Base Station Location Authentication via Encrypted Positioning Signals
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Global Navigation Satellite System (GNSS) and cellular-network location services are vulnerable to spoofing attacks, which can lead to inaccurate location determination, compromising user equipment (UE) and potentially affecting self-driving systems and emergency responders.
Innovation Solution
A base-station-location server authenticates base stations by comparing their locations to independently determined values, generating security keys for authenticated stations to encrypt positioning reference signals, allowing UE to verify the authenticity of base stations and use secure cellular-network location services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If base stations transmit positioning reference signals without authentication, then UE can determine location quickly using cellular-network location services, but the location determination becomes vulnerable to spoofing attacks
Solution Approach 1:
The base-station-location server performs preliminary authentication of base stations before they provide positioning services. The server determines locations of base stations using information from multiple sources and compares these to locations provided by the base stations themselves, authenticating them in advance. This preliminary verification prevents spoofing attacks without requiring complex real-time authentication during positioning operations.
Solution Approach 2:
A base-station-location server is introduced as an intermediary between base stations and UE. This server acts as a trusted mediator that audits base station locations, generates security keys for authenticated base stations, and provides authentication information to UE. The intermediary handles the complexity of authentication centrally, allowing simple positioning operations at the base station and UE levels while maintaining high reliability through centralized verification.
2Reliability
If UE uses GNSS techniques to determine location, then location can be obtained independently, but the system becomes vulnerable to GNSS spoofing attacks
Solution Approach 1:
The system applies preliminary anti-action by implementing authentication mechanisms that prevent spoofing attacks before they can affect location determination. The base-station-location server authenticates base stations in advance and provides authentication information to UE, creating a defensive layer against both GNSS and cellular-network spoofing attacks. This proactive security measure counters potential harmful actions before they can compromise location accuracy.
3Measurement precision
If base-station-location server audits all base stations using multiple sources, then authentication accuracy improves, but the time and resources required for authentication increase
Solution Approach 1:
The base-station-location server performs authentication audits on a selective and periodic basis rather than continuously for all base stations. The server determines locations using information from multiple sources when needed for verification, but can rely on previously authenticated base stations during normal operation. This partial auditing approach maintains high verification accuracy while reducing the time and computational resources required compared to continuous comprehensive audits of all base stations.
Data Source
AI summary
This document describes techniques and apparatuses for base station location authentication. In particular, a base-station-location server 264 provides protection against a Global Navigation Satellite System (GNSS) spoofing attack or a cellular-network spoofing attack by auditing processed locations 504 of base stations 120 within a cellular network. The base-station-location server 264 maintains a list of authenticated base stations, generates a security key 321 for a base station 120 that is authenticated, and sends the security key 321 to the base station 120 in an authentication message 522. The authenticated base station 120 uses the security key 321 to generate an encrypted positioning reference signal that protects timing information and/or a location 504 of the base station 120. The encrypted positioning reference signal also enables a user equipment (UE) to determine that the base station 120 is authenticated by the base-station-location server 264.


