Location-Aware Security Classification for Fake Base Station Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G mobile networks, attackers with mobility capabilities can launch fake base station attacks, compromising security and privacy by moving to different locations and intercepting communication content, necessitating effective security analytics across varying geographical areas.

Innovation Solution

A method for obtaining a security classification result involves a security function network element performing security analytics on a target location area based on behavior information of terminal devices, including traffic data and movement tracks, to determine the degree of potential attacks and adjust security protection modes accordingly.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If security analytics are performed on all location areas continuously, then security detection capability is improved, but network signaling overhead and processing burden increase

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidsignaling overhead
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent implements location-area-based security analytics, where different location areas are classified into different security risk levels (high-risk, medium-risk, low-risk). Security analytics are selectively performed based on the specific characteristics of each location area rather than uniformly across all areas. This local differentiation reduces overall signaling overhead while maintaining security detection capability in high-risk areas.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent performs security analytics selectively on specific location areas identified as high-risk or medium-risk, rather than continuously on all location areas. By focusing analytics resources on partial areas where security threats are more likely to occur, the system achieves effective security detection while significantly reducing network signaling overhead and processing burden.

Inventive Principle:
Principle #16Partial or excessive action

2Reliability

If security protection is forcibly enabled in high-risk areas, then network security is improved, but terminal device power consumption increases

Engineering Contradiction:
Improvenetwork securityVSAvoidterminal device power consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements location-area-based security protection policies, where security protection levels are adjusted according to the specific risk characteristics of each location area. In high-risk areas, security protection is forcibly enabled to ensure network security. In low-risk areas, security protection can be relaxed or disabled, thereby reducing terminal device power consumption while maintaining overall network security.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If behavior information is collected from all terminal devices, then security analytics accuracy is improved, but privacy protection becomes more difficult

Engineering Contradiction:
Improvesecurity analytics accuracyVSAvoidprivacy risk
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent extracts and analyzes only the necessary behavior information elements required for security assessment, such as terminal device movement patterns, location area changes, and communication behavior characteristics. By selectively extracting only the essential security-relevant information rather than collecting all possible terminal data, the system achieves accurate security analytics while minimizing privacy intrusion.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12627703B2Method for obtaining security classification result and communication apparatus
Publication Date: 2026.05.12 HUAWEI TECH CO LTD
  • US12627703B2 patent drawing
  • US12627703B2 patent drawing
  • US12627703B2 patent drawing

AI summary

Embodiments of this application provide a method for obtaining a security classification result for a location area. A security function network element receives an identifier of a target location area and determines to perform security analytics on the target location area based on the identifier of the target location area. The security function network element may determine a security classification result of the target location area based on first information, where the security classification result indicates a degree to which a potential attack exists in the target location area. The first information is related to behavior information of a terminal device in the target location area, where the behavior information includes traffic data and/or movement track information.