Wireless Network Attack Detection via Encrypted Tunnel

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing telecommunications networks, particularly older 2G technologies, lack effective mechanisms to protect user privacy and security, as they do not support encryption of personally identifiable information (PII) like IMSI, making users vulnerable to tracking and man-in-the-middle attacks by rogue base stations.

Innovation Solution

Implementing a system where the IMSI is encrypted using public key cryptography, with the terminal and home network establishing a strongly-encrypted tunnel using a shared secret, and verifying communication parameters to detect potential attacks, ensuring secure communication even on earlier network technologies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption of PII like IMSI is implemented using public key cryptography, then subscriber privacy and security are enhanced, but device complexity and computational overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-establishing a shared secret between the terminal and home network before the terminal connects to the serving network. This shared secret is used to encrypt PII such as IMSI, allowing the terminal to verify the authenticity of the home network response and detect man-in-the-middle attacks. The encryption keys and authentication mechanisms are prepared in advance, enabling secure communication without adding complexity to the real-time connection establishment process.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If communication parameters are verified to detect man-in-the-middle attacks, then detection precision improves, but use of energy and processing time increase

Engineering Contradiction:
Improvedetection precisionVSAvoiduse of energy
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent uses an intermediary approach by introducing a shared secret as a mediator between the terminal and home network. This shared secret enables the terminal to authenticate the home network's identity through encrypted communication parameters without requiring complex continuous monitoring. The verification process leverages the pre-established shared secret to efficiently check communication parameters, reducing energy consumption compared to constant active detection mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If a strongly-encrypted tunnel is established using shared secret, then security against unauthorized access improves, but device complexity and key management overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-establishing the shared secret and encryption keys between the terminal and home network before the terminal connects to the serving network. This allows the encrypted tunnel to be set up efficiently once the terminal needs secure communication, rather than requiring complex key management during each connection attempt. The preliminary setup reduces the computational burden during actual data transmission.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If encryption and verification mechanisms are implemented on older 2G networks, then security and privacy protection improve, but compatibility and ease of operation may be compromised

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies universality by designing an encryption and verification system that can operate across multiple network generations, including older 2G networks. The shared secret mechanism and public key cryptography are implemented in a way that is compatible with existing network protocols, allowing the same security framework to protect communications on both legacy and modern networks. This multi-functional approach maintains ease of operation by using familiar network procedures enhanced with security features.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12113783B2Wireless-network attack detection
Publication Date: 2024.10.08 T MOBILE US INC
  • US12113783B2 patent drawing
  • US12113783B2 patent drawing
  • US12113783B2 patent drawing

AI summary

In some examples, a terminal can establish wireless communication with a base station. The terminal can determine a challenge, transmit the challenge, receive a response, and determine that the response is valid. The terminal can, in response, establish a secure network tunnel to a network node. In some examples, a terminal can determine a first communication parameter associated with communication with the base station. The terminal can receive data indicating a second communication parameter via a secure network tunnel. The terminal can determine that the communication parameters do not match, and, in response, provide an indication that an attack is under way against the network terminal. Some example terminals transmit a challenge, determine a response status associated with the challenge, and determine that an attack is under way based on the response status.