User Equipment Authentication via Location Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless communication networks, false base stations can authenticate user equipment, leading to authentication relay attacks where a malicious entity can manipulate location information, causing inconsistencies between network-aware and actual user locations, which can result in charging fraud and undermine criminal investigations by providing false alibis.

Innovation Solution

The implementation of a method where user equipment transmits a request message to network devices, attempts authentication, and subsequently sends location information, allowing for detection of false base stations by comparing reported and actual location information, enabling the network to reject fraudulent registrations and prevent attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If user equipment transmits location information to network devices after authentication, then location tracking accuracy is improved, but the system becomes vulnerable to authentication relay attacks where false base stations can manipulate location data

Engineering Contradiction:
Improvelocation tracking accuracyVSAvoidauthentication security
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where the network device compares the location information received from user equipment with location information independently obtained through other means (such as triangulation or GPS). This feedback loop allows the system to detect inconsistencies and identify authentication relay attacks, thereby maintaining both location tracking accuracy and authentication security simultaneously

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary verification layer between the user equipment and the network. This intermediary component validates location information by comparing multiple sources and detecting anomalies, preventing false base stations from successfully manipulating location data while preserving accurate location tracking for legitimate users

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If authentication procedures are simplified for faster connectivity, then ease of operation is improved, but the system becomes more susceptible to false base station authentication

Engineering Contradiction:
Improveauthentication speedVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by performing location verification checks during the authentication process itself, rather than as a separate subsequent step. This allows the system to maintain fast authentication speeds while preventing false base station attacks, as the verification is built into the authentication flow and can reject fraudulent connections before they are fully established

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11496896B2User equipment authentication
Publication Date: 2022.11.08 LENOVO (SINGAPORE) PTE LTD
  • US11496896B2 patent drawing
  • US11496896B2 patent drawing
  • US11496896B2 patent drawing

AI summary

Apparatuses, methods, and systems are disclosed for user equipment authentication. One method includes transmitting, from a user equipment, a request message to one or more network devices. The method includes, in response to transmitting the request message, attempting authentication with the one or more network devices. The method includes, in response to successfully authenticating with the one or more network devices, transmitting a message comprising first location information corresponding to the user equipment to the one or more network devices.