Authentication Response Message Homogeneity for Fake Base Station Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Fake base stations pose a significant threat to communication systems by impersonating legitimate stations to obtain terminal device identities, leading to potential privacy leaks and unauthorized access.
Innovation Solution
A communication method and apparatus that standardizes authentication response messages to include response values, resynchronization tokens, or cause indication values in a uniform format, making it impossible for external devices to determine the specific type of information carried, thereby enhancing terminal device security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the authentication response message uses different formats for different authentication outcomes (success, resynchronization, failure), then the terminal device can provide detailed authentication feedback, but the fake base station can determine the authentication result by analyzing the message format
Solution Approach 1:
The patent applies homogeneity by making all authentication response messages follow the same uniform format regardless of the authentication outcome. The response always includes three information elements (first for response value, second for resynchronization token, third for cause indication value), making it impossible for fake base stations to distinguish authentication results by analyzing message format differences.
Solution Approach 2:
The patent changes the parameter representation by always including all three information elements in every response message, even when certain elements are not applicable to the current authentication outcome. This parameter uniformity prevents format-based analysis attacks while still conveying necessary authentication information.
2Loss of information
If the authentication response message includes only necessary information elements for each authentication outcome, then the message size is minimized, but the fake base station can easily identify the message type and determine authentication status
Solution Approach 1:
The patent applies preliminary anti-action by proactively including all possible information elements in every response message before a fake base station can analyze the format. This preemptive approach ensures that the uniform format itself becomes the security mechanism, preventing format analysis attacks from the outset.
Solution Approach 2:
The patent uses the uniform message format structure as an intermediary that masks the actual authentication outcome. The consistent presence of all three information elements acts as a mediator that prevents direct correlation between message format and authentication status, thereby protecting against security vulnerabilities.
3Productivity
If the terminal device sends different types of response messages based on authentication verification results, then the authentication process is efficient, but the security of the terminal device is compromised due to format analysis attacks
Solution Approach 1:
The patent maintains authentication processing efficiency while improving security by using homogeneous message formats. All response messages contain the same three information elements, preventing format analysis attacks, while the actual authentication outcomes are still conveyed through the values within these standardized elements.
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
A communication method and a communications apparatus are provided. The method includes: receiving, by a terminal device, a first authentication request from a security function network element; obtaining, by the terminal device, authentication reference information based on the first authentication request, where the authentication reference information is a response value, a resynchronization token, or a cause indication value; and sending, by the terminal device, an authentication response message to the security function network element, where the authentication response message includes a first information element used to carry the response value, a second information element used to carry the resynchronization token, and a third information element used to carry the cause indication value, and the authentication reference information is carried in an information element corresponding to the authentication reference information.