Base Station Capability Signaling for Pseudo Station Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile networks are vulnerable to attacks from pseudo base stations, and existing solutions fail to effectively authenticate and secure communications between legitimate base stations and mobile terminals.

Innovation Solution

A method and apparatus that involve sending and receiving anti-pseudo base station capacity information between base stations and mobile terminals to enable authentication and key agreement processes matching the identified capacities, using symmetric or asymmetric keys to enhance network security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If mobile networks deploy according to 3GPP specifications, then network functionality and coverage are improved, but vulnerability to pseudo base station attacks increases

Engineering Contradiction:
Improvenetwork functionalityVSAvoidsecurity against pseudo base stations
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-configuring anti-pseudo base station capacity information in the base station before communication occurs. The base station determines its anti-pseudo base station capacity in advance and sends this information to the mobile terminal during the initial connection process, enabling the terminal to perform appropriate authentication and key agreement procedures before any potential attack can occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback by having the base station send anti-pseudo base station capacity information to the mobile terminal, which then uses this information to determine the appropriate authentication and key agreement process. This creates a feedback loop where the terminal's authentication behavior is directly influenced by the base station's declared capabilities, ensuring that both parties are aware of each other's security capacities.

Inventive Principle:
Principle #23Feedback

2Reliability

If authentication and key agreement processes are enhanced to prevent pseudo base station attacks, then network security is improved, but communication efficiency and connection speed deteriorate

Engineering Contradiction:
Improvenetwork securityVSAvoidconnection speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent applies dynamics by making the authentication and key agreement process adaptive rather than static. The mobile terminal determines the appropriate authentication process dynamically based on the anti-pseudo base station capacity information received from the base station. This allows the system to adjust the security level according to the actual threat environment and base station capabilities, avoiding unnecessary authentication overhead when attacks are not present.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements parameter changes by varying the authentication and key agreement parameters based on the anti-pseudo base station capacity. When the base station has high anti-pseudo base station capacity, more robust authentication parameters are used. When capacity is lower or attacks are not detected, simpler authentication processes can be employed, thus maintaining security while improving connection speed.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3913953B1Anti-pseudo base station method and apparatus, and computer-readable storage medium
Publication Date: 2026.03.04 ZTE CORP
  • EP3913953B1 patent drawingFigure 1~2
  • EP3913953B1 patent drawingFigure 3~4
  • EP3913953B1 patent drawingFigure 5~7

AI summary

An anti-pseudo base station method and apparatus, and a computer-readable storage medium are provided. The anti-pseudo base station method includes: sending, by a base station, first anti-pseudo base station capacity information to a mobile terminal, wherein the first anti-pseudo base station capacity information is used for identifying an anti-pseudo base station capacity of the base station. According to the solution provided by the embodiments, the terminal can be informed of the anti-pseudo base station capacity of the base station conveniently, so as to execute a corresponding authentication and key agreement and distribution process conveniently, and therefore improve network security.