UE False Base Station Attack Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 3GPP standards fail to protect against spoofing attacks by malicious eNode B (eNB) base stations, which can cause legitimate user equipment (UE) devices to lock out of the network, disrupting communication and potentially impacting public safety.
Innovation Solution
A UE device is configured to receive an EPS Mobility Management (EMM) error code and, upon confirmation by a second eNB in a different tracking area, enter a lock state to prevent further attach requests to the initial malicious eNB, thereby preventing network disruption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the UE enters a lock state upon receiving an EMM error code from an eNB, then the UE can prevent further attach requests to the malicious eNB, but the UE may be locked out by a spoofing attack causing network disruption
Solution Approach 1:
The patent applies preliminary action by requiring the UE to perform verification of the eNB's authenticity before entering the lock state. The UE checks whether the eNB is legitimate through validation procedures (such as verifying authentication tokens or network identifiers) before accepting the EMM error code as valid. This preliminary verification prevents malicious eNBs from triggering false lockouts, while still allowing legitimate lockouts when the verification succeeds and the eNB is confirmed to be authentic.
2Reliability
If the UE sends attach requests to multiple eNBs to confirm the error code, then the UE can validate the error code legitimacy, but the device complexity increases
Solution Approach 1:
The patent applies segmentation by dividing the error code validation process into distinct stages: (1) receiving the EMM error code from the initial eNB, (2) selecting and attempting attachment to a second eNB for verification, and (3) making the final lock state decision based on the verification result. This segmented approach breaks down the complex validation logic into manageable steps, improving implementability while maintaining security.
Solution Approach 2:
The patent uses a second eNB as an intermediary to verify the authenticity of the EMM error code. Instead of the UE directly trusting the error code from the initial eNB, the error code's validity is mediated through a second independent eNB that confirms whether the initial eNB was legitimate. This intermediary mechanism adds security without requiring complex direct verification between the UE and the network core.
Data Source
AI summary
Embodiments provide a user equipment (UE) device that includes a memory and a processor configured to execute instructions stored in said memory. The processor is configured by the instructions to receive a first evolved packet system (EPS) mobility management (EMM) attach reject message in response to an attempt to attach to a first eNode B (eNB) of a radio access network (RAN). If the attach reject message includes an Evolved Packet System mobility management (EMM) error code, the processor directs an attach request to a second, confirming eNB. The processor may be further configured by the instructions to receive a second attach reject message from the second eNB and enter a lock state only the condition that the second attach reject message also includes an EMM error code, optionally the same EMM error code received in the first attach reject message.


