Network Node False Base Station Detection via Protocol Timing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current telecommunication systems are vulnerable to false base station attacks, where non-legitimate devices intercept traffic between wireless devices and network nodes, making it difficult to prevent such attacks without significant modifications to radio protocols, and existing intrusion detection systems are ineffective in detecting these attacks targeting end users.

Innovation Solution

A detecting node in the communications network that analyzes protocol events and time instances to identify communications with non-legitimate devices, allowing the network to determine if a wireless device has been connected to a false base station without requiring modifications to the wireless device or significant hardware upgrades, by using existing network nodes and software updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing intrusion detection systems are used, then network infrastructure security can be monitored, but they are ineffective in detecting attacks targeting end users

Engineering Contradiction:
Improvedetection effectivenessVSAvoidcoverage scope
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Instead of having the wireless device detect the non-legitimate device itself, the patent inverts the detection approach by having the network node detect protocol events and time instances from the wireless device's communications to determine if it has been communicating with a non-legitimate device. This inversion allows the detection capability to be embedded in the network infrastructure where it can effectively monitor all end users.

Inventive Principle:
Principle #13The other way round (Inversion)

2Reliability

If radio protocols are modified to prevent false base station attacks, then security can be improved, but significant modifications to radio protocols are required

Engineering Contradiction:
ImprovesecurityVSAvoidprotocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary detection mechanism at the network node that analyzes protocol events and time instances without requiring modification of the existing radio protocols between the wireless device and network. The network node acts as a mediator that interprets existing protocol interactions to detect non-legitimate devices, thereby improving security while maintaining protocol compatibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If wireless devices are equipped with detection capabilities, then they can identify non-legitimate devices, but modifications to the wireless device are required

Engineering Contradiction:
Improvedetection accuracyVSAvoiddevice implementation
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

Instead of equipping wireless devices with detection capabilities, the patent inverts the approach by having the network node perform the detection based on protocol events from the device. This eliminates the need for complex modifications to wireless devices while achieving the same security objective through network-side analysis.

Inventive Principle:
Principle #13The other way round (Inversion)

4Measurement precision

If comprehensive monitoring is implemented, then detection accuracy improves, but operational costs increase

Engineering Contradiction:
Improvedetection precisionVSAvoidoperational cost
Core Design Contradiction:
Measurement precisionVSLoss of energy

Solution Approach 1:

The patent implements partial monitoring by focusing detection efforts on specific protocol events and time instances that are indicative of non-legitimate device communications, rather than monitoring all communications comprehensively. This selective approach maintains detection precision while reducing the operational burden and costs associated with comprehensive monitoring of all network traffic.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11297072B2Node and method for detecting that a wireless device has been communicating with a non-legitimate device
Publication Date: 2022.04.05 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US11297072B2 patent drawing
  • US11297072B2 patent drawing
  • US11297072B2 patent drawing

AI summary

Embodiments herein relate to a method performed by a detecting node (101) in a communications network (100), for detecting that a wireless device, WD, (120) associated with a first domain of the communications network (100) has been communicating with a non-legitimate device (150). The non-legitimate device (150) is a device associated with a second domain of the communications network (100). The non-legitimate device (150) impersonates a network node (110, 111, 140) of a first domain of the communications network (100). The detecting node (101) obtains information regarding one or more protocol events related to the communication between the WD (120) and a first network node (110, 111, 140). The information comprises a time instance related to the one or more protocol events. The detecting node (101) determines, based on the time instance and a set of time limits related to the one or more protocol events, that the WD (120) has been communicating with the non-legitimate device (150).