UE False Base Station Attack Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 3GPP standards fail to protect against spoofing attacks by malicious eNode B (eNB) base stations, which can cause legitimate user equipment (UE) devices to lock out of the network, disrupting communication and potentially impacting public safety.

Innovation Solution

A UE device is configured to receive an EPS Mobility Management (EMM) error code and, upon confirmation by a second eNB in a different tracking area, enter a lock state to prevent further attach requests to the initial malicious eNB, thereby preventing network disruption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the UE enters a lock state upon receiving an EMM error code from an eNB, then the UE can prevent further attach requests to the malicious eNB, but the UE may be locked out by a spoofing attack causing network disruption

Engineering Contradiction:
Improvenetwork securityVSAvoidfalse base station attack
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by requiring the UE to perform verification of the eNB's authenticity before entering the lock state. The UE checks whether the eNB is legitimate through validation procedures (such as verifying authentication tokens or network identifiers) before accepting the EMM error code as valid. This preliminary verification prevents malicious eNBs from triggering false lockouts, while still allowing legitimate lockouts when the verification succeeds and the eNB is confirmed to be authentic.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the UE sends attach requests to multiple eNBs to confirm the error code, then the UE can validate the error code legitimacy, but the device complexity increases

Engineering Contradiction:
Improveerror code validationVSAvoidattachment procedure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the error code validation process into distinct stages: (1) receiving the EMM error code from the initial eNB, (2) selecting and attempting attachment to a second eNB for verification, and (3) making the final lock state decision based on the verification result. This segmented approach breaks down the complex validation logic into manageable steps, improving implementability while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses a second eNB as an intermediary to verify the authenticity of the EMM error code. Instead of the UE directly trusting the error code from the initial eNB, the error code's validity is mediated through a second independent eNB that confirms whether the initial eNB was legitimate. This intermediary mechanism adds security without requiring complex direct verification between the UE and the network core.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10285060B2Preventing attacks from false base stations
Publication Date: 2019.05.07 NOKIA OF AMERICA CORP
  • US10285060B2 patent drawing
  • US10285060B2 patent drawing
  • US10285060B2 patent drawing

AI summary

Embodiments provide a user equipment (UE) device that includes a memory and a processor configured to execute instructions stored in said memory. The processor is configured by the instructions to receive a first evolved packet system (EPS) mobility management (EMM) attach reject message in response to an attempt to attach to a first eNode B (eNB) of a radio access network (RAN). If the attach reject message includes an Evolved Packet System mobility management (EMM) error code, the processor directs an attach request to a second, confirming eNB. The processor may be further configured by the instructions to receive a second attach reject message from the second eNB and enter a lock state only the condition that the second attach reject message also includes an EMM error code, optionally the same EMM error code received in the first attach reject message.