This attack is illustrated in Figure 10, where squares of various shades represent their respective SFN values (system frame number, subframe, and time slot). It can be seen that the MitM's SFN clock is slightly ahead. In this configuration, since both the UE and gNB share the same SFN resources, the solution described in S3-210193, posted to SA3-102-e, does not work as claimed.
[0080] Below, we will describe several techniques that allow the solution in the embodiment shown in Figure 9 to provide better security assurance. The transmission of a DCI message from the gNB must occur after waiting for a randomized time T, and the assigned transmission parameters are for the next viable transmission symbol just after T. Thus, MitM does not know when to send the DCI message to the UE. If MitM waits until the gNB listens, MitM does not need to forward the DCI message, wait for RRC(0), and forward RRC(0). Another possible solution, in step 9 of the solution in Figure 9, is to compare not only the absolute SFN values (i.e., system frame number, subframe, time slot) but also any parameters used for resource allocation (especially if they are related to the current SFN), such as parameter k2. Note that if this is done, it is not necessary to randomize resource allocation. • (Because the definition of SFN includes only the system frame number, subframe, and time slot) the probability of accurately guessing SFN2 can be high, and therefore the probability of an attacker positioning themselves between the UE and gNB undetected is also relatively high. This can be improved as follows: 1. One option is to also use the SLIV (specifically, the start symbol) when comparing SFN1 and SFN2. This means comparing not only the system frame number, subframe number, and time slot, but also the start symbol. 2. Another option is to repeat the procedure n times, minimizing the probability of accurately predicting SFN2 each of those n times. Another option is for gNB to observe the results of the procedure from different UEs. If the procedure is positive in any of these m UEs, gNB can suspect the presence of MitM in some of the other connections.
[0081] Accordingly, according to another aspect of the present invention, an apparatus may be proposed for detecting attacks by a fake wireless device impersonating a genuine or authentic access device in a wireless network, the apparatus comprising an attack inspection unit for examining the timing of communication resources allocated by allocation and the parameters used for such allocation. The apparatus can then determine, based on the results of the inspection, the presence of a fake wireless device or an attack by said fake wireless device.
[0082] Instead of using parameters for allocation, the inspection unit can compare the absolute time between the receipt of the resource allocation message and the response message. This absolute time can be measured by an independent clock. This absolute value is related to k2 and SLIV.
[0083] Other parameters used for allocation may include, for example, a delay value between the received allocation message and the allocated resource (e.g., k2) or SLIV.
[0084] The timing of communication is absolute time (for example, referenced in one of the following: system frame number, subframe, time slot, or start symbol).
[0085] It should be noted that an attacker can use an RF repeater capable of forwarding RF signals between the UE and the base station with virtually imperceptible delay. If an attacker can do so, the proposed technique will not work. On the one hand, such an attacker would not be able to perform any useful attack actions (discarding, injecting, or modifying specific messages). However, if the technique described in this embodiment is applied at a known point in the communication interaction, an attacker will be able to construct an advanced MitM attack device as shown in Figure 11. This attack device has two main parts: an RF repeater capable of forwarding signals without delay, and a conventional MitM part consisting of a fake base station and a fake UE. The fake UE connects to the real base station, and the fake base station connects to the real UE. Between them, this MitM hardware can perform a number of actions, including modifying, injecting, or discarding messages. These two parts are managed by a MitM / RF repeater controller, which can decide whether to forward messages between the real UE and the real base station via the RF repeater or via the conventional MitM hardware. With this advanced MitM hardware, if the technique described in the first embodiment is used at a specific known point in time, for example, immediately after RRC security is activated, the attacker can use an RF repeater at that time, for example, for about one second before or after RRC security is established, and for the remaining time, the attacker can use more conventional RRC hardware.
[0086] In order to counter such sophisticated attackers, or to increase the robustness of the technique, the MitM detection technique in this embodiment, or any other embodiment of the present invention, should be used at an unknown time or an unspecified time instant. For example, the detection technique may be performed at a random time or according to a secret schedule. If this is done, the attacker will need to guess when the MitM detection technique will be used. If the attacker does not make an accurate guess and the attacker is using conventional MitM hardware (instead of an RF repeater), the MitM detection technique will be successful. This unknown time is selected by the UE in the MitM detection technique described above when the UE sends a request for resource allocation. These times may also be agreed upon in advance between the UE and the base station, for example, by distributing a schedule in a protected manner (e.g., an RRC message) and executing the protocol accordingly. This RRC message may be sent from the gNB to the UE once RRC security is established and may include or indicate when the UE will trigger the protocol.
[0087] Furthermore, this advanced MitM attack, as illustrated in Figure 11, can also be used to circumvent other MitM countermeasures if they are performed at specific known points in time. For example, if the cryptographic CRC is used only at specific known instants for the purpose of detecting MitM, it may also be possible to circumvent the cryptographic CRC technique (depending on which parameters are used to serve as input to the cryptographic CRC). Detection is triggered by the fact that cryptographic CRC verification fails if MitM is present. As before, this advanced MitM can be circumvented if such MitM countermeasures are performed at unknown points in time. For example, a UE or gNB might agree in advance on a schedule (shared in a protected manner) to activate / deactivate the cryptographic CRC accordingly. Based on the understanding that RF repeaters are likely to use omnidirectional antennas, and base stations and UEs use directional antennas or beamforming, the cryptographic CRC method could include a bit pattern indicating the number of spatial streams or antenna port numbers (in the case of spatial multiplexing) as an additional input for calculating the cryptographic CRC. This includes the index of the synchronous system block (SSB), or the inputs used by spatial multiplexing (such as training signals, pre-coding symbols, and information about channel estimation feedback).
[0088] It should be noted that the solution in the first embodiment is triggered by the UE. According to the above discussion for defeating a sophisticated attacker in Figure 10, the communication initiation point is distributed to the UE by a real base station in a protected manner. This same message can also be seen as the distribution of an on-demand MitM detection message directed to the UE. This message should contain the initiation point for a future MitM detection process. This message may also be empty, i.e., it does not trigger a MitM detection process. The purpose of such an empty message is to make it more difficult for a sophisticated attacker in Figure 10 to know when to activate the RF repeater. Whether the message is empty or an actual on-demand MitM detection message is selected by the real base station in a randomized manner.
[0089] It should be noted that when this on-demand MitM detection message is included, this first embodiment is similar to other embodiments that rely on configuration grant scheduling.
[0090] Figure 4 schematically shows the signaling and processing diagram of the FBS detection procedure according to the second embodiment. The upper part of Figure 4 above the dotted line shows the procedure without a MitM attack, and the lower part of Figure 4 below the dotted line shows the procedure with a MitM attack.
[0091] In the second embodiment, instead of requiring two RRC messages from RUE10 (e.g., steps S330 and S370 in Figure 3) to confirm the SFN value to be used, only a single RRC message is required. That is, in a single response RRC message RRC(SFN), RUE10 includes the assigned set of SFN parameters.
[0092] However, the second embodiment is still configured to achieve random or seemingly random resource allocation by the RBS30, as follows:
[0093] The top of Figure 4 shows that RUE10 replies immediately after (i.e., directly in response to) the resource allocation RA(SFN) by RBS30. Resource allocation by RBS30 is randomized by signaling or triggering it at time SFN-1 after the random latency RWT determined by RBS30 (e.g., by the randomizer 25 in Figure 2). Thus, RBS30 can verify the validity of the RRC message received from RUE10 based on its expected reception time SFN (e.g., at the immediately following system frame number (SFN)).
[0094] The lower part of Figure 4 shows the resulting effect of the presence of the MitM attack system 20. As can be read from the lower part of Figure 4, the additional delay introduced by the forwarding process of the MitM attack system 20 results in the expected RRC message E-RRC(SFN) of RUE10 not being received on time at RBS30 (i.e., at the time SFN expected by RBS30). The available RRC message A-RRC(SFN) forwarded via the MitM attack system 20 will be received by RBS30 too late, at a later time SFN+2. This can be detected at RBS30 to determine whether it is an FBS or MitM attack. In Figure 4 and other embodiments, SFN-1, SFN, SFN+1, and SFN+2 may mean specific values of the system frame number, but they may also mean, for example, a specific set of time and frequency resources for the exact same system frame number. For example, these may mean subsequent subframes or time slots, or orthogonal frequency division multiplexing (OFDM) symbols or frequency resources. Generally, the term “SFN” as used in this disclosure may refer to a system frame number, but it may also refer to a specific subframe and a specific start time slot within a frame when using a particular frequency resource. In particular, it may refer to an allocated resource block containing a large number of resource elements.
[0095] Figure 5 schematically shows a more detailed signaling and processing diagram of the FBS detection procedure according to the second embodiment in the absence of a MitM attack.
[0096] In Figure 5, the first step S510 is for RUE10 and RBS30 to establish access layer (AS) security so that RRC messages can be exchanged in a secure manner. In the next step S520 after AS security has been established, RBS30 allocates resources for the uplink to RUE10, for example, by a resource allocation of typed grant type 2. This means that the allocated resources are sent to RUE10 in secure RRC messages.
[0097] Next, RBS30 (for example, the timer function of randomizer 25 in Figure 2) randomizes the resource allocation process by generating and applying a random latency (RWT). After this latency RWT, RBS30 activates the allocated resources by sending a DCI message in step S530. Furthermore, RBS30 starts a timer to determine the maximum waiting time until it has received a valid response from RUE10. Upon receiving the DCI message sent by RBS30 in step S530, RUE10 immediately (i.e., directly) replies in step 540 using a protected message containing other relevant information related to the received DCI message and / or resource allocation or timing (in particular the time allocated for the first reply message (shown as SFN2), the entire allocated resource, and / or the RNTI value used to scramble the DCI message). RBS30 then only needs to check in step S540 whether this reply message contains the correct information and whether it was received before the execution timer for the maximum waiting time expired.
[0098] Figure 6 schematically shows a more detailed signaling and processing diagram of the FBS detection procedure according to the second embodiment in the case of a MitM attack. Other information included in the reply message in step 540 is, for example, the RNTI value used to scramble the DCI message, the timing advance of the base station that allocated / triggered the semi-persistent schedule / uplink grant, and / or the SFN on which the semi-persistent schedule / uplink grant was received.
[0099] As can be seen from Figure 6, all messages are slightly delayed due to the processing time introduced by the MitM attack system 20. If the FBS23 of the MitM attack system sends the first DCI message earlier in S630 after security is established in step S610 and secure resources are allocated in step 620, the MitM attack system 20 can cache the response with resources including time SFN1 from RUE10 received in step S640, and prepare for the time when the second DCI message arrives from RBS30 in step 650. Therefore, the MitM attack system 20 can send the cached response with resources including time SFN1 to RBS30 in step S670. However, the content of the response (response including time SFN1) received in RBS30 after the normal delay (ND) before the expiration of the timer for maximum latency will be incorrect (indicated as "X1" in Figure 6).
[0100] Otherwise, if the FBS23 of the MitM attack system 20 waits in step S650 until it receives a second DCI message from the RBS30, and then forwards it in step S660, the response with resources including SFN2, received from RUE10 in step S680 and forwarded to RBS30 in step S690, will arrive too late because it includes the delay (MitMD) added by the MitM attack system 20, i.e., it will arrive after the timer for maximum latency in RBS30 has expired (indicated by "X2" in Figure 6).
[0101] Therefore, randomized resource allocation is achieved by introducing a randomized latency (RWT) from the sending of a first message with allocated resources by RBS30 in step S520 / S620 to the sending of a second message that activates the allocated resources by RBS30 in step S530 / S650. Because the time is randomized, the MitM attack system 20 is unable to monitor the expected behavior of RBS30 when sending these two messages. Since the MitM attack system 20 cannot derive a fixed delay time (e.g., 20ms) after sending the first message, it cannot set the SFN clock of the MitM attack system 20 to be faster by the derived amount (e.g., 20ms).
[0102] By introducing randomized latency, communication between RUE10 and RBS30 may be interrupted for a certain period of time. For example, the latency may be randomized over a time range long enough to prevent the MitM attack system 20 from accurately predicting this time.
[0103] It should be noted that the MitM system may attempt to correct the timing advance by delaying the message from its FUE21 to the RBS30. In a 4G system, this can mean a difference of up to 1282 × 0.52 μs = 0.66 ms, which corresponds to a distance of approximately 100 km. However, in 4G / 5G systems, cells may be sized to be much smaller, in particular to be small cells typically limited to a few hundred meters. Thus, in these cells, the maximum feasible timing advance is limited to 0.0066 ms (1 / 100). If the RBS30 detects a much larger timing advance in this embodiment or other embodiments, this is a direct indicator of the presence of the MitM system 20. Since the timing advance value is directly related to the distance between RUE10 and the RBS30, for larger cells, the RBS30 may request the location of RUE10 as a way to determine whether the timing advance is correct or not. Furthermore, it should be noted that if the MitM system 20 is located between RUE10 and RBS30, it is highly likely that the MitM system 20 will need to receive the entire radio frame before it can forward. If this is the case, it is better to arrange the message using a subcarrier spacing frequency (e.g., 15kHz) and several symbols (e.g., seven symbols). This has been verified to result in a latency of 1.071ms, and therefore, even if the timing advance value is corrected to its maximum of 0.66ms, it is still small compared to the processing time of the data packet itself and cannot hide the presence of the MitM system 20.
[0104] In addition to the considerations in the previous paragraph, the following exemplary countermeasures can be introduced to improve the robustness of the proposed solution. 1. The RBS30 sends a waiting time in a secure RRC message, causing the RRC10 to generate a false protected (RRC) message during this waiting time. This prevents the MitM system 20 from accurately inferring which messages are involved in the procedure and which messages should be manipulated. 2. A very precise time alignment is achieved between RBS30 and RUE10 using an initial RRC message. The secure RRC message from RBS30 may include, as part of the encrypted RRC message, the SFN value that RBS30 sends the RRC message to RUE10, the resources used for its transmission (subframe, slot, frequency), and the timing advance calculated by RBS30 for RUE10. Therefore, FBS23 must send this message to RUE10 using the exact same SFN and resources, as well as the exact same timing advance as RBS30. If, during the waiting period, the SFN value is skipped slightly, the timing advance is significantly altered (e.g., in comparison to the UE's movement / velocity), and / or the second DCI message is not received at the exact correct time, RUE10 may signal an error in its reply message. 3. The latest timing advance in the payload is included in the response message in step S540 of Figure 5 to ensure that the timing advance matches the current RBS timing advance. 4. Prevent RUE10 from retransmitting in the event of a packet failure when sending a reply message. If a packet transmission failure is detected, the protocol should time out, and RBS30 may restart the process to detect and avoid a MitM. 5. If the message is not properly received, RBS30 prevents retransmitting the message in step S530 of Figure 5. If a packet transmission failure is detected, the protocol should time out, and RBS30 may restart the process to detect and avoid MitM. 6. (For example, during a random time interval, FBS23 may be attempting to get the correct message from RUE10 at the correct time,) If RUE notices in step S530 of Figure 5 that there are many messages within a short time frame to activate the set grant schedule, RUE10 may either disconnect from RBS30 and / or notify RBS30 of suspected activity through protected messages. 7. The UE and / or RBS in the vicinity of the RUE are instructed to send a (narrowband) signal at a very low frequency with maximum transmit power using omnidirectional antenna transmission (according to the latest location estimate for the RUE obtained from the core network's location service, or according to the latest distance measurement to the RUE, e.g., round-trip time measurement). This is a narrowband pulse (similar to, for example, a scheduling request (SR)), but in some cases, multiple bits are encoded from the current SFN value or real-time clock to signal the current time for use by the RBS and RUE. The RBS, RAN, or core network to which the UE is connected instructs other nearby base stations (possibly from different operators) to synchronize their clocks and / or send the same signal. The timing of this signal may follow a configuration grant schedule sent from the RBS to the RUE via a secure RRC message. If the RUE sends a signal (for example, to send some bits of its SFN value or a duplicate portion of a previously sent RRC message), the configuration grant schedule is extended with a field indicating transmit power, which takes precedence over any transmit power control that may be received from the MitM. The RBS, RAN, or core network to which the RUE is connected instructs other nearby base stations (possibly from different operators) to listen for this signal. Because this signal travels along very long distances, it may be received directly by one of the genuine base stations. If the MitM repeats or manipulates such a signal, this may be detected by the RUE or one or more base stations that share information with each other. Furthermore, these messages can be protected if they refer to one-to-one communication between the RUE and the RBS. Messages sent by the RBS can also be signed to ensure source authentication.
[0105] In the second embodiment, it is necessary to consider the minimum delay between messages in steps S530 and S540, i.e., the minimum delay between DCI transmissions on the PDCCH channel and the corresponding PUSCH channel. Note that this consideration also applies to other embodiments, e.g., the first embodiment. That is, the minimum delay between a schedulable PDCCH and PUSCH is 0.375 ms for a subcarrier interval (SCS) of 120 kHz when the default time-domain resource allocation table is used, and 1 ms for 15 kHz.
[0106] When considering the delay between PDCCH and PUSCH, it should be as small as possible so that the MitM system 20 cannot hide itself. Assuming that the MitM system 20 requires approximately 500 μs for packet processing, the total processing time brought in by the MitM system 20 will be 500 μs for message transfer in step S530 and 500 μs for message transfer in step S540. In addition to these processing times, RUE 10 will bring in some processing time. Successful MitM detection can be achieved by forcing the delay between PDCCH and PUSCH to be less than 1 ms. In practice, this means that only row indexes 0-7 of the default table (see 6.1.2.1.1-2 in TS 38.214-g30) are allowed for the entire SCS configuration. If the table is customized and sent by RBS, the maximum delay should be less than 1 ms.
[0107] For dynamic scheduling and configuration grant type 2, DCI messages (Clause 7.3 of TS 38.212-g10) are used to carry the control information necessary for scheduling uplink resources. For scheduling resources for uplink channels (PUSCH), the DCI format is 0_0, 0_1, and 0_2. Time-domain resource alignment may be used as a parameter. Details of this 4-bit field and resource allocation in the time domain are further described in Clause 6.1.2.1 of TS 38.214-g30. This field provides an index for the time-domain resource allocation table. The time-domain resource allocation table may be pre-configured or shared via the information element (IE) push-TimeDomainResourceAllocation (Clause 6.3.2 of TS 38.331-g20) in the RRC message pushConfigCommon (sent via SIB1 or dedicated RRC signaling) or push-Config (sent via dedicated RRC signaling). The applicable tables for each case are described in table 6.1.2.1.1-1 in TS 38.214. The default table is described in 6.1.2.1.1-2 of TS 38.214-g30, and in the case of the default table, K2 is always greater than 0. When the table is sent by RBS30, it is propagated in IE push-TimeDomainResourceAllocation, which consists of the following:
[0108] PUSCH-TimeDomainResourceAllocation ::= SEQUENCE { k2 INTEGER(0..32) OPTIONAL, -- Need S mappingType ENUMERATED {typeA, typeB}, startSymbolAndLength INTEGER (0..127) }
[0109] The above data representation, combined with the NR numerology described in Table 4.3.2-1 of TS 38.211, yields the following results. Regardless of the time domain resource allocation table used (default or sent by RBS30), any PUSCH scheduling will occur at least 32ms after the DCI message sent via PDCCH. The minimum delay between PDCCH and PUSCH that can be scheduled when the default time-domain resource allocation table is used is 0.375 ms for a 120 kHz SCS. When 15 kHz is used, the minimum delay is 1 ms. This can be quite different if the RBS30 sends its own table, but the RBS30 may be aware of what that means.
[0110] Taking into account the above considerations and the discussion regarding timing advance, the second or other embodiment involves an SCS of 15kHz with a minimum delay of 1ms.
[0111] The following describes a third embodiment. Unlike the above embodiment, in which RBS10 is required to respond immediately to resource allocation messages, the third embodiment does not require an immediate response from RUE10.
[0112] Figure 7 schematically shows the signaling and processing diagram of the FBS detection procedure according to the third embodiment. Here again, the upper part of Figure 7 above the dotted line shows the procedure without a MitM attack, and the lower part of Figure 7 below the dotted line shows the procedure with a MitM attack.
[0113] The top of Figure 7 shows the operation in the absence of a MitM attacker, where the RRC message is used for resource allocation. RUE10 must wait for the required time (e.g., time domain offset) and then reply with a protected message with the allocated resources. The bottom of Figure 7 shows how the solution allows RBS30 to detect the MitM attack system 20 because the expected message is received later than expected.
[0114] In the example in Figure 7, a configuration grant type 1 scheduling is used. However, the same idea can be applied to other scheduling methods, provided that an attacker cannot learn about the allocated resources. For example, allocated resources could be exchanged in a confidential manner, such as by applying encryption.
[0115] In a third embodiment, the proposed randomization of resource allocation can be achieved by adapting RBS30 to distribute randomized allocated resources in a secure manner, and subsequently monitor that RUE10 is not sending data on other resources (e.g., time and / or frequency) and that RUE10 is sending predetermined messages on the allocated resources (e.g., time and / or frequency).
[0116] In 5G systems, secure exchange of scheduling information is achieved by transmitting scheduling over the Physical Downlink Control Channel (PDCCH) in all cases except for Uplink (UL) Setting Grants (CG) (Types 1 and 2), which are encrypted and sent in RRC messages. In UL CG Type 2, the schedule is activated using DCI messages. Information exchanged via the PDCCH is scrambled according to the scrambling logic for the PDCCH as defined in Section 7.3.2.3 of the 3GPP® specification TS 38.211. The logic for generating pseudo-random sequences (i.e., the gold code) is described in Section 5.2.1 of the same specification.
[0117] Because secure data exchange is required, one example of this might be the use of an uplink configuration grant schedule type 1 distributed securely in an RRC message.
[0118] As shown in Figure 7, the RRC message RRC(tDO,tDA) sent from RBS30 to RUE10 allocates resource allocation fields for the time domain offset tDO and the time domain allocation tDA.
[0119] In response to receiving the RRC message RRC(tDO,tDA), RUE10 activates the configuration grant after the expiration of the time-domain offset tDO set by this parameter by sending a secure uplink message SUM(tDO,tDA) to RBS10.
[0120] The time-domain offset field gives the time-domain offset tDO for SFN=0.
[0121] Furthermore, the value "m" for the time domain allocation tDA in the time domain allocation field points to, for example, row or column number "m+1" in at least one resource allocation lookup table provided by the randomizer 25 in Figure 2.
[0122] Specific rules may be used to determine which resource allocation lookup table should be used.
[0123] With that type of resource allocation, once the network uses RRC to configure time-domain resources, the allocation can only be changed by sending an RRC reset message to RUE10 to reset the parameters.
[0124] Further details regarding the configuration of grant schedules type 1 and type 2 using RRC signaling can be found in section 5.8.3 of the 3GPP® specification TS 38.321.
[0125] Further details regarding the data structure of the configuration parameters involved in the third embodiment can be found in the 3GPP® specification TS 38.331. In particular, this information is encoded in an rrc-ConfiguredUplinkGrant structure where tDO corresponds to the timeDomainOffset parameter and tDA corresponds to the timeDomainAllocation parameter. Note that other fields in this structure, which are not described here, enable similar randomization techniques, such as the frequencyHoppingOffset parameter or the frequencyDomainAllocation parameter.
[0126] Further details about timeDomainAllocation can be found in TS 38.212-7.3.1 and TS 38.214-6.1.2.1.
[0127] Using the mechanism of the third embodiment, the MitM attack system 20 cannot predict when RUE 10 will transmit data, as long as the allocated resources follow a pattern that appears random. This is achieved, for example, by adapting RBS 30 to select a random time-domain offset tDO that follows a uniform random distribution. Other parameters, such as the time-domain allocation tDA or frequency-domain allocation fDA, can also be randomized in a similar manner.
[0128] If the time domain offset tDO is randomized, RUE10 sends a predetermined reply message SUM(tDO,tDA) at time SFN=tDO. RBS30 can then monitor whether it receives a message from RUE10 before or after the time domain offset tDO, and can verify that RUE10 only sends the predetermined reply message SUM(tDO,tDA) at the time domain offset.
[0129] As shown in the upper part of Figure 7, the RBS30 can verify that no transmission occurs during the time-domain offset tDO ("CNT" in the upper part of Figure 7), that the reply message SUM(tDO,tDA) is received at the correct time (and frequency) ("CCT" in Figure 7), and that no transmission occurs after the correct time ("CNT" in the lower part of Figure 7).
[0130] In the upper part of Figure 7, where there is no MitM attack, all checks are positive (thumbs up) because the MitM attack system 20 is not involved.
[0131] However, in the lower part of Figure 7, the involvement of the MitM attack system 20 introduces an additional delay, causing the reply message SUM(tDO,tDA) from RUE10 to be received at a later time in RBS30. As a result, RBS30's first check for no transmission during the time domain offset tDO (the upper part of Figure 7, labeled "CNT") is positive (thumbs up), while the second check for the correct reception time (the "CCT" in Figure 7) and the third check for no transmission after the correct reception time (the lower part of Figure 7, labeled "CNT") are both negative (thumbs down). Consequently, RBS10 detects the RBS or MitM attack and applies corrective or mitigating measures.
[0132] This procedure (i.e., the MitM detection and avoidance phase) may be repeated multiple times immediately after security is established or at different times to ensure that no MitM attack system exists. This procedure may also be repeated during migration (and when a handover is required).
[0133] To further enhance security, RUE10 can transmit specific content within its assigned time slot (SFN=tDO). For example, RUE10 can transmit a resource allocated in a secure manner (e.g., confidentially and with integrity protected), specifically the time domain offset tDO. Thus, RBS30 verifies not only that RUE10 transmits within a randomly allocated time / frequency resource, but also that within that allocated time / frequency resource, the allocated resource is confirmed by the content of the received message. Other information that may be exchanged includes a nonce (e.g., any (random or pseudo-random) number) that has been previously received from the base station and whose value is unique to the user resource.
[0134] This simple check in RBS30 may be performed once or multiple times after security is established or after a handover when RUE10 connects to the network.
[0135] In one example, the third embodiment can be made more resilient to FBS or MitM attacks by including, in addition to the time domain offset, a time difference between the reception of the first message in RUE10 in Figure 7 and the transmission of the second message from RUE10 in Figure 7 within the reply from RUE10. This time difference is calculated by RUE10, for example, by calculating the time difference between the time domain offset and the current SFN, or by starting an independent timer (e.g., counting CPU cycles) when the first message is received from the base station and stopping the timer when the second message is sent. The transmission time can be measured in seconds (milliseconds, microseconds) by multiplying the number of CPU cycles by the CPU clock time. If this is done, subsequent FBS or MitM attacks will be more difficult. The MitM attack system 20 attempts to shift the timing of its SFN clock slightly ahead of the RBS30's SFN clock so that RUE10 can reply to the MitM attack system 20 earlier, and then forward the reply to RBS30 at the correct time. However, if the reply includes a time difference between the two messages, RBS30 can detect that RUE10 is operating under a different SFN clock.
[0136] This technique, which measures the time difference between receiving the first message (for resource allocation) and sending the second message (acknowledging this resource allocation), can also be applied when the time-domain offset is fixed and not randomized. This is because the MitM system 20 would introduce too much computation / communication overhead, causing the response message (the second message) to arrive too late. For example, if the message is transmitted with a subcarrier interval of 15 kHz, the transmission of OFDM symbols takes 66.67 ms. If seven symbols are allocated for the transmission of the message, the transmission of the message (on the physical layer) takes 0.467 ms. If this is done in both the UL and DL directions, the MitM system 20 would incur a delay of almost 1 ms without considering any computational delay. If RBS30 performs resource allocation on a given RUE10 at the beginning of a slot (including 14 OFDM symbols) so that data transmission from RUE10 to RBS30 occurs at the beginning of the subsequent slot (i.e., 1 ms later), the presence of the MitM system 20 prevents this protocol from functioning as expected. Note that the message performing resource allocation is protected (encrypted / integrity protected) so that the MitM system 20 cannot send a spoofed message earlier. Furthermore, the protocol may take into account transmission delays, and considerations regarding timing advances also apply.
[0137] Furthermore, the time difference between the reception of the first message and the transmission of the second message at RUE10 may be smaller than the time difference between the time the first message is sent from RBS30 and the time the second message is received at RBS30. This time difference, which should be corrected by RBS30, is due to the message propagation time, which is equal to twice the propagation time from RBS to RUE. In other words, this is related to timing advance. In this regard, the same considerations as in the second embodiment are applied to ensure that this third embodiment is resilient to potential timing advance operations.
[0138] To enhance security in the third embodiment, it should be noted that RBS30 may also apply an additional random delay before sending the initial message shown in Figure 7, as done in the second embodiment.
[0139] Figure 8 schematically shows the signaling and processing diagrams of an example of the FBS detection procedure according to the third embodiment.
[0140] In this embodiment, a setting grant scheduling type 1 is used, in which the first message from RBS30 to RUE10 in step S810 distributes a setting schedule with a random time-domain offset tDO and a period in an RRC message. Furthermore, RBS30 activates the timer operation according to the time-domain offset tDO. The timer duration is slightly longer than the time-domain offset tDO but shorter than the time-domain offset plus the period.
[0141] In response to receiving the first message, RUE10 sets and activates a timer operation in step 820 to wait for the expiration of a random time-domain offset tDO, which has been pre-calculated by RBS30 and distributed to RUE10 in the first message. Furthermore, RUE10 monitors the physical downlink control channel (PDCCH) for any further messages to be received.
[0142] After the time-domain offset tDO expires, RUE10 sends a second message in step S830a, a secure message (e.g., an RRC message sent over a physical uplink shared channel (PUSCH)) that includes the received time-domain offset tDO and the time difference between the receipt of the first message and the transmission of the second message. RBS30 includes logic (e.g., detector unit 22 in Figure 2) for detecting FBS or MitM attacks in the RRC layer, including a predefined timer (set to the value of the time-domain offset tDO). The logic of RBS30 further checks whether the message was received before the timer expires. If the message has arrived, the logic of RBS30 checks whether the received message includes the correct value of the time-domain offset tDO and the correct time difference between the receipt of the first message in step S810 and the transmission of the second message in step S830a. If the logic of RBS30 cannot verify the correctness of this information, RBS30 determines that an FBS or MitM attack has occurred. Even if RBS30 has not received any messages, RBS30 will still determine the presence of an FBS or MitM attack.
[0143] The period received in step S810 determines the time frame during which RUE10 can send further messages in subsequent steps S830b, S830c, etc. Further details regarding the period, which depends on the set subcarrier interval, can be found in TS38.321 and TS 38.331 of the 3GPP® specifications.
[0144] Finally, in step S840, RBS30 responds to RUE10 with downlink control information (DCI) transmitted via the PDCCH channel, including cell-based radio network temporary identification information (C-RNTI), and a configuration schedule that may be overwritten based on the response received from RUE10.
[0145] The following describes a fourth embodiment in which randomized schedules are exchanged in a confidential manner.
[0146] In the fourth embodiment, RBS30 sends scheduled resources to RUE10 in an encrypted manner so that only RBS30 and RUE10 know which time / frequency resources should be used for transmitting / receiving data. Furthermore, resource allocation is randomized in such a way that an attacker cannot easily predict the time slot or frequency range allocated to RUE10.
[0147] For this purpose, RBS30 applies a secure random generator to obtain a random seed. This seed can then be used to derive a pseudorandom sequence in a secure manner, for example, using SHAKE, which is part of SHA3. Alternatively, any secure pseudorandom number generator can be used. Given this pseudorandom sequence prs (where prs[n] represents the nth bit in the pseudorandom sequence), and assuming (as an example) RBS30 has two potential time slots {s_0, s_1} for RUI10, RBS30 allocates s_prs[n] at time n. RBS30 can obtain the seed and send it to RUE10 along with {s_0, s_1} in an encrypted and, at choice, integrity-protected manner. RUE10 will then use s_prs[n] at time n. An alternative to this is for RBS30 to directly compute the pseudorandom sequence prs and send it to the UE in a protected manner. Next, at time (or transmission number) n, RUE10 and RBS30 will use s_prs[n]. The advantage of this alternative is that RUE does not require any additional extensions to derive a pseudo-random sequence from the seed.
[0148] In this example of the fourth embodiment, the MitM attack system 20 may be able to observe that RUE 10 uses both time slots s0 and s1, but the MitM attack system 20 is unaware of the slots allocated to RUE 10 by RBS 30 at a particular time n. The MitM attack system 20 can only transfer the same information to both time slots s0 and s1, which is easily monitored and detected by RBS 30. Reuse of time slots s0 and s1 between users will also result in reception and decryption errors in RBS 30.
[0149] When configuration grant scheduling is used, RRC messages can be used to exchange this information in a secure manner. Since dynamic scheduling does not use encryption during resource allocation, applying this embodiment to dynamic scheduling requires that these messages be encrypted.
[0150] This embodiment has described an uplink communication path in which MitM is detected by RBS30. However, this embodiment and other embodiments are also applicable to downlink communication paths in which the role of detecting MitM is performed by RUE. In particular, RUE determines a pseudo-random sequence prs and sends it to RBS in a protected message, e.g., RRC. Triggered by this message, RBS allocates transmit resources to the downlink using a semi-persistent schedule, for example, two time slots {s_0, s_1} may be used. RBS then transmits at time n using s_prs[n]. RUE is responsible for detecting the presence of MitM by checking whether the transmission was properly performed in the time slot s_prs[n] allocated at time n.
[0151] According to the fifth embodiment, randomized radio network temporary identification information (RNTI) is used to randomize resource allocation in a communication link.
[0152] RNTI is an n-bit identifier, for example, n=16, used to identify the communication link between RUE10 and RBS30. Its value depends on the type of RNTI and remains relatively stable for a given purpose.
[0153] For example, there are many types of RNTIs depending on the purpose, such as paging or broadcasting, or the type of resource allocation. Examples include SI-RNTI (System Information RNTI), P-RNTI (Paging RNTI), RA-RNTI (Random Access RNTI), TC-RNTI (Temporary Cell RNTI), C-RNTI (Cell RNTI), MCS-C-RNTI (Modulation Coding Scheme Cell RNTI), CS-RNTI (Setting Scheduling RNTI), TPC-PUCCH-RNTI (Transmit Power Control-PUCCH-RNTI), TPC-PUSCH-RNTI (Transmit Power Control-PUSCH-RNTI), TPC-SRS-RNTI (Transmit Power Control-Sounding Reference Signal-RNTI), INT-RNTI (Interrupt RNTI), SFI-RNTI (Slot Format Indicator RNTI), and SP-CSI-RNTI (Semi-Persistent CSI RNTI).
[0154] According to the fifth embodiment, the RNTI used on the communication link between RUE10 and RBS30 during communication changes with each assigned transmission in a randomized manner known only to RUE10 and RBS30. The key idea of this embodiment is that a different network identifier is assigned for each different time unit, e.g., subframe or slot, known only to RUE10 and RBS30. If the MitM system 20, which is in the middle, takes even a short time to transfer the message on the UL / DL transmission path, the validity of the network identifier expires. In order to successfully transfer the message further, the MitM system 20 needs to know the next identifier in advance, but it is released only when it is on demand by RUE10 or assigned by RBS30. This can be achieved by the following alternative options.
[0155] According to the first option, RBS30 prepares a list of random RNTIs and sends it to RUE10 in a confidential manner. Note that the list is defined as a data type representing a countable number of ordered values. Each value in the list / data type contains some timing / expiration information. Then, during communication, RUE10 uses a different RNTI (selected from the received RNTI list) in each subsequent assigned transmission. If the receiver receives a message with an incorrect RNTI, for example, an RNTI before the one in the list, this provides an indicator of the presence of the MitM system 20, which can be used to detect and avoid its presence.
[0156] The first option can be implemented after access layer security has been established by distributing a list of RNTIs with N entries over a secure channel, such as an RRC. This RNTI list can be used, for example, with dynamic scheduling using C-RNTI. In this scenario, if RUE10 receives a DCI message for dynamic resource allocation using its C-RNTI, and RUE10 has a non-empty RNTI list, RUE10 will use the following elements from the RNTI list instead of its C-RNTI when sending. Alternatively, RBS30 will use the following elements from RUE10's RNTI list when sending a DCI message. In this way, only the target RUE10 knows which resources have been allocated to them, and only the target RUE10 can reply on these allocated resources. Note that RNTI may not be explicitly sent and may be used to scramble a message or the cyclic redundancy code (CRC) of a message (e.g., TS 38212-7.3.1.1).
[0157] According to the second option, RBS30 generates a seed and sends it to RUE10 in a confidential manner. The seed is then used to derive a pseudorandom RNTI for each transmission. The RNTI can be derived by a pseudorandom number generation function. The advantage of the second option is that it is a more compact method.
[0158] According to the third option, RBS30 prepares two lists of RNTI and sends them to RUE10 in a confidential manner. Then, during communication, RBS30 uses the elements of the first list of RNTI to allocate resources to RUE10, and RUE10 uses the elements of the second list of RNTI for each transmission.
[0159] The third option is similar to the first option, but the list of RNTIs may be distributed, for example, in an RRC message. The DCI message will use the RNTIs from the first list of RNTIs. Then, only the target RUE10 knows which UE these resources were allocated to. When RUE10 replies, it replies with the next RNTI listed in the second list of RNTIs, so that only RBS30 knows which UE the data transmission belongs to. The two lists help minimize the risk of downlink and uplink communications being mismatched. MitM knows which RNTIs were used for resource allocation on the downlink, but MitM does not know which RNTIs will be used for transmissions on the uplink. The result of this structure is that a MitM attack system 20 between RUE10 and RBS30 does not know (i.e., cannot predict) how to trigger a data transmission from RUE10 because the FBS23 of the MitM attack system 20 does not know the UE's list of RNTIs. FBS23 also doesn't know which RNTI the UE is using on the subsequent communication link, meaning FBS23 doesn't know how to forward / manipulate the message, or it's too late to do so. Note that in this case, the resources allocated to RUE10 may remain stable (e.g., periodic time slot, same frequency range) while the RNTI changes. The MitM attack system 20 may still attempt to delay / cached the data packets of the communication and retransmit them within these same periodic time slots and frequency ranges. However, in this case, the RNTI used (from the RNTI list) will also be delayed, which also gives RBS30 a hint about the presence of an FBS or MitM attack.
[0160] If the solution by the third option of the fifth embodiment is used, RBS30 distributes two lists of RNTI to several UEs and observes whether the communication link is functioning as before or whether the communication link is interrupted. In the latter case, it indicates the presence of an FBS or MitM attack, and RBS30 can notify RUE10 and / or the network. This is a decision for RUE10 to either maintain communication at the risk of a potential FBS or MitM attack, or connect to a different RBS with the hope that there is no MitM attack system located between them.
[0161] In summary, the idea in this embodiment is to ensure that a false base station cannot easily manipulate the transmissions of the RUE and RBS. To this end, it is proposed to use a predetermined set of RNTIs for scrambling subsequent messages between the RUE and RBS by securely sending a list of at least RNTIs (or a seed for generating it) to the RUE in advance using a protected (RRC) message from the RBS to the RUE. Along with sending such a list, the RUE is given a policy (e.g., a pre-configured policy, or a policy contained in / triggered by a secure message containing the sequence or a separate secure message) to accept subsequent messages only if they are scrambled with RNTIs that exactly match the RNTIs from the sequence of RNTI values sent securely in advance, and to stop the procedure because it is risky to continue considering the possibility that the message may be corrupted. The RNTIs in the list should be used at predetermined time instants or sequentially in assigned transmit / receive slots. Naturally, this only works when the signal quality is very good, as scrambling affects the CRC. Therefore, this policy is conditional on signal quality (e.g., RSRP) exceeding a specific threshold and only during a dedicated time interval for inspecting for false base stations. Normally, if the CRC or RNTI does not match, the UE will discard the message or request a retransmission. This should not happen during the time interval for detecting false base stations.
[0162] The FBS attempts to either simply forward a message scrambled with an RNTI from the RBS, or manipulate that message (by determining the RNTI from the incoming message and creating a new message with a new CRC scrambled with the determined RNTI), but the timing of that forwarded / manipulated message would be too late, especially considering both uplink and downlink paths. By using the above policy during a dedicated interval for detecting false base stations, it prevents the MitM from forwarding the message or sending a message in advance to trigger the UE, causing it to respond or send a message before the RBS has a chance to determine which RNTI value to use next. Given that only 65536 values are possible for a typical RNTI value, the FBS may, by chance, send a message scrambled with the correct RNTI to the RUE. Using a sequence with multiple valid RNTI values, and requiring multiple messages during the interval message exchange to detect a false base station (for example, by sending several false messages after the initial RRC message mentioned above), makes it much more difficult for FBS to correctly infer each subsequent RNTI value.
[0163] In summary, in cellular or other wireless networks, FBS devices behave as appropriate base stations managed by the network operator, aiming to attract wireless communication devices with different objectives, including FBS or MitM attacks. To detect and / or avoid such FBS or MitM attacks, it is proposed to randomize resource allocation and, in RBS, check that wireless communication devices (e.g., UEs) are not transmitting other resources and are only transmitting their allocated resources.
[0164] Although the present invention has been illustrated and described in detail in the drawings and the foregoing description, such illustrations and descriptions are for illustrative purposes only and should not be considered limiting. The present invention is not limited to the embodiments disclosed.
[0165] The above embodiment of the MitM detection and avoidance procedure can be repeated multiple times immediately after security is established or at different times to ensure that no MitM attack system exists. This procedure can also be repeated while moving (and when a handover is required). In particular, the proposed procedure can be initiated after a fixed event in the RBS once a secure connection with the RUE is established. The procedure can be initiated after receiving the trigger_MitM_detection_and_avoidance message from the RUE. This applies to the first to third embodiments. The first embodiment is similar to a dynamic grant configuration, the second embodiment is similar to a configuration grant (CG) type 2, and the third embodiment is similar to a configuration grant (CG) type 1.
[0166] The trigger_MitM_detection_and_avoidance message is an RRC protection message or scheduling request (SR) transmitted using PUCCH format 0 or 1, as described in clause 9.2.4 of TS 32.213-g10. Two options are intended to inform the RBS that this SR will trigger the start of the MitM detection phase. First, the message may contain one bit to signal the start of the MitM detection phase, on which the RBS can initiate a process for CG type 2, CG type 1, or dynamic grant. Second, the first SR after RRC security mode completion or any other well-known exchange between the RBS and RUE after communication has been protected (>RRC security mode completed) may be used to signal the start of the MitM detection phase, on which the RBS can initiate a process for CG type 2, CG type 1, or dynamic grant.
[0167] Note that the following existing specifications limit the maximum random delay applicable after receiving a trigger_MitM_detection_and_avoidance message when its type is a Scheduling Request (SR). In particular, if a RUE does not receive a grant from an RBS, the RUE is configured to periodically retransmit the SR multiple times to sr-TransMax (a field defined as part of IE SchedulingRequestConfig in TS 38.331). This period is defined by the field periodityAndOffset as part of IE SchedulingRequestResourceConfig. The maximum period is specified in TS 38.331 and clause 9.2.4 of TS 32.213-g10. Considering NR numerology, the maximum random delay under the current standard is 80ms. This random delay is not large enough when using SR messages, and this affects the likelihood that the MitM system can accurately estimate the allocated resources. If this likelihood is too high, the MitM detection and avoidance procedures in any of the above embodiments may be repeated multiple times until the likelihood of the MitM system making an accurate prediction becomes sufficiently low.
[0168] In some solutions used to detect fake base stations, public-key cryptography is applied to ensure source authentication. In these solutions, the RBS or a network function in the core network signs the RBS system information. This means that the RUE has knowledge of the public key of either the RBS or the network function. This public key may be used by the RUE to protect a symmetric key K that may be shared with the RBS in the trigger_MitM_detection_and_avoidance message. This trigger_MitM_detection_and_avoidance message may be sent by the RUE after it has obtained the base station's MIB and SIB1 and verified their digital signatures.
[0169] The solutions of the above embodiments can be combined.
[0170] Beyond its primary objective of detecting and evading MitM attacks, the proposed techniques may find other applications. For example, the techniques in general, and in particular the fourth and fifth embodiments, can be used to make it more difficult for outsiders to track a UE. In particular, it prevents tracking a UE using other signals that are sent multiple times at regular intervals, such as positioning signals or sounding reference signals from the Uu / uplink interface or PC5 / sidelink interface for performing ranging or positioning, or ProSe discovery messages via PC5 / sidelink. Since tracking a device is generally considered a violation of privacy, preventing tracking can be valuable in certain applications. Generally, any active transmitter, not just a UE, can be located using two or more receivers with directional antennas at known locations. The location can be obtained by measuring the direction of each receiver to the transmitter. An attacker who wishes to track a particular transmitter (or UE) can do so using the techniques described above, but only if the attacker can determine which of the many transmissions in its range are made by the same transmitter as the one to be tracked.
[0171] If an attacker can for any reason obtain the transmission schedule or identifier of a particular UE, the attacker can determine which of the many transmissions it receives are from the same UE. By performing direction finding using two or more receivers on messages transmitted on the UE's known transmission schedule, the attacker can track the UE. Due to the reasons of the proposed techniques (specifically (1) by randomizing the transmission schedule in the fourth embodiment and (2) by applying randomized identifiers in the fifth embodiment), and because the schedule / identifier is transmitted over a secure encrypted channel, it is at least more difficult, or even impossible, for an attacker to know or simply guess the UE's transmission schedule / identifier. For best protection, the fourth and fifth embodiments are adapted so that all transmission schedules are sent to the UE in an encrypted and randomized form after the establishment of a secure encrypted channel between the RBS and the UE. The transmission schedule defines resources scheduled for uplink transmissions via the Uu interface and / or resources scheduled for sidelink transmissions via the PC5 interface (e.g., through a semi-persistent schedule / resource pool or as configuration / dynamic grants). These transmission schedules are typically sent to the UE by the access device (e.g., base station) via RRC, for example. In the case of sidelinks, these transmission schedules are sent to two or more UEs involved in the sidelink communication. For Mode 1 resource allocation in sidelinks, this is typically done through a configuration / dynamic grant specified in 3GPP® TS 38.331 (e.g., via RRC / DCI), and for Mode 2 resource allocation (where the UE may randomly select from a configuration pool of resources), this is typically done by sending a pool of resources indicated by sl-TxPoolNormal or sl-TxPoolExceptional as defined in TS 38.321.Furthermore, in the case of sidelink / PC5, the transmit schedule is also sent from one sidelink UE to another sidelink UE or negotiated between two sidelink UEs. In the case of mode 2 resource allocation, the transmitting UE sends an SCI message to the other sidelink UE indicating which resources (i.e., randomly selected) it intends to use. The transmit schedule on which the (sidelink) UE is configured is also a separate schedule that uses or partially overlaps with a subset of configured / dynamic resources or resource pools. In all embodiments described, the transmit schedule is defined as a set of transmit time, time interval, delay time, repetition frequency, and (minimum / maximum) number of repetitions. The transmit schedule is relevant only to certain types of signals. A certain class of signals used in 3GPP® systems is the positioning reference signal (PRS) [3GPP® TS 38.211 V16.4.0, clause 7.4.1.7]. These downlink signals are normally transmitted only by the base station. These signals are pseudo-random, but strictly speaking, knowledge of which particular PRS is transmitted by which device, when, and on what frequency is obtainable for anyone receiving all transmissions from the base station. Here, the PRS transmitted by the UE can be considered its identifier, and the timing and frequency at which the PRS is transmitted can be considered its schedule. Generally, base stations do not require protection against tracking because their location is static and usually publicly known. However, if the PRS signals are implemented in a PC5 interface, also known as a sidelink, the PRS signals can also be transmitted or forwarded by intermediate devices, and another UE outside the base station's RF range (outside its coverage area) can receive them, measure their arrival time and possibly arrival angle, and send back the measurement results (e.g., arrival time information, arrival angle information, processing time information, and estimated distance processed from the measurement results) to the transmitting sidelink UE, and / or relay device, and / or base station, and / or core network.An intermediate device is a UE (mobile phone, IoT device) or relay device (e.g., smart repeater, IAB node) capable of generating or transmitting signals (such as PRS) used to perform distance / angle measurement or positioning. Such an intermediate device supports sidelink / PC5 communication for communicating with other communication devices. Combining the measurement results from a (possibly out-of-range) UE obtained through at least two intermediate devices as described above, with the locations of at least two intermediate devices, makes it possible to determine the location of the (possibly out-of-range) UE. This determination can be made entirely in the (core) network (suggesting that the intermediate devices need to transmit the measurement results to the (core) network) or by one of the intermediate devices (suggesting that the other intermediate devices need to transmit the measurements, and possibly their own locations, to this intermediate device).
[0172] The problem is that these intermediate devices are not (or may not be) owned by the mobile network operator, in the sense that their base stations are not owned by the network operator, and the owners of these devices may not want them to be tracked, as their devices transmit PRS signals to assist other devices in positioning. Just as with signals in general, the techniques in general, and especially embodiments 4 and 5, can be used to make it more difficult for outsiders to track intermediate devices transmitting or forwarding PRS signals. Specifically, (1) the intermediate device is provided (in a secure manner) with a set of randomized identifiers corresponding to the PRS signals that the intermediate device will broadcast; (2) the intermediate device is provided (in a secure manner) with a given timing / frequency schedule for broadcasting the PRS signals (this includes a randomized delay that the intermediate device should apply before (re)broadcasting the signal (for example, when forwarding the PRS signals); and (3) the intermediate device is provided (in a secure manner) with a randomized transmit power value for the PRS signals. Countermeasures (1), (2), and (3) ensure that intermediate devices cannot be easily tracked based on the identification information of the PRS signal, the schedule of the PRS signal, or the signal strength of the PRS signal. Typically, this information needs to be provided (in a secure manner) to both the transmitter of the PRS signal (e.g., an intermediate device) and one or more receivers of the PRS signal (which may or may not be intermediate devices).Whether a receiver is trustworthy enough to share this information may be determined by a management entity based on (e.g., subscription information and / or authorization information, application-level information (e.g., provided by an NEF (e.g., a UE belonging to the same trusted group of devices)), service level agreement of the involved UEs, proximity approximation between the transmitter and receiver devices (e.g., based on RAT-dependent localization), contextual information (e.g., in an emergency, by one or more nearby devices receiving information from an Emergency Call Center (PSAP) involved in the emergency call), reliability / reputation (e.g., based on analysis of (historical) device usage data, device users, or device security features or authentication information, such as processed by a Network Data Analysis Function (NWDAF), for example), and device capabilities (e.g., number of antennas, supported frequency bands, etc.). The management entity that provides this information to intermediate devices and / or receiver devices is a network function in the 5G core network, e.g., a location management function or another network function specialized in ranging or localization based on ranging. The management entity that provides this information to intermediate devices and / or receiver devices is also a base station. In the first case, the information is secured (confidentiality / integrity) with NAS security or AS security, for example, as part of an RRC message. Note that the distributed information may also refer to a set of seeds used to derive the PRS signal itself at different points in time or time periods. For example, an intermediate device receives a set of seeds, each assigned to a time period, e.g., a UTC time zone characterized by a start time and an end time, and this seed is then used by the intermediate device to generate a PRS signal, which is broadcast at a specific timing / frequency and given transmit power during that time period. The UE receiving the positioning signal registers the timing and characteristics of the received signal and reports them to a management entity, e.g., the network function of the core network.Since the management entity knows the parameters used for transmitting the positioning signal, it can derive positioning / distancing information related to the receiving UE. In certain cases, a UE interested in the distance / positioning service may need to register for the service, for example, by sending a request to the management entity. During registration, the UE also receives a set of seeds from the management entity that determine the PRS signal, including the identification information, timing, frequency, and transmit power of the surrounding intermediate device. In this way, the UE can process the received positioning information and / or derive positioning / distancing information. Note that tracking the UE becomes more difficult by shortening the duration of the time period. Tracking the UE during that time period becomes feasible by lengthening the duration of the time period, but management overhead is reduced. Randomization of the identifier corresponding to the PRS signal, the resources used for the PRS, the signal strength of the PRS, or any waveform / signal changes of the PRS is also achieved by combining one or more pre-configured pseudorandom functions with a set of seeds as input to the pseudorandom functions. Information regarding these pseudo-random functions and seeds is configured (securely) in both the transmitter and receiver of the PRS signal via RRC or through network policy / configuration information via NAS. By applying the same pseudo-random function and the same seed, both the transmitter and receiver will use the same resulting random value for each PRS signal. If the seed is time-dependent, the transmitter and receiver also need to be synchronized (for example, by using a single base station or sidelink UE as a clock source, or by providing UTC time or SFN, possibly encrypted and signed by a digital signature network function).Regardless of whether a securely provided randomization function is used, or whether other means are used to securely set an identifier corresponding to the PRS signal, the resources used for the PRS, the signal strength of the PRS, or any waveform / signal change of the PRS, the managing entity must ensure that after the arrival time / distance / angle measurement using the PRS signal is completed, the transmitter and / or receiver receive or issue updates regarding a securely provided randomization function, its seed, and / or a securely set random set of identifiers corresponding to the PRS signal, the resources used for the PRS signal, a random set of signal strength of the PRS, or information regarding the waveform / signal change of the PRS, preferably encrypted with an unused key that is not available to both the transmitter and receiver. By doing so, the PRS will be untrackable by a previously used receiver. When a PRS signal is forwarded (i.e., rebroadcast), the original source device of the PRS signal must be provided with secure scheduling information, randomization information, and other information (a subset of which) applied by the intermediate device causing delays and / or modifications, as well as general information (e.g., relay identification information) that informs the source device that the signal is being forwarded by another device (i.e., an intermediate device). This allows the source device to modify the behavior of its signal processing and / or its distance / location estimation calculations. This information is also provided dynamically through the connection between the intermediate device and the source device, for example, as part of a reporting message (e.g., sent as a MAC control element or measurement report). The forwarding device also compensates for the fact that the PRS signal is being forwarded by an intermediate device by providing the source device, receiver device, or location service performing distance / location estimation based on the PRS signal with information about potential processing delays, location information, antenna capability / configuration, and information about the received PRS (e.g., timing information).
[0173] The problem with using PRS signals through an intermediate device is that PRS are downlink signals, and UEs do not normally transmit them. Some uplink signals that UEs normally transmit include, for example, sounding reference signals (SRS) [3GPP® TS 38.211 V16.4.0, Clause 6.4.1.4], or various demodulated reference signals as specified in [3GPP® TS 38.211 V16.4.0, Clause 7.4.1.1]. While potentially less precise than PRS signals, the arrival time measurement of these signals is used in a similar manner to PRS to determine the location of a potentially out-of-range UE, through two or more intermediate devices that transmit these signals (such as sounding reference signals or demodulated reference signals) via sidelink communication. Here again, the technique in general, and particularly embodiments 4 and 5, can be used to make it more difficult for outsiders to track intermediate devices transmitting SRS or demodulated reference signals. In particular, (1) intermediate devices and / or receiver devices are provided in a secure manner by the management entity with a set of randomized identifiers corresponding to the SRS or demodulated reference signal that the intermediate device will broadcast; (2) intermediate devices and / or receiver devices are provided in a secure manner by the management entity with a given timing / frequency schedule for broadcasting the SRS or demodulated reference signal (including a randomized delay to be applied before the intermediate device (re)broadcasts the signal); and (3) intermediate devices and / or receiver devices are provided in a secure manner by the management entity with a randomized transmit power value for the SRS or demodulated reference signal. Countermeasures (1), (2), and (3) ensure that intermediate devices cannot be easily tracked based on the identification information, schedule, or signal strength of the SRS or demodulated reference signal. Base stations, intermediate devices, or receiver devices are also provided with the same set of seeds for a specific time period to ensure that they can properly process the SRS signal they receive. Similarly, the techniques described above for PRS signals can also be applied to SRS signals and demodulated reference signals.
[0174] Similar randomization techniques can be applied to other features of the positioning signals described above, such as frequency hopping sequences, or to other synchronization signals broadcast through the PC5 interface, such as ProSe discovery messages via PC5 / sidelink, sidelink primary synchronization / reference signals, or sidelink secondary synchronization / reference signals, in order to prevent attackers from tracking (intermediate) devices.
[0175] For example, devices are known to be profiled or even tracked based on the resources they are assigned. For instance, a device accessing different internet resources is also involved in certain communication traffic. If an attacker observes the resources assigned to a device, they can infer what types of internet resources the device is accessing. Another potential application concerns secure wake-up radios to prevent DoS attacks. If a specific identifier is used to wake up a device, this could be used by an attacker to perform a DoS attack against that particular device by waking it up until its battery is depleted. These applications can be addressed by the techniques presented herein, for example, by the fourth and fifth embodiments.
[0176] In a related attack, the Sparrow attack (S3-212452 / FSAG Doc 92_009 / https: / / arxiv.org / pdf / 2108.12161.pdf), a malicious UE uses the Random Access (RACH) procedure as a hidden communication channel. In the RACH procedure, in message 1, the UE sends its Random Access preamble transmission; in message 2, the gNB sends its Random Access response; in message 3, the UE sends its scheduled UL transmission; and in message 4, the gNB replies using content resolution. This attack assumes that the malicious sending UE (UE1) is allowed to include a random bit sequence x in message 3 to distinguish itself from other UEs simultaneously competing for RACH access. When the gNB replies with its content resolution message, in message 4, the gNB must include the bit sequence x received from the malicious sending UE1, so that another malicious receiving UE2 can receive it. This is feasible because the base station broadcasts message 4. Thus, a malicious sending device UE1 can send a message to a malicious receiving device UE2. Note that https: / / arxiv.org / pdf / 2108.12161.pdf states that messages 2 and 4 are sent in a basic transmission mode (e.g., broadcast SRB). Note that message 2 is addressed to the UE using the RA-RNTI derived from the transmission slot selected by the UE to send message 1. In message 2, the gNB assigns the TC-RNTI (16 bits long) to the UE. The bit sequence x is 48 bits long and is represented as a Conflict Resolution Identifier (CRI) containing a 40-bit randomly selected value.
[0177] In https: / / arxiv.org / pdf / 2108.12161.pdf and S3-212783, the method for dealing with a Sparrow attack is described as taking a bit sequence x received from the UE and computing a function H(). For example, H() is a cryptographic hash function on x concatenated with a salt s of a random value, i.e., H(x|s), where | means concatenation. Then, in message 4, the gNB sends H(x|s) (or some bits of H(x|s), e.g., the least significant bit or some random bits) along with the salt s to the UE. Here, the salt acts as a hint to the UE about how to verify that message 4 is indeed intended for this purpose, since the UE must verify that the calculation of concatenating the value x sent in message 3 with the received salt s is equal to the received H(x|s). The problem with this technique in S3-212783 is that sending s requires additional bandwidth, and its length also contributes to the possibility of collisions. To address this bandwidth issue, gNB calculates a salt s, for example, used to determine the communication resources (e.g., time slot, SFN, frequency) used to send message 4, such that the salt s is implicitly sent in message 4. The salt is also one of several other communication parameters used in the RACH procedure, such as the (randomized) resource allocation for message 2, or an RNTI, such as one of the RNTIs used to identify message 4. When the UE receives message 4, it determines the value of s from, for example, the communication resources used to send message 4, or an RNTI. Once the UE obtains s, it can verify that the message was addressed to the UE by checking that the hash of its bit sequence x concatenated with the received s is equal to H(x|s) received in message 4. This technique of distributing salts reduces communication overhead.https: / / arxiv.org / pdf / 2108.12161.pdf and S3-212783 also explain that the output of H(x|s) may be truncated (e.g., k least significant bits are sent), only some bits are sent (K-erasure), or some errors are introduced (K-error). For example, in the case of K-erasure, it is necessary to signal the bits to be removed. This can be done by a mask of the same length as H(x|s), for example, L bits in length. Then the remaining Lk bits must be sent. For example, sending such a mask in K-erasure requires additional bandwidth, i.e., L bits. This can be dealt with if the mask is derived from several randomly generated parameters that are uniquely exchanged in message 4 or the previous message, e.g., RNTI or allocated transmission resources. To generate a bit sequence in the form of a mask from smaller random values, the mask is computed by applying a specific function based on a hash function such as SHA-256, e.g., a pseudo-random function, to generate an L-bit bit sequence of fixed weight K. Since the weights are fixed, they can be specified in the technical specifications and do not need to be replaced. One way to compute such a bit sequence is to randomly generate indices between 0 and L-1 until K different indices are generated. The mask then becomes a bit sequence of L bits, with 1s at the positions of the generated indices. Another technique is to set up a bit sequence with K 1s and LK 0s and apply a random sort. This is possible if L-length values (e.g., 128 bits long) are randomly generated (e.g., by applying a pseudo-random function to the seed), with the least significant bit of the first K values set to 1 and the least significant bit of the last LK values set to 0. In the next step, L seemingly random values are sorted. The mask is constructed by concatenating the least significant bits of the L sorted values.Another option is to randomly generate L-bit length candidate masks from the seed, count the number of 1s, and accept them if the number of 1s is greater than a minimum threshold (th_min) and less than or equal to a maximum threshold (th_max). If the candidate mask does not meet the required weight, the process is repeated. If th_max - th_min > 1, the value of k, or any additional 1s the mask contains compared to th_min, needs to be replaced.
[0178] It should be noted that the underlying techniques proposed in S3-212452 or https: / / arxiv.org / pdf / 2108.12161.pdf may not completely solve the Sparrow attack, as the malicious sending UE1 can control / determine the bit sequence x to be sent, and the malicious receiving UE2 can find it using a dictionary. For example, suppose the malicious sending UE1 can send either x0=000...000 or x1=1111...111, and UE2 knows these two values. Suppose the gNB sends LK least significant bits of the hash(x|s) for the known s. When the malicious receiving UE (UE2) receives this value, UE2 takes x0 and x1 and obtains hash(x0|s) and hash(x1|s). UE2 then truncates the output, considering only the LK least significant bits. If one of the values matches, UE2 understands that UE1 sent it a message.
[0179] In another relevant embodiment for addressing a Sparrow attack, the gNB encrypts or scrambles the received bit string x using, for example, a function (e.g., a hash) of the bit string and salt as a key. When the UE receives the result in message 4, the UE can verify whether the message is intended for the UE by decrypting (or descrambling) the received value using the same key derived from the transmitted value x and salt. If malicious devices UE1 and UE2 wish to use this technique for communication, UE2 would need to decrypt (or descramble) the received value with all possible keys derived from all possible messages xi and salts s.
[0180] In the above embodiment, it should be noted that it is advantageous to make the salt as long as possible in order to increase the effort required by a malicious receiver and prevent pre-computation of the dictionary. The problem is that sending a long salt is not feasible because the current standard limits the size of the CRI to 48 bits. Therefore, it is advantageous to send this salt or a portion of it implicitly to make the attack as complex as possible. Alternatively, if both the UE and gNB have access to a common value, for example, a counter derived from UTC time, such a counter can also be used as part of the salt. The least significant bit of the UTC time may be swapped to resolve potentially erroneous time synchronization.
[0181] https: / / arxiv.org / pdf / 2108.12161.pdf states that the total size of a message is 2L + SK, where L is the length of H(x|s), S is the length of the salt, and K is the number of bits not sent. The presented embodiment explains how the message size can be reduced to LK because the S-bit salt can be implicitly sent, and the L-bit length mask used to select the K bits to be removed can also be implicitly sent (the mask is generated by a pseudo-random function from an implicitly sent seed).
[0182] Another related embodiment for addressing a Sparrow attack uses highly focused beamforming when sending message 4. This reduces the risk of another UE receiving it.
[0183] In the above embodiment, backward compatibility between the legacy UE and the new gNB, and between the new UE and the legacy base station, must be considered. Optionally, the new gNB broadcasts its capability as part of system information, for example, by indicating a bit in SIB1. The gNB also signals this information in message 2 or 4, for example, by setting a specific bit to a predefined value. Another option is for the new UE to signal how the bit sequence in a message should be calculated by simply retransmitting the bit sequence in message 3, or by including this value in a specific transmission as described above. The UE may signal this fact by setting a bit to a specific value in message 1 or 3. The new gNB will use this to determine how the bit sequence in reply message 4 should be calculated. If the new UE observes that the gNB is a legacy base station, for example by observing that SIB1 does not explicitly state that the new gNB supports this functionality, the new UE will know that it should examine the bit sequence received in message 4 using the bit sequence it sent in message 3. If a new UE obtains evidence indicating that the gNB is a new base station that supports enhanced Sparrow attack prevention measures, the UE will examine the value of the incoming bit string in message 4, for example, as shown in one of the embodiments above.
[0184] Furthermore, the underlying principles are also applicable to other wireless systems in 3GPP® and other standards organizations. For example, 3GPP® is studying the use of relay devices such as UEs or base stations in integrated access backhaul (IAB) networks to expand its reach. In such use cases, MitM attackers may also be located between the remote UE and the relay UE. The proposed or similar techniques can detect and evade MitM attackers in such situations.
[0185] Furthermore, the proposed enhanced detection and / or mitigation measures for MitM attacks can be implemented in any type of wireless network using FBS or relay. For example, they can be applied to devices communicating using cellular wireless communication standards, specifically the 3rd Generation Partnership Project (3GPP®) 5G specification.
[0186] Therefore, wireless communication devices can be various types of devices, such as mobile phones, vehicles (for vehicle-to-vehicle (V2V) communication or more common vehicle-to-vehicle / vehicle-to-infrastructure (V2X) communication), V2X devices, IoT hubs, and IoT devices (including low-power medical sensors for health monitoring, medical (emergency) diagnostic and treatment devices for hospitals or emergency personnel, and virtual reality (VR) headsets).
[0187] Furthermore, the present invention may be applied to medical applications or connected healthcare involving multiple wireless (e.g., 4G / 5G) connected sensor or actuator nodes; medical applications or connected healthcare where wireless (e.g., 4G / 5G) connected devices occasionally consume or generate continuous data streams at a specific average data rate (e.g., video, ultrasound, X-ray, computed tomography (CT) imaging devices, real-time patient sensors, audio, voice, or video streaming devices used by medical staff); general IoT applications involving wireless, mobile, or fixed sensor or actuator nodes (e.g., smart cities, logistics, agriculture, etc.); emergency services and critical communications applications; V2X systems; systems for improving coverage for 5G cellular networks using high-frequency (e.g., mmWave) RF; and any other application area of 5G communications where relay is used.
[0188] Other variations of the disclosed embodiments can be understood and practiced by those skilled in the art practicing the claimed invention, from a consideration of the drawings, this disclosure, and the appended claims. The term “equipment (having, including)” in the claims does not exclude other elements or steps, and singular elements do not exclude plural elements. A single processor or other unit may fulfill the functions of multiple items described in the claims. The mere fact that certain means are described in different dependent claims does not imply that combinations of these means cannot be used for benefit. The foregoing description details certain embodiments of the invention. However, regardless of how detailed the foregoing description may be in text, the invention is practiced in many ways and should not be limited to the disclosed embodiments. The use of certain technical terms in describing certain features or aspects of the invention should not be taken as to suggest that such technical terms are to be redefined herein to be limited to any particular characteristics of the features or aspects of the invention to which they relate.
[0189] A single unit or device may satisfy the functions of multiple items within the claims. The mere fact that certain means are described in different dependent claims does not imply that combinations of these means cannot be used for benefit.
[0190] The operations described, such as those shown in Figures 3 to 8, may be implemented as program code means of a computer program and / or as dedicated hardware for associated communication devices or access devices, respectively. The computer program may be stored and / or distributed on a suitable medium such as an optical storage medium or a solid-state medium, supplied together with or as part of other hardware, but may also be distributed in other forms, such as via the Internet or other wired or wireless telecommunications systems.
Claims
1. A device for detecting attacks by fake wireless devices that impersonate genuine or authentic access devices in a wireless network, wherein the device is: A randomizer for randomizing the assignment of at least one communication resource and / or identifier used to communicate with a wireless communication device, An attack testing unit for checking whether a transmission received from the wireless communication device used the at least one communication resource and / or identifier assigned by the randomized assignment, and for determining the presence of a fake wireless device or an attack by the fake wireless device based on the result of the check. A device equipped with the following features.
2. The apparatus according to claim 1, wherein the randomizer calculates at least one random parameter value within each predetermined range of values, and allocates time or frequency resources, in particular subsequent frames, subsequent slots, or subsequent frequency ranges, for communication with the wireless communication device based on the calculated at least one random parameter value.
3. The apparatus according to claim 1, wherein the randomizer determines a random waiting time, the apparatus sends a resource activation message to the wireless communication device after the random waiting time has expired, and the attack inspection unit checks, based on a timer function, whether a direct response has been received from the wireless communication device.
4. The apparatus according to claim 3, wherein the attack inspection unit checks whether the received direct response includes downlink control information contained in the resource activation message.
5. The apparatus according to claim 1, wherein the apparatus transmits the at least one communication resource and / or identifier assigned in the protected message.
6. The apparatus according to claim 5, wherein the allocated at least one communication resource includes at least one of a random time-domain offset value, a random time-domain allocation value, and a random frequency-domain allocation value, which are to be used for response by the wireless communication device.
7. The apparatus according to claim 6, wherein the random time-domain offset value indicates a time offset relative to the system frame number, and the attack inspection unit monitors whether a response message is received from the wireless communication device before or after the time offset.
8. The apparatus according to claim 6, wherein at least one of the random time domain allocation value and the random frequency domain allocation value points to a row or column of a lookup table.
9. The apparatus according to claim 1, wherein the attack testing unit performs a testing operation after security is established when the wireless communication device establishes a secure connection with the wireless network, or after a handover of the wireless communication device.
10. The apparatus according to claim 1, wherein the randomizer determines a random seed value to be transmitted in a protected manner to the wireless communication device in order to allocate communication resources, particularly time slots or frequency ranges, to a response message based on a pseudo-random sequence.
11. The apparatus according to claim 1, wherein the randomizer determines a random seed value for deriving a random temporary network identifier by a list of at least one random temporary network identifier or a pseudo-random function, the apparatus transmits the list of at least one random temporary network identifier or the random seed value to the wireless communication device in a manner protected for the selection of a random temporary network identifier in a subsequent transmission, and the attack testing unit determines an attack by a fake wireless device based on the received random temporary network identifier.
12. The apparatus according to claim 11, wherein the randomizer determines a first list of random temporary network identifiers to be used by the wireless communication device and a second list of temporary network identifiers to be used by the apparatus.
13. A network device for a wireless network comprising the apparatus described in any one of claims 1 to 12.
14. An attack testing system comprising a network device according to claim 13 and a wireless communication device, wherein the wireless communication device detects the assigned at least one communication resource and / or identifier, and applies the detected at least one communication resource and / or identifier to communication with the network device.
15. A method for detecting an attack by a fake wireless device that impersonates a genuine or authentic access device in a wireless network, wherein the method is: A step of randomizing the assignment of at least one communication resource and / or identifier used for communication with a wireless communication device, A step of checking whether the transmission received from the wireless communication device used the communication resources and / or identifiers assigned by the randomized assignment, A step of determining the presence of a fake wireless device or an attack by the fake wireless device based on the results of the inspection step. A method having.
16. The method according to claim 15, wherein the method is performed at time instants in accordance with a secret schedule agreed upon between the wireless communication device and the genuine or authentic access device, or at random time instants.
Citation Information
Patent Citations
Method and apparatus for optimizing uplink random access channel transmission
JP2014209777A
User equipment authentication
US20200288313A1
Security mode integrity verification
US20200288320A1
Detection of system information modification using access stratum security mode command
US20200344605A1