Wireless Device Illegitimate Base Station Detection via Fabricated Messages

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless devices face security vulnerabilities when establishing communication with unknown base stations, as malicious devices can impersonate legitimate ones, leading to data theft or interception.

Innovation Solution

A wireless device can determine the legitimacy of a base station by sending fabricated messages and analyzing responses, including area update messages with fabricated Temporary Mobile Subscriber Identity (TMSI) or service request messages, to identify inappropriate responses from illegitimate base stations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If wireless devices establish communication with unknown base stations using standard identification processes, then communication establishment is enabled, but security vulnerability increases allowing malicious devices to impersonate legitimate base stations

Engineering Contradiction:
Improvecommunication establishmentVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by performing authentication operations before establishing full communication. The wireless device sends authentication requests and verifies responses from the base station prior to allowing data transmission, preventing malicious devices from impersonating legitimate base stations

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the wireless device monitors and analyzes communication patterns, authentication responses, and signaling messages from the base station. This continuous feedback allows the device to detect illegitimate base stations and terminate communication accordingly

Inventive Principle:
Principle #23Feedback

2Reliability

If wireless devices send fabricated messages to verify base station legitimacy, then security detection capability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidverification process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies copying by creating and sending fabricated authentication messages that mimic legitimate signaling protocols. The wireless device generates test messages containing authentication requests and analyzes the base station's responses to verify legitimacy without requiring complex custom protocol implementations

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent uses parameter changes by modifying authentication message parameters such as temporary mobile subscriber identity (TMSI) values and authentication tokens. By changing these parameters in fabricated messages and observing base station responses, the device can detect illegitimate base stations through systematic parameter variation

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11638152B2Identifying an illegitimate base station based on improper response
Publication Date: 2023.04.25 QUALCOMM INC
  • US11638152B2 patent drawing
  • US11638152B2 patent drawing
  • US11638152B2 patent drawing

AI summary

Various embodiments include methods, components and wireless devices configured to identify illegitimate base station. The processor of the wireless device may determine that a device in communication with the wireless device is a suspect base station. The processor may send a fabricated message to the device, and may receive one or more response messages from the device. The processor may determine whether one or more of the response messages received from the device is an appropriate response or an inappropriate response to the fabricated message. In response to determining that a response message is an inappropriate response, the processor may determine that the device is an illegitimate base station. In response to determining that the device is an illegitimate base station, the wireless device may perform a protective action.