Wireless Device Pinning to Block Illegitimate Network Entities

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication systems face security vulnerabilities due to the inability to distinguish between legitimate and illegitimate network entities, leading to potential attacks where devices may connect to false or illegitimate cells, causing interference and data breaches.

Innovation Solution

A method where wireless communication devices obtain a configuration that adjusts connection procedures to only permit connections to legitimate network entities, preventing connections to illegitimate ones, by using pinning configurations that include explicit or implicit information about allowed network cells, priority levels, and geographic restrictions, and applying these configurations based on trigger conditions such as signal strength and attack detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If wireless communication devices are allowed to connect to any network entity, then device freedom and network flexibility are improved, but security vulnerabilities and connection to illegitimate cells increase

Engineering Contradiction:
Improveconnection flexibilityVSAvoidnetwork security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by differentiating between legitimate and illegitimate network entities. The system allows connections to legitimate network entities while blocking connections to illegitimate ones, creating different connection qualities based on entity authenticity. This is achieved through configuration data that identifies and classifies network entities, enabling selective connection behavior.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces an intermediary mechanism through the wireless communication device itself, which receives and processes configuration data containing information about legitimate and illegitimate network entities. The device uses this intermediary configuration to make informed connection decisions, acting as a mediator between the device and network entities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If devices can freely select network cells, then network accessibility is improved, but interference and data breaches from illegitimate cells increase

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidinterference and data breaches
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by providing configuration data to wireless communication devices in advance, containing information about legitimate and illegitimate network entities before connection decisions are made. This pre-provided configuration enables devices to make secure connection decisions without real-time analysis, preventing connections to illegitimate cells before they can cause harm.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent converts the potential harm of illegitimate cells into a benefit by using the same cell selection mechanisms to identify and block harmful entities. The system uses configuration data that mirrors legitimate network structures to create a detection mechanism, turning the potential vulnerability into a security feature that identifies and prevents connections to illegitimate cells.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

3Reliability

If connection procedures are restricted to legitimate entities only, then network security is improved, but device complexity and configuration requirements increase

Engineering Contradiction:
Improvenetwork securityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies self-service by enabling wireless communication devices to autonomously use the provided configuration data to make connection decisions. The device independently processes the configuration information about legitimate and illegitimate entities and automatically applies it to connection procedures without requiring external intervention or complex manual configuration.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent uses parameter changes by modifying connection procedure parameters based on the configuration data. The system changes connection parameters such as allowed network entities, priority levels, and selection criteria dynamically based on the provided configuration, enabling secure connections through parameter adjustment rather than complex procedural changes.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If pinning configurations are applied to prevent illegitimate connections, then security against false cells is improved, but connection establishment time increases

Engineering Contradiction:
Improvesecurity against false cellsVSAvoidconnection establishment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-providing configuration data that includes identification information about legitimate and illegitimate network entities before connection attempts are made. This advance preparation allows the device to quickly verify entity legitimacy during connection establishment without requiring time-consuming real-time analysis, thus reducing the time penalty of security checks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces mechanical connection verification processes with information-based verification. Instead of using complex real-time detection mechanisms, the system substitutes a more efficient information comparison approach where the device compares detected entity characteristics against pre-stored configuration data, reducing the time required for security verification.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12063512B2Systems and methods for securing wireless communication with device pinning
Publication Date: 2024.08.13 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US12063512B2 patent drawing
  • US12063512B2 patent drawing
  • US12063512B2 patent drawing

AI summary

Systems and methods of the present disclosure are directed to a method performed by a Wireless Communication Device (WCD) for securing wireless communication. The method includes obtaining a configuration descriptive of network entity(s) comprising (a) Legitimate Network Entity (LNE(s)); (b) or Illegitimate Network Entity (INE(s)); or (c) both LNE(s) and INE(s). The method includes determining that a trigger condition for applying the configuration has occurred. The method includes, responsive to making the determination, applying the configuration to the WCD such that connection related procedure(s) of the WCD related to connection between the WCD and the network entity(s) are adjusted in such a manner that the WCD is permitted to connect to only the LNE(s), not permitted to connect to the INE(s), both permitted to connect to only the LNE(s) and not permitted to connect to the INE(s), or not permitted to connect to any network entity.