Authentication Response Message Homogeneity for Fake Base Station Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Fake base stations pose a significant threat to communication systems by impersonating legitimate stations to obtain terminal device identities, leading to potential privacy leaks and unauthorized access.

Innovation Solution

A communication method and apparatus that standardizes authentication response messages to include response values, resynchronization tokens, or cause indication values in a uniform format, making it impossible for external devices to determine the specific type of information carried, thereby enhancing terminal device security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the authentication response message uses different formats for different authentication outcomes (success, resynchronization, failure), then the terminal device can provide detailed authentication feedback, but the fake base station can determine the authentication result by analyzing the message format

Engineering Contradiction:
Improveauthentication securityVSAvoidmessage format complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies homogeneity by making all authentication response messages follow the same uniform format regardless of the authentication outcome. The response always includes three information elements (first for response value, second for resynchronization token, third for cause indication value), making it impossible for fake base stations to distinguish authentication results by analyzing message format differences.

Inventive Principle:
Principle #33Homogeneity

Solution Approach 2:

The patent changes the parameter representation by always including all three information elements in every response message, even when certain elements are not applicable to the current authentication outcome. This parameter uniformity prevents format-based analysis attacks while still conveying necessary authentication information.

Inventive Principle:
Principle #35Parameter changes

2Loss of information

If the authentication response message includes only necessary information elements for each authentication outcome, then the message size is minimized, but the fake base station can easily identify the message type and determine authentication status

Engineering Contradiction:
Improveinformation efficiencyVSAvoidsecurity vulnerability to format analysis
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by proactively including all possible information elements in every response message before a fake base station can analyze the format. This preemptive approach ensures that the uniform format itself becomes the security mechanism, preventing format analysis attacks from the outset.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent uses the uniform message format structure as an intermediary that masks the actual authentication outcome. The consistent presence of all three information elements acts as a mediator that prevents direct correlation between message format and authentication status, thereby protecting against security vulnerabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If the terminal device sends different types of response messages based on authentication verification results, then the authentication process is efficient, but the security of the terminal device is compromised due to format analysis attacks

Engineering Contradiction:
Improveauthentication processing efficiencyVSAvoidterminal device security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent maintains authentication processing efficiency while improving security by using homogeneous message formats. All response messages contain the same three information elements, preventing format analysis attacks, while the actual authentication outcomes are still conveyed through the values within these standardized elements.

Inventive Principle:
Principle #33Homogeneity

Data Source

PatentEP3700245B1Communication method and device
Publication Date: 2022.10.12 HUAWEI TECH CO LTD
  • EP3700245B1 patent drawingFigure 1
  • EP3700245B1 patent drawingFigure 2A
  • EP3700245B1 patent drawingFigure 2B

AI summary

A communication method and a communications apparatus are provided. The method includes: receiving, by a terminal device, a first authentication request from a security function network element; obtaining, by the terminal device, authentication reference information based on the first authentication request, where the authentication reference information is a response value, a resynchronization token, or a cause indication value; and sending, by the terminal device, an authentication response message to the security function network element, where the authentication response message includes a first information element used to carry the response value, a second information element used to carry the resynchronization token, and a third information element used to carry the cause indication value, and the authentication reference information is carried in an information element corresponding to the authentication reference information.