Method for detecting a telephone identifier-capturing device, and computer program product

A method combining cell change probability and signaling latency analysis with ARIMA modeling detects telephone identifier capture devices across various communication standards and environments, ensuring secure user credentials.

WO2025141072A1PCT designated stage expired Publication Date: 2025-07-03THALES SA +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2024/088449
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-29
Filing Date
2024-12-24
Publication Date
2025-07-03

AI Technical Summary

Technical Problem

Existing methods for detecting telephone identifier capture devices, such as IMSI catchers, are limited by outdated databases, reliance on satellite positioning, and vulnerability to countermeasures, particularly in unfamiliar geographical areas and indoor environments, and are not agnostic to different communication standards.

Method used

A method that combines instantaneous probability of cell change and signaling plan latency measurements, using ARIMA modeling and real-time analysis, to detect anomalies indicative of a telephone identifier capture device, independent of communication standards and location.

Benefits of technology

Provides real-time, location-independent detection of telephone identifier capture devices, ensuring secure communication by preventing unauthorized access to user credentials.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024088449_03072025_PF_FP_ABST
    Figure EP2024088449_03072025_PF_FP_ABST
Patent Text Reader

Abstract

This method (100), which is implemented by a mobile terminal, consists in combining (300), in a final result (RF), a first result (RR) relating to an instantaneous probability of cell change, and a second result (RL) relating to an exchange latency on a signalling plane between the mobile terminal and a base station of a serving cell, the first result, respectively the second result, being obtained (150, 250) by comparing a measurement (Xi(t+1)) of a first quantity, respectively a measurement (L(t+1)) of a second quantity, with a prediction (X'i(t+1)) of the first quantity, respectively a prediction (L'(t+1)) of the second quantity, a telephone identifier-capturing device being detected when one and / or the other of the first and second results indicates a mismatch between the measurement and the prediction of the associated quantity.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] TITLE: Method for detecting a telephone identifier capture device and computer program product

[0002] The invention relates to the general field of mobile communications security and, in particular, to methods and systems for detecting telephone identifier capture devices.

[0003] The use of a telephone identifier capture device is known. For example, when crossing a border, such a capture device ("IMSI Catcher") can be used to capture the international identity of the mobile subscriber - the IMSI ("International Mobile Subscriber Identity") of the mobile terminal (or user equipment) of an individual, in order to associate this telephone identifier with other identification information of this individual (provided for example by his passport).

[0004] Thus, when this individual uses his mobile terminal on one of the public mobile telephone networks covering the territory whose border he is crossing, the intercepted communication data can be associated, via the captured telephone identifier, with this individual.

[0005] A phone ID capture device emulates a base station of a public network already deployed in a geographic area.

[0006] Typically, a phone ID capture device clones a distant base station, which therefore has a weak signal level, so that the capture device's signal dominates the signal from that original base station.

[0007] The base station thus emulated presents itself as any other base station on the public network, notably by using consistent identifiers.

[0008] Detecting the presence of a base station with a strong signal, the mobile terminal will connect to the emulated base station.

[0009] The mobile terminal can be caught by the capture device in all connection scenarios: initial registration type connection on a network, mobility type connection between cells of the same network (intercellular transfer or "handover"), mobility type connection between cells of two different networks (roaming).

[0010] Once the mobile terminal is connected to the emulated base station, the phone ID capture device performs a man-in-the-middle attack (MITM), for example by sending specific commands to the mobile terminal to switch to second generation (2G), which allows the emulated base station to decrypt traffic, or even voice calls. Even if the capture device cannot force the mobile terminal to switch to 2G, it can act as a relay between the mobile terminal and a base station actually belonging to the public network and thus track the mobile terminal.

[0011] However, for various reasons, an individual may not want their phone credentials captured.

[0012] For example, there is an application called AIMSICD, available for Android (registered trademark), which allows you to detect devices that capture phone identifiers. It is presented for example at the following address: https: / / cellularprivacy.github.io / Android-IMSI-Catcher-Detector / .

[0013] To do this, the application, running on the mobile terminal, measures the power of the different base stations present in the terminal's environment.

[0014] For each base station, the AIMSICD application compares the power measured by the radiocommunication module with an expected power taking into account the instantaneous position of the terminal (determined by a satellite positioning module of the mobile terminal) and a database of the positions of the official base stations of the or each public network in the geographical area within which the mobile terminal is located.

[0015] If the measured power is much higher than the expected power, the application generates an alarm indicating a risk that the base station is in fact the one emulated by a phone ID capture device.

[0016] However, this application relies on a database that is not always up to date, particularly when it concerns a geographical area located abroad for the user of the mobile terminal.

[0017] It also requires measuring the position of the mobile terminal, which is not always feasible inside a building without satellite positioning system coverage.

[0018] But most importantly, the capture device can counter the application by presenting a power level equivalent to that of the cloned cell.

[0019] The aim of the present invention is therefore to solve this problem while being agnostic to the radiocommunication means implemented (i.e. to the standard to which they belong, 2G / 3G / 4G / 5G / 6G, Wi-Fi, “Bluetooth”, mesh (“Mesh”), etc.) and being locally autonomous in any context (indoor or outdoor, etc.).

[0020] For this, the subject of the invention is a method for detecting a telephone identifier capture device, the method being implemented by the computer of a mobile terminal, characterized in that the method consists in combining, in a final result, a first result relating to an instantaneous probability of changing cell, and a second result relating to a latency of exchanges on a signaling plane between the mobile terminal and a base station of a serving cell, the first result, respectively the second result, being obtained by comparing a measurement of a first quantity, respectively a measurement of a second quantity, with a prediction of the first quantity, respectively a prediction of the second quantity, a telephone identifier capture device being detected when one and / or the other of the first and second result(s) indicate(s) a disagreement between the measurement and the prediction of the associated quantity.

[0021] According to particular embodiments, the method comprises one or more of the following characteristics, taken in isolation or in all technically possible combinations:

[0022] - the first quantity is a function, for each base station present in the environment of the mobile terminal, of an instantaneous speed of the terminal, of an instantaneous power received from the base station and of an instantaneous relative distance between the mobile terminal and each base station.

[0023] - the second quantity is the instantaneous latency on exchanges on the signaling plan measured at the terminal level.

[0024] - the prediction of the first quantity, respectively of the second quantity, is obtained by implementing ARIMA modeling.

[0025] - association conditions are defined to combine the first and second results and obtain a final result indicative of the presence of a telephone ID capture device.

[0026] - the second result is filtered using a library of error cases and expected given the messages exchanged with the base station from which the second quantity is measured.

[0027] - configuration parameters of the forecasting step of the first quantity, respectively of the second quantity, are obtained by the mobile terminal by interrogating a remote information collection center from a fleet of mobile terminals.

[0028] - the final result is displayed on a screen of the mobile terminal.

[0029] -when the final result is indicative of the detection of a telephone ID capture device, an erroneous telephone ID is transmitted in response to an identification request received by the mobile terminal.

[0030] The invention also relates to a computer program product comprising program code instructions for executing the steps of the preceding method.

[0031] The invention and its advantages will be better understood on reading the detailed description which follows of a particular embodiment, given solely as a non-limiting example, this description being made with reference to the appended drawings in which:

[0032] Figure 1 is a schematic representation of a user terminal implementing the method according to the invention; and,

[0033] Figure 2 is a block representation of the method according to the invention.

[0034] Generally, the method according to the invention provides a generic solution for detecting telephone ID capture devices.

[0035] It results from the execution of a software application on the mobile terminal in such a way as to inform, in real time, the user of this terminal of the risk of capture of his telephone identifiers by a malicious capture device emulating a base station of a public radiocommunication network.

[0036] This application is preferably based on three pieces of information to detect anomalies that can be assimilated to a request from a capture device.

[0037] The first information is radio information, resulting from the comparison between the observed electromagnetic environment and a forecast of what this electromagnetic environment should be, taking into account for example not only the power received from the base stations placed in the environment and the relative position of the mobile terminal, but also the speed of movement of the mobile terminal. Too great a difference between what is expected and what is observed is indicative of the presence of a telephone identifier capture device.

[0038] The second information is an assessment of the latency of messages between the terminal and the public radiocommunication network.

[0039] Indeed, if the exchanges are too short or too long compared to what is normally expected of an exchange with a public radiocommunication network, this is an indication of the presence of an identifier capture device which does not carry out all of the procedures normally implemented by the public radiocommunication network, but only certain steps relating to the collection of the terminal's telephone identifiers.

[0040] For example, when roaming, i.e. when the mobile terminal leaves the coverage area of ​​a network and must attach to a base station of a new network, the procedure for attaching the terminal to this new network involves an authentication procedure. During this authentication procedure, the new host network queries the terminal to obtain terminal identification information. Based on this identification information, the new host network queries, for example, a subscriber server (Home Subscriber Server - HSS for infrastructures conforming to the fourth generation - 4G or lower and Unified Data Management / Authentication Server Function - UDM / AUSF for infrastructures conforming to the fifth generation - 5G) to find out the rights attached to the terminal (and to the user of the latter).

[0041] The outcome of a successful authentication procedure is the establishment of the connection between the terminal and the new host network.

[0042] On the other hand, the outcome of a failed authentication procedure leads to the rejection of the request to establish a communication link.

[0043] By forcing roaming and performing only certain steps in the authentication process, a credential capture device collects telephone identification information from the terminal. The credential capture device does not perform the steps of querying a remote server to determine the profile of the terminal seeking to connect.

[0044] However, this step, when carried out, must take a certain amount of time. A response from the network that is too rapid (in particular the rejection of the request from the mobile terminal) is therefore a sign of the presence of a device for capturing telephone identifiers.

[0045] The third information relates to the sequence and content of messages received from the public radiocommunication network.

[0046] This is because an ID capture device is not able to generate exactly the same sequence of messages as a real base station in the network.

[0047] For example, a credential capture device tends to respond with error messages, which may be surprising compared to what is expected.

[0048] For example, an identifier capture device tends to request re-authentication following an "authentication failure" error message.

[0049] Figure 1 schematically represents a mobile terminal 10. This is in particular user equipment of the mobile telephone type. Alternatively, it can be any type of user equipment having an air interface, such as a car, a fourth generation game console - 4G, connected equipment of the Internet of Things type, etc.

[0050] The terminal 10 comprises a calculation unit, such as a processor 11, a storage unit, such as a memory 12, a radiocommunication module 13 and a positioning module 14. The memory 12 stores the instructions of different computer programs. In particular, it stores the instructions of an application 15 for detecting the presence of an IMSI capture device, such as the device 30.

[0051] While in the present disclosure the device 30 seeks to capture the IMSI of a terminal, alternatively other telephone identifiers could be captured instead of or in addition to the IMSI, such as the International Mobile Equipment Identity (IMEI), telephone number, etc.

[0052] When the instructions of the application 15 are executed by the computer 11, the terminal 10 implements the method according to the invention, which will be described below with reference to FIG. 2.

[0053] The radiocommunication module 13 allows the establishment of a two-way communication link with a base station present in the environment of the terminal 10.

[0054] This may be a base station of a public mobile telephone network, such as the "real" base stations 20_1 and 20_3 of the network 50, or a base station "emulated" 20_2 by an IMSI capture device, such as the device 30.

[0055] At any given moment, the radiocommunication module 13 is capable of measuring the power of the signals emitted by the different base stations present in its environment.

[0056] In particular, module 13 is capable of regularly measuring the received power of the reference signal - RSRP ("Reference Signal Receive Power") from each base station present in its vicinity.

[0057] In particular, the module 13 is capable of regularly evaluating a distance from the terminal to a base station. This evaluation is done for example from the synchronization progress indicator - TA ("Timing Advance"), corresponding to the time required for a signal to reach the base station from the mobile telephone.

[0058] Alternatively or in combination, the module 13 can collect any relevant measurement on the surrounding cells, to correlate what is measured at the terminal with what is actually transmitted by the base stations: cell identifier "cell ID", RSRP, quality of the received reference signal - RSRQ ("Reference Signal Received Quality") corresponding to a signal-to-noise ratio, neighbor discovery messages ("neighbor advertisement"), etc.

[0059] The radiocommunication module 13 is also capable of measuring instantaneous latency. This involves measuring the time separating two successive exchanges between the terminal and the network, along an air link established between the terminal and a particular base station among all the surrounding base stations. The module 14 is capable of determining the instantaneous position of the terminal 10 and, by time derivation, the instantaneous vector speed of the terminal 10. This is for example a satellite positioning module - GNSS ("global navigation satellite system"). Alternatively, it is possible to reconstruct the position of the terminal by triangulation from other radio transmitters (base stations, proprietary dedicated beacons, etc.).

[0060] Advantageously, the terminal 10 is equipped with a human-machine interface 16. This is for example made up of a screen and a keyboard allowing the user of the terminal 10 to interact with the latter.

[0061] In particular, the execution of the software application 15 makes it possible to display on the screen various information, such as the probability of the presence of an IMSI capture device in the environment of the terminal 10.

[0062] In addition, the application 15 can advantageously access, via the public mobile telephone network 50 and a public IP network 60, a central office 40, to receive configuration parameters and provide information to the central office 40.

[0063] The central 40 is adapted to collect, process and aggregate information from a fleet of terminals (similar to terminal 10 in that they run application 15) to construct a radio map of a territory.

[0064] The central 40 is suitable for building a knowledge base relating to errors and expectations of usual exchanges with public networks covering a territory, their usual processing.

[0065] A preferred embodiment of the method for detecting an IMSI capture device according to the invention will now be presented with reference to Figure 2.

[0066] An iteration of the method 100 is performed while the terminal 10 is connected to a public mobile telephone network 50.

[0067] This public mobile telephone network is for example a 4G network, but the person skilled in the art will know how to extend the technical teaching of the present description to other generations of mobile telephone infrastructures, in particular 5G, or to other types of connection such as Wi-Fi, Bluetooth, Mesh, etc.

[0068] The first step 110 consists of measuring the instantaneous speed V(t) of the terminal 10. This information is obtained by interrogating the satellite positioning unit 14 of the terminal 10.

[0069] In step 120, a measurement of the instantaneous power Pi(t) received from each base station i (i integer between 1 and N) present in the environment of the terminal 10 is obtained. For this, the radiocommunication module 13 of the terminal is interrogated to obtain for example the instantaneous RSRP of each station. A measurement of the relative instantaneous distance Di(t) between the terminal 10 and each base station i present in the environment of the terminal 10 is also obtained. For this, the module 13 is interrogated to obtain for example the TA of each station.

[0070] In step 130, for each base station i of the environment, an instantaneous characteristic quantity Xi(t) is calculated as a function of the speed V(t), the power Pi(t) and the distance Di(t), obtained respectively in steps 110 and 120.

[0071] The quantity X makes it possible to quantify a probability of leaving / entering the cell associated with the base station i and consequently, of having to make a cell change, either an intercellular transfer ("handover") to another cell of the same host network, or roaming on another cell of another host network.

[0072] The next step 140 consists of implementing a model in order to predict the evolution of the quantity Xi at the following instant t+1. This prediction is denoted X'i(t+1). For example, a model of the autoregressive integrated moving average type - ARIMA ("AutoRegressive Integrated Moving Average") is implemented. This is a statistical model making it possible to analyze the time series of the Xi over a history window of predefined length and ending at the current instant t. Alternatively, any other prediction model than the ARIMA model can be implemented, in particular artificial intelligence / machine learning models.

[0073] Step 150 of the method 100, which is presented at the following instant t+1, consists of comparing the measured quantity Xi(t+1), as delivered at the output of step 130 at the following instant t+1, with the quantity X'i(t+1) predicted at the output of step 140 at the previous instant t.

[0074] Different comparison rules can be used. For example, the following three rules are implemented: when the difference between measured quantity Xi(t+1) and predicted quantity X'i(t+1) is less than a first threshold, S1, the RR result of the comparison takes for example the value "0" ("green"). when this difference is greater than the first threshold S1, but less than a second threshold, S2, then the RR result takes the value "1" ("orange"). when this difference is greater than the second threshold, S2, then the RR result takes the value "2" ("red").

[0075] Advantageously, the rules implemented in step 150 are configurable, in particular by interrogating the central office 40.

[0076] At the end of step 150, we therefore have a first piece of RR information relating to the radio environment of the terminal 10. The following steps of the method 100 make it possible to obtain RL information relating to the latency of the communications.

[0077] In a step 210, a measurement of the instantaneous latency L(t) is obtained for example by interrogating the module 13 of the terminal 10.

[0078] This is the latency on the signaling plane of the base station to which the terminal is connected, i.e. the serving cell.

[0079] It should be noted that, with other base stations in its environment, the terminal is passive and cannot measure latency. Alternatively, the terminal 10 may be programmed to voluntarily attempt to connect to neighboring cells, in an attempt to detect telephone ID sensor devices.

[0080] All exchanges are to be considered, but the exchanges that immediately follow the switch to a new serving cell are the most interesting: “PRACH” request (“Physical Random Access Channel”) used by the terminals to request an uplink allocation from the base station, to measure, at the physical level, the initial TA; connection procedure, for an evaluation of the latency at the level of radio resource control - RRC (“Radio Resource Control”); authentication and attachment procedure, for an evaluation of the latency at the level of network authentication (NAS - “Non-Access Stratum”).

[0081] In a step 240, a model is used to predict the latency at the next instant L'(t+1). Advantageously, just as in step 140, an ARIMA model is used. Alternatively, any other prediction model can be used, in particular AI / ML models.

[0082] In step 250, which is presented at the following instant t+1, a comparison is made between the measured latency L(t+1) as indicated by the module 13 at the instant t+1 and the prediction of the latency L'(t+1) calculated at the output of step 140 at the previous instant t.

[0083] Again, different rules may be implemented, but preferably rules similar to those implemented in step 150 are used to obtain a three-valued RL0 result, either "0", "1", or "2".

[0084] Advantageously, the rules implemented in step 250 are configurable, in particular by interrogating the central office 40.

[0085] In a step 260, the RL0 result is filtered according to a library of errors and expectations 270, to obtain a filtered result RL. Indeed, the 3GPP standard defines standard procedures, including in particular cases of error in the implementation of exchanges on the serving cell. It is then advantageous to filter a latency difference according to the error case actually encountered and an associated expectation (or behavior), in particular in terms of latency difference.

[0086] This provides the ability to compare the encountered behavior with typical behavior, and decide whether the measured latency deviation is consistent with a normal environment or the presence of an ID capture device.

[0087] Advantageously, the 270 library is regularly updated, in particular by querying the 40 exchange.

[0088] Finally, in a step 300, the outputs of the comparison step 150 and the filtering step 260 are conditionally associated.

[0089] The conditions of association are for example the following rules:

[0090] If “0” and “0”, then final RF result is “OK”.

[0091] If "0" and "1", final result is "need further investigation".

[0092] If "0" and "2", if "1" and "1", if "1" and "2", and if "2" and "2", then the final result is "not OK".

[0093] Finally, in step 310, the final RF result is displayed on the terminal screen to help the user decide on an action, such as providing an incorrect telephone identifier when one of the IMSI capture devices has been detected (RF = "not OK"),

[0094] Alternatively, instead of a display action, the software application 15 may automatically command the performance of the required action, such as indicating erroneous telephone identifiers to the device 30.

[0095] For example, once a credential capture device is detected, the terminal can mark the base station emulated by that credential capture device and avoid it.

[0096] Advantageously, periodically, the application 15 communicates with a central information collection center 40 so as to obtain configuration and update parameters, in particular for the modeling steps 140 and 240.

[0097] The central 40 allows information to be collected from the applications 15 running on a fleet of terminals.

[0098] For example, the central 40 makes it possible to construct a radio map of a territory. This information can make it possible to provide the configuration information for steps 150 and 250, such as the latency comparison rules.

[0099] The exchange 40 also collects information on the processes, specific to each country, implemented on the signaling (or control) plane of communications between a terminal and the mobile telephone network. This information will make it possible to populate a knowledge base, in order to configure the rules for comparing the probability of leaving a cell used in step 150, the latency comparison rules used in step 250, and the library 270 of error and expected cases used in step 260.

[0100] The central unit 40 has, for example, the capacity to carry out mission preparation, in particular by defining a movement path for a terminal 10 based on the expected electromagnetic environment, i.e. based on the radioelectric mapping of the planned movement territory of the terminal user.

[0101] This makes it possible to configure the comparison functions (step 150 and step 250) of the application 15 of the telephone 10 before carrying out the mission, for example by defining the value of the first and second thresholds for each geographical area along the envisaged path.

[0102] Alternatively, this geographic zoning information and configuration parameter values ​​are transmitted from the central office 40 to the terminal 10 as the terminal moves. In this alternative, the terminal 10 can indicate to the central office 40 its current position. The central office 40 responds by giving the configuration parameters associated with the zone in which the terminal is located at the current time.

[0103] Thus, in an area where an IMSI catching device is believed to be present, the first and second thresholds are lowered so as to interpret each deviation in latency or radio environment as a solicitation of an IMSI catching device.

[0104] The exchange 40 can transmit other information to the application 15 running on the terminal 10 such as for example the names of the cells or other characteristics such as confidence indicators relating to the base stations that the terminal is supposed to encounter. In this way, the application 15 is able, when a new base station appears in its environment, to compare the name of this base station with the information received from the exchange 40 in order to discriminate between legal base stations and base stations emulated by an IMSI capture device.

[0105] The fact of detecting locally, by an application running on the terminal, presents numerous advantages compared to the state of the art and the need to interrogate a central and therefore to have to signal by the exchange of messages between the terminal and the central.

[0106] The present invention is implemented in real time and not a posteriori. It makes it possible to inform the user of the terminal so that he reacts or, alternatively, to react automatically in his place to defend himself against any attempt to intercept his telephone identifiers.

[0107] This function thus guarantees the integrity of the user's future communications using the terminal since this telephone identification information is not shared and does not allow the user to be recognized when using their telephone.

Claims

CLAIMS 1. Method (100) for detecting a telephone identifier capture device (30), the method being implemented by the computer of a mobile terminal (10), characterized in that the method consists in combining (300), in a final result (RF), a first result (RR) relating to an instantaneous probability of changing cell, and a second result (RL) relating to a latency of exchanges on a signaling plane between the mobile terminal (10) and a base station of a serving cell, the first result, respectively the second result, being obtained (150, 250) by comparing a measurement (Xi(t+1)) of a first quantity, respectively a measurement (L(t+1)) of a second quantity, with a prediction (X'i(t+1)) of the first quantity, respectively a prediction (L'(t+1)) of the second quantity,a telephone identifier capture device (30) being detected when one and / or the other of the first and second result(s) indicate(s) a disagreement between the measurement and the prediction of the associated quantity., 2. Method according to claim 1, in which the first quantity is a function, for each base station present in the environment of the mobile terminal (10), of an instantaneous speed of the terminal, of an instantaneous power received from the base station and of an instantaneous relative distance between the mobile terminal (10) and each base station.

3. Method according to claim 1 or claim 2, in which the second quantity is the instantaneous latency (L(t)) on the exchanges on the signaling plane measured at the terminal (10).

4. Method according to any one of the preceding claims, in which the prediction of the first quantity, respectively of the second quantity, is obtained (140, 240) by implementing ARIMA modeling.

5. Method according to any one of the preceding claims, in which association conditions are defined to combine the first and second results and obtain a final result (RF) indicative of the presence of a telephone identifier capture device.

6. Method according to any one of the preceding claims, in which the second result is filtered (260) using a library of error and expected cases (270) taking into account the messages exchanged with the base station from which the second quantity is measured.

7. Method according to any one of the preceding claims, in which configuration parameters of the step of predicting the first quantity, respectively of the second magnitude, are obtained by the mobile terminal (10) by interrogating a remote central unit (40) for collecting information from a fleet of mobile terminals.

8. Method according to any one of the preceding claims, wherein the final result (RF) is displayed on a screen of the mobile terminal (10).

9. Method according to any one of the preceding claims, in which, when the final result (RF) is indicative of the detection of a telephone identifier capture device (30), an erroneous telephone identifier is transmitted in response to an identification request received by the mobile terminal.

10. Computer program product comprising code instructions which, when executed by a computer of a mobile terminal, allow the implementation of an identification method according to any one of claims 1 to 9.