Base Station Integrity Verification via System Message Hashing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless communication systems lack effective methods to distinguish between legitimate and fake base stations, leading to security challenges as user equipment cannot verify the authenticity of base stations, making them vulnerable to malicious attacks.
Innovation Solution
The method involves configuring and authenticating base stations using integrity information within system messages, employing HASH values and digital signatures to ensure information integrity, allowing user equipment to verify the legitimacy of base stations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If current protocols are used without verification, then wireless UEs can quickly join base stations, but UEs cannot distinguish between valid and fake base stations
Solution Approach 1:
The patent applies preliminary action by embedding integrity information (HASH values and digital signatures) into system messages before transmission. This allows UEs to verify base station authenticity proactively during the initial connection phase rather than requiring complex post-connection verification protocols, thus improving reliability without significantly increasing operational complexity.
Solution Approach 2:
The patent introduces integrity information (HASH values and digital signatures) as an intermediary element that mediates between the base station and UE. This intermediary provides a straightforward verification mechanism where UEs can authenticate base stations by checking these pre-configured integrity values against received system messages, resolving the contradiction between verification reliability and protocol complexity.
2Reliability
If a database of fake base station features is used, then some fake stations can be detected, but the method is passive and cannot recognize new fake stations with different features
Solution Approach 1:
The patent applies self-service by enabling UEs to autonomously verify base station authenticity using integrity information embedded in system messages. Each UE can independently calculate and compare HASH values without relying on external databases or manufacturer updates, allowing the system to automatically detect both known and new types of fake base stations, thus improving both reliability and adaptability.
Solution Approach 2:
The patent uses preliminary action by pre-configuring integrity information in system messages before transmission. This allows for proactive verification of base station authenticity, enabling the detection of both existing and novel fake base station types without requiring prior knowledge or database updates, thereby enhancing both detection reliability and adaptability to new threats.
3Reliability
If integrity information is configured in system messages, then base station authenticity can be verified, but the system requires additional information blocks and HASH calculations
Solution Approach 1:
The patent applies merging by integrating integrity information (HASH values and digital signatures) directly into existing system messages. This combination approach allows verification functionality to be embedded within standard messaging protocols, providing reliable integrity verification while minimizing additional complexity by reusing existing message structures rather than creating separate verification channels.
Data Source
Figure 1A
Figure 1B
Figure 2~3
AI summary
A method and apparatus for configuring and detecting information integrity, and for discovering fake base stations based on integrity information in a system message is disclosed. In one embodiment, a method for authenticating a first wireless communication, includes: transmitting a first message from a first unit of the first wireless communication node to a second unit of the first wireless communication node, wherein the first message comprises first integrity information of at least one first information block in a system message configured by the first unit; receiving a second message by the first unit of the first wireless communication node from the second unit of the first wireless communication node, wherein the second message comprises second integrity information of at least one second information block in the system message configured by the second unit; and transmitting a third message from the first wireless communication node to a wireless communication device, wherein the third message comprises third integrity information and is configured to be used by the wireless communication device to determine fourth integrity information.