Telecommunications Channel Switching for Eavesdropping Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The GSM encryption algorithm A5/1 has vulnerabilities that can be exploited by eavesdropping equipment, particularly with the advent of affordable FPGA processing, allowing attackers to intercept and decrypt communications, which is a significant threat due to the high cost and time required for deploying a stronger encryption algorithm.

Innovation Solution

Implementing a method that rapidly changes communication sessions between different channels and keys, making it difficult for attackers to identify and intercept the decryption key by issuing commands to reassigned traffic channels and frequencies, and generating new cipher keys, thereby evading real-time decryption attempts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the A5/1 encryption algorithm is used to encrypt communications, then security is provided to some degree, but the algorithm has weaknesses that allow eavesdropping attacks with affordable FPGA equipment

Engineering Contradiction:
ImprovesecurityVSAvoideavesdropping vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies dynamics by making the communication channel assignment change over time. The network node dynamically reassigns the mobile station to different traffic channels at predetermined intervals, preventing static eavesdropping setups. This temporal variation in channel assignment disrupts the attacker's ability to continuously monitor and decrypt communications using fixed FPGA equipment.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements preliminary action by pre-planning channel reassignment at predetermined times before the attacker can complete key extraction. The network node schedules channel changes in advance, ensuring that even if an attacker has partially extracted a decryption key, the channel change occurs before the key can be fully utilized for real-time decryption, rendering the extracted key obsolete.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If a stronger encryption algorithm is deployed, then eavesdropping protection is improved, but the deployment cost is very expensive and requires terminal and network equipment redesign

Engineering Contradiction:
Improveeavesdropping protectionVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies parameter changes by modifying the channel assignment parameters (traffic channel frequencies and time slots) rather than changing the encryption algorithm itself. This approach improves security by varying the communication parameters over time, achieving enhanced protection without the high cost and complexity of deploying stronger encryption algorithms that would require hardware redesign.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If the communication session remains on a fixed channel, then the attacker can record and process data to obtain decryption keys, but changing channels frequently requires additional network control messages

Engineering Contradiction:
Improvesecurity against key extractionVSAvoidnetwork control complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements periodic action by reassigning traffic channels at predetermined time intervals during the communication session. This periodic channel changing disrupts the attacker's continuous recording and processing capability, as the channel changes occur at regular intervals that prevent the attacker from accumulating sufficient data to extract decryption keys, while using standard periodic handover procedures.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentEP2263395B1Improving security in telecommunications systems
Publication Date: 2015.09.09 VODAFONE GRP PLC
  • EP2263395B1 patent drawingFigure 1
  • EP2263395B1 patent drawingFigure 2
  • EP2263395B1 patent drawingFigure 3

AI summary

Security of communications between a mobile terminal 1 and a cellular network node (base station 3) is enhanced. A communication session transmitted on a first traffic channel '0' is encrypted using a key 'KA'. The security is enhanced by causing the communication channel to change to a second communication channel '7' after a predetermined time, preferably very quickly after establishing the key. In one embodiment the communication channel then changes to a third communication channel '25' after a predetermined time. In another embodiment the communication session is encrypted using a second key 'KB' after causing the communication channel to change to the second communication channel '7'.