Multilateration Timing Advance Security via Identifier Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current positioning methods in wireless telecommunications, such as the MTA procedure, are vulnerable to bandit devices generating false timing advance information, leading to degraded accuracy in estimating the position of valid devices.

Innovation Solution

Incorporating unique identifiers in RRLP Multilateration Timing Advance Request messages to validate timing advance information, ensuring that only valid devices can report accurate timing advance data to the positioning node, thereby preventing false information from bandit devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the MTA procedure is performed without unique identifiers, then the positioning system can operate with simpler signaling, but the system becomes vulnerable to bandit devices generating false timing advance information

Engineering Contradiction:
Improveaccuracy of position estimationVSAvoidcomplexity of positioning procedure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by including unique identifiers (such as device IDs or location service IDs) in the RRLP Multilateration Timing Advance Request messages before the actual timing advance measurement process. This pre-established identification mechanism allows the positioning node to verify the legitimacy of each timing advance report, preventing bandit devices from injecting false information. The identifier is embedded in advance in the request message, so when the response is received, verification can immediately occur without adding complex post-processing steps.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If identifiers are added to validate timing advance information, then the system can prevent false information from bandit devices, but the signaling overhead increases

Engineering Contradiction:
Improveintegrity of timing advance informationVSAvoidsignaling overhead
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent uses copying by reusing existing identifier fields that are already part of the standard RRLP messaging structure. Rather than introducing entirely new message types or extensive additional data fields, the solution copies or repurposes existing identification elements (such as device identifiers or location service identifiers) to serve the additional function of validating timing advance information. This approach minimizes signaling overhead while maintaining reliability.

Inventive Principle:
Principle #26Copying

3Productivity

If the system accepts timing advance information without validation, then the positioning procedure is faster, but bandit devices can trigger false timing advance reports leading to degraded position accuracy

Engineering Contradiction:
Improvespeed of positioning procedureVSAvoidaccuracy of position estimation
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent implements feedback by creating a closed-loop verification process where the positioning node sends out requests with unique identifiers, receives responses that include those same identifiers, and automatically verifies the match. This feedback mechanism ensures that only legitimate responses from authorized devices are processed for position calculation. The verification step is integrated into the existing message flow, allowing rapid validation without significant delays to the overall positioning procedure speed.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10382968B2Increased security for multilateration timing advance
Publication Date: 2019.08.13 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US10382968B2 patent drawing
  • US10382968B2 patent drawing
  • US10382968B2 patent drawing

AI summary

A positioning node (e.g., SMLC), a Radio Access Network (RAN) Node (e.g., BSS/BTS), and a wireless device (e.g., MS) are described herein which implement procedures and corresponding modified or new messages/information elements/fields to reduce the possibility of a bandit (e.g., invalid or unauthorized) wireless device from triggering the RAN Node (e.g., BSS/BTS) to generate false timing advance (TA) information associated with the wireless device and report the false TA information to the positioning node (e.g., SMLC) which leads the positioning node (e.g., SMLC) to estimate with degraded accuracy a position of the wireless device.