A defense method for against signal attacks
The method addresses jamming attacks in wireless networks by using the base station to detect and counter fake Wake-Up Signals, ensuring network communication flow and energy efficiency without added complexity.
Patent Information
- Application Number
- PCT/TR2025/050816
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-07-29
- Publication Date
- 2026-02-05
AI Technical Summary
Existing wireless communication networks, particularly those using 5G and low-power Wake-Up Receivers (WURs), are vulnerable to jamming attacks where attackers mimic Wake-Up Signals (WUS) to drain device batteries, cause denial of service, and disrupt network traffic due to the simplicity and ease of mimicking these signals, which existing solutions fail to address without increasing complexity or requiring additional processing capabilities.
A method where the base station processes and partially decodes the WUS to detect fake signals, sending a jamming signal to prevent the WUR from triggering the main radio, thus maintaining network communication flow without additional complexity or processing.
Effectively prevents fake wake-up signals from draining device batteries and disrupting network traffic by leveraging the base station's processing capabilities to maintain network integrity and energy efficiency.
Smart Images

Figure TR2025050816_05022026_PF_FP_ABST
Abstract
Description
[0001] A DEFENSE METHOD FOR AGAINST SIGNAL ATTACKS
[0002] TECHNICAL FIELD
[0003] The present invention generally relates to wireless communication networks, and particularly relates to detecting communication jamming attack and defense method for against signal attacks. The method is providing for signal detection and prevention of false wake-up signals especially in Internet of Things (loT) devices.
[0004] PRIOR ART
[0005] In the prior art, current wireless networks including 5G and other systems devices suffer from high power consumption, requiring frequent recharging or battery changing, particularly within a few hours for smartphones and just days / weeks for resourcelimited sensors. This challenge is particularly significant for devices with small batteries or those lacking convenient access to charging facilities, such as wearables and remote sensors. While prolonged periods of extended Discontinuous Reception (eDRX) can provide certain power-saving benefits, the associated latency drawbacks pose significant challenges for time-sensitive applications like fire detection and industrial automation.
[0006] 3GPP Rel-18 seeks to overcome existing limitations by introducing an innovative ultralow power wake-up mechanism (method). Departing from the conventional continuous polling approach, this new paradigm enables User Equipment (UE) to enter a deep sleep state, i.e., and be awakened by a dedicated "Wake-Up Signal" (WUS) transmitted by the network / access point / base-station or gateway. This transformative solution involves the use of a separate, ultra-low power Wake-Up Receiver (WUR) separated from the main radio (MR) that consumes substantial data. Essentially, it employs a sentinel to safeguard the device's valuable energy reserves.
[0007] The design of the Wake-Up Signal (WUS) itself holds great significance, influencing both power consumption and the reliable detection capabilities of the compact Wake- Up Receiver (WUR). The primary goal is to develop optimal WUS / WUR solutions customized for power-sensitive UE’s, including mobile devices, loT sensors and wearables, yielding substantial benefits beyond the power-saving methods introduced in Rel-15 / 16 / 17. Importantly, this initiative extends its impact beyond these specific use cases, encompassing potential applications in areas such as XR glasses and smart homes.
[0008] The integration of the WUS frame with the legacy 5G NR is a challenging task as discussed in [1], mainly due tradeoff between accuracy and complexity. As the 3GPP standards continue to evolve towards release 19 a more concrete establishment of the OFDM based WUS is proposed. Nevertheless, those WUS regardless of the waveform / signaling scheme used forthem are simple, short length and simple in terms of complexity, coding and encryption to simplify the WUR / WUS as much as possible as they are considered an additional component to the existing core receiver or main radio. Here arises a critical problem assimilate in the ease of mimicking those WUS and sending fake and unnecessary WUS to the UEs from non-authentic entities (fake base station, jammer...). This fake wake-up demands result in draining the battery of those UE’s, denial of service attacks (DOS) and increasing the traffic and interrupting the normal flow of the communication in the networks.
[0009] The main technical problem is that to detect / mitigating and combat jamming signal attacks with adding more complexity to the low-end devices and their WUS / WUR. Additionally, any proposed solution must comply with the WUS frame structure and requires additional signal coding including MAC and high-level encryption to the WUS.
[0010] In any network using WUS / WUR technology, the base station (BS) (or a master node) wakes-up devices by sending a WUS to a specific user or group of users. Those WUS and their corresponding WUR are simple in terms of design, complexity, hardware and encryption / security. Meanwhile this simplicity allows reducing the cost, complexity and cost while deploying low-power technology, they leverage the security of communication since the sequence / ID and the signals used for wake-up are easy to track, detect and mimic. Consequently, any outside entity can mimic those signals and their pattern and send false wake-up alarm / signal to unnecessarily wake-up the devices which results in the following issues: 1- Draining the power and battery life of end devices for non-communication purposes.
[0011] 2- Those attacks are considered as denial of service, where the normal transmission / reception of devices is endangered while wasting duty-cycle limitations.
[0012] 3- Causing disrupting traffic in the network, where unusual transmission / receptions are leading to interference and collisions.
[0013] There exist various patent documents and articles in the literature about jamming signal detection. Some of these are outlined below.
[0014] Patent document WO2023211668A1 relates to Qualified Jamming Signal Detection. This patent utilizes two or multiple satellite positioning signals, and some metric to detect a jamming signal at a satellite positioning receiver to decide whether a jamming signal is detected or not. This process requires the UE radio to have GPS capability which is not feasible to have along with the WuR, making this solution not practical for Lp-WuS / Wur systems.
[0015] Another approach is described in patent document EP3091519A1. This patent document relates to Jamming Detection Method and Device. In this patent, a method for detecting jamming signal is employed where a device scans one or multiple frequency bands to sense a jamming signal. If the device detects the jamming signal, it transmits an alarm or feedback signal through an ultra-narrow band network such as ISM bands. However, as this approach demands a feedback signal transmitted from the UE, it cannot be integrated with WuR because it doesn’t have the transmission capability. In addition, triggering the main radio to send the feedback signal can cause battery drain which contradicts the main goal of using Lp-WuS / WuR.
[0016] The patent document US11757559B2 relates to collaborative signal jamming detection. This patent includes a jamming detection mechanism where a collaborative jamming detection from multiple vehicles is used. Specifically, a local jamming information from those vehicles such as attack time, frequency and localization is transferred to the base station to form a global jamming map which is shared then with other vehicles. This approach has a resilient scheme against jamming but at the cost of a very complicated process that the WuR cannot deliver where a WuR doesn’t have the ability to get the attack time, attack localization and also attack frequency.
[0017] The article [2] relates to real-time jamming detection using the sum-of-squares paradigm. The proposed approach requires the UE receiver to have a DSP processing capability in order to implement the algorithm that takes the squares of the carrier to noise density power ratio which is practical to implement in a WuR as it doesn’t contain anu DSP processing capabilities.
[0018] The existing solutions do not have countermeasures against snapshot attacks of WUS mimicking and retransmission from other attackers, where the existing solution is limited to:
[0019] - Using MAC encryption, or traditional high layer coding which requires more processing capabilities at the WUR to operate. However, due to latency, simplicity and power constraints those solutions do not fit those WUS-WUR based devices.
[0020] - Beamforming and space separation techniques, which assume that the BS knows the position of those devices and that those links between the BS and devices are secured and reliable.
[0021] - Other methods may consider that the sequences / ID used into the WUS are hard to track, follow and imitate which is not the case due to the simplicity of the WUS-WUR repetition pattern of the transmission and infinite capabilities of the jammer / attacker.
[0022] For above problems, it’s necessary to find a solution to detect / mitigate and combat those attacks without adding more complexity to the low-end devices and their WUS / WUR. Additionally, any proposed solution must respect the WUS frame structure and does not introduce additional signal coding including MAC and high-level encryption to the WUS.
[0023] The aforementioned issues have necessitated the introduction of an innovative solution within the relevant technical field. BRIEF DESCRIPTION OF THE INVENTION
[0024] The present invention relates to a method to eliminate the above-mentioned disadvantages and bring new advantages to the relevant technical field.
[0025] The present invention relates to communications technologies, and in particular to a method for signal detection and prevention of false wake-up signals especially in Internet of Things (loT) devices.
[0026] The invention proposes an efficient and simple method to prevent the attackers from performing sequential and unnecessary fake wake-up to the devices, by disrupting the wake-up procedure.
[0027] The method does not include any additional processing, tracking and mitigation scheme at the low-end devices and allows the base-station to act based on priori information or / and detection mechanisms. This method provides to disrupt the fake wake-up signal from waking the devices while preserving the simplicity and normal flow of communication in the network.
[0028] A main object of the invention is providing a method that is to prevent the attackers from performing sequential and unnecessary fake wake-up to the devices, by disrupting the wake-up procedure.
[0029] The invention proposes a solution to detect / mitigate and combat jamming signal attacks without adding more complexity to the low-end devices and their WUS / WUR. Moreover, the invention considers the WUS frame structure and does not introduce additional signal coding including MAC and high-level encryption to the WUS.
[0030] Thanks to the proposed invention, it is aimed to provide the normal flow of the communication in the networks without being affected by fake signals.
[0031] Moreover, the present invention solves the problems such as draining the battery of those UE’s, denial of service attacks (DOS) and increasing the traffic and interrupting the normal flow of the communication in the networks. In order to achieve all the objects stated above and arising from the above detailed description, a defense method for against signal attacks is proposed in the invention.
[0032] The advantage of the invention is as follows:
[0033] • Does not introduce additional signal coding including MAC and high-level encryption to the WUS.
[0034] • Providing energy efficiency by segmenting the WUR process.
[0035] • Incorporating a single feedback system for both WUS signal and initial communication process between BS and UE.
[0036] • Ensuring more coverage area compared to other techniques by exploiting processing gain of a spread sequence and its robustness to interference.
[0037] Another possible embodiment of the invention is characterized in that;
[0038] • The BS that makes decisions and operations over the received WUS.
[0039] • The BS that works with the UE to modify the jamming signal or perform any action to change the signal sequence or identity (ID).
[0040] • The BS that beamforming the jamming signal or transmitting the jamming signal via power level.
[0041] • Decoding and processing the fake WUS as a single symbol or a part of the block of symbols.
[0042] The proposed method is dependent on the computer implemented method. In the first aspect, the embodiment of the present invention relates to a method for detecting communication jamming attack which can be executed by an apparatus for wireless communication at a base station in a wireless communications system (the apparatus may include a processor, memory coupled with the processor, and instructions stored in the memory), or a network device, or by a component of the network device (such as a processor, a chip, or a chip system, etc.), or can be implemented by all or logical modules or software implementations of some network device functions or computer implemented device. Other aspects, features, and embodiments will become apparent to those of ordinary skill in the art, upon reviewing the following description of specific, exemplary aspects in conjunction with the accompanying figures. While features may be discussed relative to certain aspects and figures, all aspects can include one or more of the advantageous features discussed herein. In other words, while one or more aspects may be discussed as having certain advantageous features, one or more of such features may also be used in accordance with the various aspects discussed herein. Such exemplary aspects can be implemented in various devices, systems, and methods.
[0043] BRIEF DESCRIPTION OF THE DRAWINGS
[0044] The present disclosure, in accordance with one or more various examples, is described in detail with reference to the following figures. The drawings are provided for purposes of illustration only and merely depict examples of the disclosure. These drawings are provided to facilitate the reader's understanding of the disclosure and should not be considered limiting the breadth, scope, or applicability of the disclosure. It should be noted that for clarity and ease of illustration these drawings are not necessarily made to scale.
[0045] Figure 1 : An attacker is learning the pattern of the wake-up signal transmitted by the base-station to devices.
[0046] Figure 1 : Retransmission of fake WUS by an attacker to unnecessarily wake-up the devices.
[0047] Figure 2: The WUS structure with multiple symbols.
[0048] Figure 3: The BS processes partially the WUS to detect whether it's valid or fake.
[0049] Figure 4: The BS sends a jamming signal to interrupt the WUR (8) from triggering the MR on.
[0050] Figure 5: Flowchart of the proposed method.
[0051] REFERENCE NUMBERS GIVEN IN THE FIGURE
[0052] The reference numbers of the elements included in the figures are provided below for reference.
[0053] 1 BS 2 UE
[0054] 3 Retransmission of WUS
[0055] 4 Attacker
[0056] 5 WUS
[0057] 6 WUS learning
[0058] 7 Real WUS
[0059] 8 WUR
[0060] 9 Fake WUS
[0061] 10 Specific sequence or pattern
[0062] 11 Process of first symbol
[0063] DETAILED DESCRIPTION OF THE INVENTION
[0064] In this detailed description, the subject matter is explained with references to examples without forming any restrictive effect only to make the subject more understandable.
[0065] To achieve all the objectives mentioned above and that will emerge from the following detailed description. The invention generally relates to a method for detecting communication jamming attack and defense method for against signal attacks in wireless communication networks.
[0066] The proposed method by the invention that is for signal detection and prevention of false wake-up signals especially in loT devices. In another saying, the proposed method disrupts the fake wake-up signal from waking the devices while preserving the simplicity and normal flow of communication in the network. In this way, the method proposes a new defense method for against wake-up signaling attacks especially in loT devices.
[0067] The invention has countermeasures against snapshot attacks of WUS (5) mimicking and retransmission from other attackers (4). A defense method for against signal attacks is illustrated in Figure 6. The process steps of the method that carries out these measures are stated below, respectively. A computer implemented defense method for against signal attacks for wireless communication networks having at least base station, user-equipment (UE), and particularly in IOT devices, the method comprises following steps:
[0068] • Sending wake up signal (WUS (5)) which is designed that the first symbols can be determined through a sequence, a preamble or and On-Off Keying (OOK) scheme, to user-equipment(s) by base station (BS) (1),
[0069] • Tracking or performing sounding over WUS (5) by attacker,
[0070] • Mimicking WUS (5) and transmitting fake WUS (5) to UE(s) (2) by Jammer,
[0071] • Reaching BS (1) by WUS (5), and partially decoding and processing the fake WUS (5),
[0072] • Checking the WUS (5) from BS (1 );
[0073] • If the WUS (5) is from BS (1), dropping signal,
[0074] • If the WUS (5) is not from BS (1), sending a jamming signal (such as white noise to interrupt the WUR (8) from processing the WUS (5) and triggering its main radio (MR) on).
[0075] Mimicking mentioned in the method means that is used in physical layer security that indicates the ability of the attacker to copy the transmitted signal identically and act as a BS (1).
[0076] Partially mentioned in the method means that is as explained in Figure 3 the WuS signal consists of block of symbols, so the term partially refers to the process of a single symbol or a part of the block of symbols.
[0077] Decoding and processing mentioned in the method means that: Each symbol of the WuS signal is demodulated based on the nature of the WuS signal. If it is an OFDM signal the decoding and processing implementation consists of applying an OFDM receiver starting from matched filtering, Fast Fourier Transform (FFT) process, channel estimation, till the bits level decoding.
[0078] A user-equipment (UE (2)) employing WUR (8)-WUS (5) to trigger its MR (main radio) in the context of low-power communication, receives known / partially known (may change after a duration or number of transmission) signal, this signal is agreed-upon previously between the BS (1) and the UE (2). After transmitting the WUS (5), the WUR (8) processes it, and if it is intended to its corresponding UE (2), the WUR (8) triggers the MR (Main radio) ON to perform communication with the BS (1). In the presence of an attacking entity (such as a fake base station) the WUS (5) is detected / intercepted, decoded / learned and imitated. This process is highly likely due to the simplicity of the WUS (5), repetitive transmission pattern and high capabilities of the attacker (4), this process is illustrated in Figure 1.
[0079] Attacker (4) operation on WUS (5):
[0080] The attacker (4), after determining the pattern / type and / or information in the WUS (5), can either modify the information on it and retransmit the signal periodically using any pattern to the devices, or keep the same signal and broadcast it to the devices to trigger the UE (2) or a group of UE (2) ON unnecessarily. This fake imitating scheme can have multiple motivations, including power draining, denial of service, disrupting communication in the network... etc. The fake WUS (9) transmitted by the attacker (4) can be repeated in any pattern, the operation discussed above is depicted in Figure 2.
[0081] While the attacker (4) sends the fake WUS (9) to the users, the BS (1) will as well receive those signals since it has two separate chains for reception and transmission (the BS (1) receives all the time). The WUS (5) uses known and limited sequences (such as Zadoff-chu sequencess) for time correlation or OOK signaling to indicate the ID / sequences of the UE (2) or group of UE’s (2) as shown in Figure 3. Regardless of the waveform used, the first symbols (or all the symbols) use those correlation or OOK sequences in the WUS (5). Hence from those symbols the BS (1) can decide whether it transmitted this signal or it was not initiated from it, this can be done by checking transmission time, commands, registers or any information that the BS (1) can access to. As illustrated in Figure 3, the attacker (4) sends a fake WUS (9), which is received at the UE (2) and BS (1) at TP1and TP2, respectively, since the propagation delays are in nanoseconds it does not matter which whether the BS (1) or UE (2) receives the signal first. BS (1) decision and operation over received WUS (5).
[0082] At the BS (1) side, after reception of the WUS (5) at TP2, it is processed partially (using one or multiple symbols) and the sequences correlation pattern is obtained, this information is used by the BS (1) to decide whether the signal was transmitted from it or not, the decision can leverage the following parameters (but not exclusively):
[0083] - Sequences or information on WUS (5) such as payload or ID.
[0084] - Prior information on previous transmissions.
[0085] - The received signal power (RSSI).
[0086] The WUS (5) has a duration of Twurwhich is much longer than the propagation delays, processing delay and the decision delay of the BS (1), since the WUS (5) have multiple symbols and each symbol duration is in microseconds or more. The previous operations are illustrated in Figure 4. At the UE (2) after receiving the WUS (5) at Tp2(here it does not matter whether TP2is bigger than rplor the opposite), the WUR (8) cannot trigger the MR unless the WUS (5) is processed fully or mostly which takes Tproc< hence ensuring that even after r^eds +Tproc +Tp2 passes, where T eds>Tproc represents the delay for decision and processing the WUS (5) partially by the BS (1).
[0087] In the case that the BS (1) decides that the WUS (5) is fake and it was initiated from a non-authorized source, it transmits a jamming signal such as white noise after receiving the signal at rp2by t^ds +Tproc This white noise will be received by the WUR (8) after a propagation delay TP3between the BS (1) and the UE (2), making the total delay between receiving the WUS (5) from the attacker (4) and the white noise from the BS (1) (neglecting the difference between TP2and which is less that the total WUS (5) duration Twur, hence this jamming signal transmitted from the BS (1) will prevent the WUR (8) from triggering the MR by corrupting the WUS (5). This process holds as long as:
[0088] Which is valid due to existing propagation delays, processing delays and symbol durations. The last operation and the flowchart of the whole method are illustrated in figure 5 and figure 6, respectively.
[0089] Operation after attacker (4) detection:
[0090] The BS (1) can either transmit the jamming signal in omni-directional or using beamforming if it acquires the position of the specific targeted device. Additionally, the BS (1) can deal with the jammer in any way available including positioning and locking it into a specific signal pattern after detecting the existing of fake WUS’s (9). The BS (1) can initiate communication with the attacked UE (2) to coordinate operation or WUS (5) sequences or ID change.
[0091] In figure 1 , the BS (1) sends a WUS (5) for UE’s (2) WUR (8), and an attacker (4) tracks or performs sounding over those signals.
[0092] In figure 2, the attacker (4) determines the signal structure, modify its contents or keep it, then retransmits this WUS (5).
[0093] In figure 4, the BS (1) leverages those initial symbols to determine whether the received signal is the reflection of the transmitted signal to the corresponding WUS (5) or not using prior knowledge or specific processing.
[0094] Prior knowledge: Prior knowledge is the BS prior knowledge about its transmitted WuS to the UE to compare with the received signal.
[0095] Initial symbols: refers to the first symbols of the WuS that contain the BS ID or its fingerprint, by decoding the first symbols the BS can recognize whether the signal is a reflected signal or an attacker signal.
[0096] BS (1) decision and operation over received WUS (5). The base-station can use other parameters to decide on the WUS (5) eligibility such as AoA and RSSI.
[0097] The other parameters are mentioned like RSSI and AoA.
[0098] RSSI: Based on received signal strength the BS can distinguish between an attacker signal or a reflected signal.
[0099] AoA: based on angle of arrival the BS can know whether the received signal belongs to the attacker or not as attacker signals arrive at different AoA that are not predefined on the BS.
[0100] The BS (1) may beamform the jamming signal or transmit it over a specific power level (greater than the RSSI of the received signal and it can be maxed based on BS limits due to energy saving). Additionally, the BS (1) can coordinate with the UE (2) after that, to change its signal or performing any operation to change its sequences or identity (ID). The scope of protection of the invention is specified in the attached claims and cannot be limited to those explained for sampling purposes in this detailed description. It is evident that a person skilled in the art may exhibit similar embodiments considering the above-mentioned facts without drifting apart from the main theme of the invention.
[0101] References
[0102] [1] 3GPP TR 38.869 NR; Study on low power wakeup signal and receiver for NR.
[0103] [2] Borio, Daniele, and Ciro Gioia. "Real-time jamming detection using the sum-of- squares paradigm." In 2015 International Conference on Localization and GNSS (ICL-GNSS), pp. 1-6. IEEE, 2015.
Claims
CLAIMS1. A computer implemented defense method for against signal attacks for wireless communication networks having at least base station, user-equipment (UE), and particularly in IOT devices, the method comprises following steps:• Sending wake up signal (WUS (5)) which is designed that the first symbols can be determined through a sequence, a preamble or and On-Off Keying (OOK) scheme, to user-equipment(s) by base station (BS) (1),• Tracking or performing sounding over WUS (5) by attacker,• Mimicking WUS (5) and transmitting fake WUS (9) to UE(s) (2) by Jammer,• Reaching BS (1) by WUS (5), and decoding and processing the fake WUS (9),• Checking the WUS (5) from BS (1 );• If the WUS (5) is from BS (1), dropping signal,• If the WUS (5) is not from BS (1 ), sending a jamming signal.
2. The method according to claim 1, wherein said BS (1) makes decisions and operations over the received WUS.
3. The method according to claim 1 , wherein said the BS (1) works with the UE (2) to modify the jamming signal or perform any action to change the signal sequence or identity (ID).
4. The method according to claim 1, wherein said the BS (1) is beamforming the jamming signal or transmitting the jamming signal via power level.
5. The method according to claim 1, wherein said jamming signal is a white noise to interrupt the WUR (8) from processing the WUS (5) and triggering its main radio on.
6. The method according to claim 1, wherein said decoding and processing the fake WUS (9) as a single symbol or a part of the block of symbols.
Citation Information
Patent Citations
Avoiding false detection associated with wake-up signal
EP3997919B1
Wireless communication jamming using signal delay technology
US8543053B1
Wake-up control system and method for controlling receiver wake-up
US8564419B2