Fake Base Station Detection via Downlink Security Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless communications, fake base station attacks compromise communication security by intercepting and forwarding messages, making it difficult for terminal devices to distinguish between normal and fake base stations, leading to potential privacy data breaches and communication disruptions.

Innovation Solution

A method involving terminal devices sending uplink messages through a second network device, which performs security processing on the messages based on time information, allowing the terminal device to verify the authenticity of the network device and identify potential fake base stations through encryption, integrity protection, and verification processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a fake base station is placed near a terminal device, then the terminal device is attracted to camp on the fake base station due to better signal quality, but the terminal device cannot distinguish between normal and fake base stations, leading to communication security threats

Engineering Contradiction:
Improvecommunication securityVSAvoiddifficulty of distinguishing normal and fake base stations
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies preliminary action by having the terminal device perform security verification on downlink messages before fully camping on a base station. The terminal device verifies security parameters (integrity protection, encryption) in the downlink message received from the base station before completing the camping process, thereby preventing connection to fake base stations in advance

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback by having the terminal device verify security parameters in downlink messages and provide feedback on verification results. If verification fails, the terminal device does not camp on the base station or switches to a normal base station, creating a feedback mechanism that prevents connection to fake base stations

Inventive Principle:
Principle #23Feedback

2Reliability

If the terminal device performs security verification on downlink messages, then the terminal device can identify fake base stations, but the verification process increases device complexity and processing overhead

Engineering Contradiction:
Improveability to identify fake base stationsVSAvoidcomplexity of security verification process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security verification is performed as a preliminary check during the initial access and camping process, before full communication establishment. This allows verification to be done with minimal additional complexity since the terminal device already has the necessary security parameters and algorithms available for initial access

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The terminal device performs self-service by using its own stored security parameters and algorithms to verify downlink messages independently, without requiring additional network support or increased network device complexity. The verification process leverages existing terminal capabilities

Inventive Principle:
Principle #25Self-service

3Reliability

If the fake base station forwards downlink messages from the normal base station to the terminal device, then the terminal device receives messages but cannot determine authenticity, but implementing security processing and verification enhances communication security

Engineering Contradiction:
Improvecommunication securityVSAvoidcomplexity of security processing
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Security processing (integrity protection and encryption) is applied preliminarily by the normal base station to downlink messages before transmission. This preliminary security processing allows the terminal device to verify message authenticity using its own security verification capabilities, resolving the contradiction between security enhancement and complexity

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Security parameters and verification mechanisms act as intermediaries between the normal base station and terminal device. These intermediaries enable the terminal device to distinguish authentic messages from forwarded fake messages without requiring complex additional processing, as the security parameters are already embedded in the downlink messages

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12096222B2Fake network device identification method and communications apparatus
Publication Date: 2024.09.17 HUAWEI TECH CO LTD
  • US12096222B2 patent drawing
  • US12096222B2 patent drawing
  • US12096222B2 patent drawing

AI summary

This application provides a fake network device identification method and a communications apparatus. An uplink message sent by a terminal device is forwarded to a first network device via a second network device. After receiving the uplink message, the first network device generates a downlink message for the uplink message, performs security processing on the downlink message based on first time information, and/or sends the downlink message to the second network device. The second network device sends, to the terminal device, the downlink message on which the security processing is performed. The terminal device performs security verification on the received downlink message, and/or identifies whether the second network device is a fake network device. This helps improve communication security.